BusinessMCP
Semgrep logo

Semgrep

Security

by trailofbits

3/3 audits passCC-BY-SA-4.0

Use Semgrep in BusinessMCP

Free · imported in one click after signup

View on GitHub

Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep…

Semgrep is Trail of Bits' static-analysis skill (publisher trailofbits, CC-BY-SA-4.0) for running a Semgrep security scan over a codebase. The agent detects languages, selects rulesets, and must present the exact plan (rulesets, target, engine and mode) for explicit approval before any scan runs. Its bundled scripts/run-scans.sh then generates and batches every semgrep command, and a Python script merges the results to SARIF. Its principles are strict: every command uses --metrics=off, third-party rulesets from Trail of Bits, 0xdea and Decurity are included when the language matches, Semgrep Pro is checked for cross-file taint analysis, and rulesets that failed or were skipped must be reported rather than presented as a complete scan. It offers two modes, "run all" and "important only".

Use it for a first-pass security audit or to find known bug patterns before code review. The skill says not to use it for binary analysis, where Semgrep CI already exists, or for writing custom rules.

This is mainly for coding agents such as Claude Code that can run Semgrep locally. The skill depends on its bundled scripts; BusinessMCP imports skills as instructions only and does not run those scripts, so an imported copy serves as guidance rather than a working scanner.

What you can do with it

  • Run a first-pass security scan of a new codebase
  • Scan only high-confidence, high-impact security findings
  • Merge per-ruleset Semgrep output into one SARIF file
  • Check a repo with Trail of Bits and Decurity rulesets

Run it on your business data

Imported into BusinessMCP, Semgrep becomes a playbook your AI business analyst applies to your connected GitHub repositories.

Use Semgrep in BusinessMCP

Install it in a coding agent

One command adds Semgrep to your project.

npx skills add https://github.com/trailofbits/skills --skill semgrep

How we vetted it

Source
trailofbits/skills at 0cc1c73
Licence
CC-BY-SA-4.0
Security audits (skills.sh)
Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
Bundled scripts
Yes — read them before installing

Checked 2026-09-25 against its skills.sh listing. How we vet skills

Frequently asked questions

Does the Semgrep skill scan without asking?

No. Presenting the scan plan and waiting for an explicit yes is a hard gate; the original "scan this codebase" request does not count as approval.

Why does it always use --metrics=off?

Semgrep sends telemetry by default and --config auto also contacts its servers, so the skill turns metrics off on every command to avoid leaking data during a security audit.

How do I install Semgrep?

Run `npx skills add trailofbits/skills --skill semgrep`, or import it from the BusinessMCP dashboard, where only its instructions are kept and its scripts are not run.

Run Semgrep against your whole business

Free plan, no credit card.

Use Semgrep in BusinessMCP