MCP100 IndexSecurity & Testing
MCP100 SelectedFirst-party MCP

semgrep

by ecosystem:semgrep

Updated August 14, 2026 · Reviewed July 30, 2026

Security & TestingCybersecuritySoftware & Technology

MCP100 verdict

Run Semgrep security scans and inspect local or authorized Semgrep AppSec findings.

MCP100 Assessment

Editorial verdict

Run Semgrep security scans and inspect local or authorized Semgrep AppSec findings.

Reviewed 2026-07-30 · Next review 2026-10-30

Task Fit

Mapped

Specialized workflows

Trust

Reviewed

A dated editorial review is published on the MCP detail page.

Maintenance

Activity observed

A dated repository or package update is available; editorial maintenance review is still pending.

Popularity

Signals available

Visible usage signals are shown for discovery only, not as proof of safety.

Best for

  • Static-analysis and secure-coding investigation within the maintained Semgrep CLI.

Not ideal for

  • Teams outside the publisher ecosystem or without least-privilege credentials

Avoid if

  • The connected identity is broader than the task requires
  • Tool calls cannot be reviewed before consequential mutations

Trade-offs

  • Scanning shares source-derived findings with the MCP client and may consume substantial local resources.

Evidence scope

Evidence

Current source snapshot

Popularity

16.2k MCP repository stars

No MCP-specific package metric is stored

Stars observed 2026-08-14T18:46:26.000Z · Downloads observation date unavailable

No exact repository popularity metric was collected during this ecosystem review.

No exact package popularity metric was collected during this ecosystem review.

Maintenance

Publisher activity observed 2026-08-14T17:24:23Z

Current source snapshot

Trust review

Source relationship: First-party MCP

Reviewed 2026-07-30 · Next review 2026-10-30