Semgrep MCP Server Setup Guide

Prerequisites
  • Ensure you have Python 3.13+ installed.

Installation

CLI Installation

  1. Install uv using their installation instructions.
  2. Clone the repository.
  3. Install Semgrep:
    pip install semgrep
     

Docker Installation

  1. Build the Docker image:
    docker build -t mcp-server .
     

Usage

Running the Server

CLI

  1. Start the MCP server:
    uv run mcp run server.py -t sse
     

Docker

  1. Run the Docker container:
    docker run -p 8000:8000 mcp-server
     
  2. Alternatively, use the published image:
    docker run -p 8000:8000 ghcr.io/semgrep/mcp:latest
     

Creating Your Own Client

  1. Connect to the MCP server using the following Python code:
    from mcp.client import Client
     
    
     client = Client()
     client.connect("localhost:8000")
     
    
     # Scan code for security issues
     results = client.call_tool("semgrep_scan", {
      "code": "def get_user(user_id):n return User.objects.get(id=user_id)",
      "language": "python"
     })
     

Cursor Plugin Configuration

  1. Go to Cursor > Settings > Cursor Settings.
  2. Choose the MCP tab.
  3. Click “Add new MCP server”.
  4. Set the following:
  5. Ensure the MCP server is enabled.

Alternative Configuration

  1. Add the following to ~/.cursor/mcp.json:
    {
      "mcpServers": {
      "Semgrep": {
      "url": "http://localhost:8000/sse"
      }
      }
     }
     

Advanced Usage

Scan an Entire Directory

results = client.call_tool("scan_directory", {
  "path": "/path/to/code",
  "config": "p/security-audit"
 })
 

Filter Results by Severity

filtered = client.call_tool("filter_results", {
  "results_file": "/path/to/results.json",
  "severity": "ERROR"
 })
 

Development

Running the Development Server

  1. Start the MCP server in development mode:
    uv run mcp dev server.py
     
  2. The server runs on http://localhost:3000 with the inspector server on http://localhost:5173.

Note

  • When opening the inspector server, add query parameters to the URL to increase the default timeout of the server from 10s:
    http://localhost:5173/?timeout=300000
     
Share this post: