Showcase


Try itExperimental
See what an agent can do with Semgrep before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$semgrep --versionrecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommitevidence →
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanningevidence →
Stories about container scanning in this arena
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracyevidence →
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency scaevidence →
Stories about dependency sca in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rulesevidence →
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detectionevidence →
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbomevidence →
Stories about supply chain sbom in this arena
Triage noise — stories about triage noise in this arenaTriage noiseevidence →
Stories about triage noise in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Semgrep stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
~6/10
unlocks → Webhooks · Official SDKs · Scoped API keys · Machine-readable spec · Versioning policy
Subscribe to events via webhooks
—0/10
Build against official SDKs
—0/10
Issue scoped/least-privilege API credentials for an agent
—0/10
Connect an agent via an official MCP server
✓6/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓8/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
~5/10
unlocks → MCP client
Operate the product with natural-language commands
~3/10
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
~6/10
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommit
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanning
Stories about container scanning in this arena
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency sca
Stories about dependency sca in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rules
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detection
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom
Stories about supply chain sbom in this arena
Triage noise — stories about triage noise in this arenaTriage noise
Stories about triage noise in this arena
Sorted by importance (agentic first) (high → low) · 55/55 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 6/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 6/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 5/10 | Cclaimed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Xcommunity | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Xcommunity | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
Run scans in CI on every pull request and fail the build on new findings via exit codes C Ci gates | devops-lead | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | full | 9/10 | Xcommunity | |
Run the scanner as a pre-commit hook so secrets and issues never enter my git history C Pre commit | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | full | 9/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | full | 8/10 | Cclaimed | |
Run static analysis that finds vulnerability classes like injection and XSS in my source code C Code analysis | developer | Sast rules — stories about sast rules in this arenaSast rules | 3 | full | 8/10 | Xcommunity | |
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings G Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | partial | 7/10 | Xcommunity | |
Scan my dependency manifests and lockfiles for packages with known vulnerabilities C Sca scanning | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 3 | full | 7/10 | Xcommunity | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 7/10 | Cclaimed | |
Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives C Ai triage | ai-native user | Triage noise — stories about triage noise in this arenaTriage noise | 3 | partial | 6/10 | Xcommunity | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 5/10 | Cclaimed | |
Baseline or ignore existing and false-positive findings so only new issues alert C Fp management | security-engineer | Triage noise — stories about triage noise in this arenaTriage noise | 3 | partial | 4/10 | Cclaimed | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | partial | 4/10 | Cclaimed | |
Scan a repository and its full git history for hardcoded secrets and credentials C Secret scanning | developer | Secret detection — stories about secret detection in this arenaSecret detection | 3 | partial | 4/10 | Cclaimed | |
Scan container images for OS-package and application-layer vulnerabilities before deploying them C Containers | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 3 | none | 0/10 | ||
Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling C Output formats | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | full | 9/10 | Xcommunity | |
Detect taint-style vulnerabilities that flow across files and function boundaries C Code analysis | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | full | 8/10 | Cclaimed | |
Have detected secrets verified against the issuing service so I know which ones are live C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | full | 8/10 | Cclaimed | |
Write custom static-analysis rules in a simple syntax and share them across repositories C Custom rules | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | full | 8/10 | Xcommunity | |
See scan findings surfaced as pull-request comments or checks in GitHub or GitLab C Ci gates | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | full | 7/10 | Cclaimed | |
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands C Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | full | 7/10 | Tprobed | |
Apply suggested or automatic code fixes for findings instead of only reading reports C Fix suggestions | developer | Sast rules — stories about sast rules in this arenaSast rules | 2 | partial | 6/10 | Cclaimed | |
Define custom detection rules for my organization's internal token and secret formats C Custom detection | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | partial | 6/10 | Xcommunity | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Cclaimed | |
Prioritize dependency alerts by whether the vulnerable code is actually reachable from my code C Sca scanning | security-engineer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | partial | 6/10 | Cclaimed | |
Scan projects across all the major languages and package ecosystems my organization uses C Coverage | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | partial | 6/10 | Xcommunity | |
Generate a software bill of materials (SPDX or CycloneDX) for my project or image C Sbom | security-engineer | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 2 | partial | 5/10 | Cclaimed | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 5/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 5/10 | Xcommunity | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 4/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 4/10 | Tprobed | |
Have AI draft remediation pull requests for security findings that I review and merge C Ai remediation | ai-native user | Sast rules — stories about sast rules in this arenaSast rules | 2 | partial | 4/10 | Cclaimed | |
Scan Terraform, Kubernetes, and other IaC files for security misconfigurations C Iac misconfig | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 2 | partial | 3/10 | Cclaimed | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 3/10 | Cclaimed | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | 0/10 | ||
Get concrete upgrade paths or automated fix pull requests that remediate vulnerable dependencies C Dependency fixes | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | none | 0/10 | ||
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secrets C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | none | 0/10 | ||
Filter and gate on findings by severity or confidence so low-value noise does not block builds C Fp management | developer | Triage noise — stories about triage noise in this arenaTriage noise | 2 | none | untested | none yet | |
Detect the licenses of my dependencies and enforce a license policy in scans C Licenses | devops-lead | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 1 | none | 0/10 | ||
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | 0/10 |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 38 stories with headroom
What would move Semgrep’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
Evidence shows Semgrep exposes itself as an MCP server (semgrep-probe-3) so other agents can call its scanning tools, but there is no evidence that Semgrep itself can consume/plug in external MCP servers to use their tools — no client-side MCP integration is documented anywhere in the docs, CLI reference, or platform API pages.
Container scanning — stories about container scanning in this arenaScan container images for OS-package and application-layer vulnerabilities before deploying them
nonemoves PA Scoreimpact 30
The evidence pack covers Semgrep Code (SAST), Secrets, and Supply Chain (dependency/OSS SCA) scanning of source repositories, CI pipelines, and manifests, but contains no mention of scanning container images or detecting OS-package vulnerabilities inside image layers — a capability offered by dedicated container scanners.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
Evidence shows Semgrep AppSec Platform has an API for listing deployments/findings/projects, but there is no mention of scoped or least-privilege API tokens/credentials designed for agent use, nor any granular permission/role system for API keys.
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
The evidence shows Semgrep offers a CLI, a REST API for the AppSec Platform, and an MCP server, but nowhere is an official client SDK (e.g., Python/JS/Go library for programmatic integration) documented or referenced.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Evidence shows Semgrep provides a REST API for querying findings/deployments and CI-integration on push/PR events, but nothing describes a webhook subscription mechanism for events; no docs mention webhook endpoints or event-driven notifications to external systems.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Semgrep documents an AppSec Platform API (list deployments, findings, projects) but there is no evidence of an interactive API reference with runnable/try-it examples; the openapi.json/swagger probes returned 404 on all candidate paths, indicating no interactive spec-based docs.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Semgrep documents a REST API for the AppSec Platform (semgrep-docs-17/59) but a direct probe for machine-readable OpenAPI/Swagger specs at standard paths returned 404 everywhere (semgrep-probe-2), and no evidence of a published API spec exists elsewhere in the pack.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Missing: versioning scheme documentation, deprecation policy/notice process, changelog or migration guides for API changes.
Showing the top 8 of 38 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map16 surfaces · 40 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Hacker News13 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Get AI-generated insights and suggestions from my data inside the product
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- Scan projects across all the major languages and package ecosystems my organization uses
- Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling
- Scan my dependency manifests and lockfiles for packages with known vulnerabilities
- Read the product's source under an open license
- Run static analysis that finds vulnerability classes like injection and XSS in my source code
- Write custom static-analysis rules in a simple syntax and share them across repositories
- Define custom detection rules for my organization's internal token and secret formats
- Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives
GitHub README12 stories
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Self-host the core product
- Prevent my data from being used to train AI models
- Control data retention and deletion
- Opt out of telemetry and usage tracking
- Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives
- Baseline or ignore existing and false-positive findings so only new issues alert
Getting started docs11 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Use an official CLI
- Perform bulk operations across many items at once
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling
- Export all of my data in open formats and leave
- Self-host the core product
- Detect taint-style vulnerabilities that flow across files and function boundaries
- Run static analysis that finds vulnerability classes like injection and XSS in my source code
Writing rules docs11 stories
- Define rules that trigger actions automatically on events
- See scan findings surfaced as pull-request comments or checks in GitHub or GitLab
- Scan Terraform, Kubernetes, and other IaC files for security misconfigurations
- Scan projects across all the major languages and package ecosystems my organization uses
- Do everything through the API that I can do in the UI
- Have AI draft remediation pull requests for security findings that I review and merge
- Detect taint-style vulnerabilities that flow across files and function boundaries
- Run static analysis that finds vulnerability classes like injection and XSS in my source code
- Write custom static-analysis rules in a simple syntax and share them across repositories
- Apply suggested or automatic code fixes for findings instead of only reading reports
- Define custom detection rules for my organization's internal token and secret formats
For developers docs9 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Use an official CLI
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Export all of my data in open formats and leave
- Self-host the core product
- Prevent my data from being used to train AI models
- Control data retention and deletion
- Opt out of telemetry and usage tracking
Deployment docs8 stories
- Run the product headlessly / in CI for automation
- Set up automations that run autonomously in the background
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Schedule recurring jobs or workflows
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- See scan findings surfaced as pull-request comments or checks in GitHub or GitLab
- Apply suggested or automatic code fixes for findings instead of only reading reports
Semgrep code docs8 stories
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Define rules that trigger actions automatically on events
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Do everything through the API that I can do in the UI
- Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives
- Baseline or ignore existing and false-positive findings so only new issues alert
semgrep.dev8 stories
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands
- Have AI draft remediation pull requests for security findings that I review and merge
- Apply suggested or automatic code fixes for findings instead of only reading reports
- Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives
Extensions docs6 stories
- Run the product headlessly / in CI for automation
- Set up automations that run autonomously in the background
- Define rules that trigger actions automatically on events
- Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands
- Run the scanner as a pre-commit hook so secrets and issues never enter my git history
- Scan a repository and its full git history for hardcoded secrets and credentials
Semgrep appsec platform docs5 stories
Semgrep secrets docs5 stories
- See scan findings surfaced as pull-request comments or checks in GitHub or GitLab
- Have AI draft remediation pull requests for security findings that I review and merge
- Define custom detection rules for my organization's internal token and secret formats
- Scan a repository and its full git history for hardcoded secrets and credentials
- Have detected secrets verified against the issuing service so I know which ones are live
Semgrep supply chain docs4 stories
- Scan projects across all the major languages and package ecosystems my organization uses
- Scan my dependency manifests and lockfiles for packages with known vulnerabilities
- Prioritize dependency alerts by whether the vulnerable code is actually reachable from my code
- Generate a software bill of materials (SPDX or CycloneDX) for my project or image
MCP docs3 stories
OpenAPI spec2 stories
_llms docs2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$semgrep --versionreproduced$ semgrep --version 1.176.0
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
10 of 21 testable claims verified · 1 contradicted → integrity 38/100
30 distinct capability claims found in Semgrep’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
10
Verified
10
Unverified
1
Contradicted
20
Undersold
Verified (18)
“Can scan an entire codebase, repository, or folder within a monorepo for security issues”
Run static analysis that finds vulnerability classes like injection and XSS in my source codefullproof ↗
“Can export scan results to a SARIF file”
Emit scan results in machine-readable formats like JSON or SARIF for downstream toolingfullproof ↗
“Supports writing custom rules to control what Semgrep detects in repositories”
Write custom static-analysis rules in a simple syntax and share them across repositoriesfullproof ↗
“Provides a Semgrep Editor to write and test rules interactively”
Write custom static-analysis rules in a simple syntax and share them across repositoriesfullproof ↗
“AI-Powered Detection automatically identifies complex business logic flaws like IDOR and broken authorization”
Get AI-generated insights and suggestions from my data inside the productpartialproof ↗
“Dynamic Dependency Resolution builds a complete dependency inventory via manifest parsing and repository integration”
Scan my dependency manifests and lockfiles for packages with known vulnerabilitiesfullproof ↗
“Guides creating a Semgrep job in explicitly supported CI providers”
Run scans in CI on every pull request and fail the build on new findings via exit codesfullproof ↗
“Provides an API to list deployments, gather findings, and list projects on the AppSec Platform”
Drive the product through a documented public APIpartialproof ↗
“Search-pattern matching can find code matching a given pattern (e.g. 2 matches x = 1; y = x + 1)”
Write custom static-analysis rules in a simple syntax and share them across repositoriesfullproof ↗
“Official CLI command 'semgrep ci' runs a first scan of a project”
“CLI supports exporting SARIF output via 'semgrep ci --sarif --sarif-output=semgrep.sarif'”
Emit scan results in machine-readable formats like JSON or SARIF for downstream toolingfullproof ↗
“Custom rules can automate code review comments, identify secure coding violations, and scan configuration files”
Write custom static-analysis rules in a simple syntax and share them across repositoriesfullproof ↗
“Detects malicious dependencies associated with supply chain attacks”
Scan my dependency manifests and lockfiles for packages with known vulnerabilitiesfullproof ↗
“Automates scanning of repositories at development events such as push and pull/merge requests”
Run scans in CI on every pull request and fail the build on new findings via exit codesfullproof ↗
“Can be installed via pipx or uv as a CLI tool”
“'semgrep scan' command supports scanning local codebases without a Semgrep account”
Run the product headlessly / in CI for automationfullproof ↗
“Semgrep Supply Chain is an SCA tool that detects security vulnerabilities from open source dependencies”
Scan my dependency manifests and lockfiles for packages with known vulnerabilitiesfullproof ↗
“Semgrep Assistant (AI) contextually post-processes findings to reduce noise by ~20%”
Use AI to triage findings — explaining them, deduplicating, and flagging likely false positivespartialproof ↗
Unverified (10)
“Cross-file analysis detects vulnerabilities that flow across files and folders”
Detect taint-style vulnerabilities that flow across files and function boundariesfullproof ↗
“Semgrep Secrets scans code to detect exposed API keys, passwords, and other credentials”
Scan a repository and its full git history for hardcoded secrets and credentialspartialproof ↗
“Detected secrets are validated against the issuing service to confirm they are live/in-use”
Have detected secrets verified against the issuing service so I know which ones are livefullproof ↗
“Posts PR/MR comments to inform developers of valid secrets directly in their pull or merge requests”
See scan findings surfaced as pull-request comments or checks in GitHub or GitLabfullproof ↗
“Flags a vulnerability finding as reachable when a matching code pattern exists in the codebase”
Prioritize dependency alerts by whether the vulnerable code is actually reachable from my codepartialproof ↗
“Generates reports and SBOMs providing a complete inventory of open source components”
Generate a software bill of materials (SPDX or CycloneDX) for my project or imagepartialproof ↗
“Managed Scans enable bulk onboarding and scanning of repositories without requiring CI changes”
Perform bulk operations across many items at oncepartialproof ↗
“Can run as a pre-commit hook to prevent secrets and security issues from entering git history”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Custom rules can automate code review comments, identify secure coding violations, and scan configuration files”
Scan Terraform, Kubernetes, and other IaC files for security misconfigurationspartialproof ↗
“Can triage findings by sending alerts/notifications or creating tickets to track Semgrep Code findings”
Baseline or ignore existing and false-positive findings so only new issues alertpartialproof ↗
Contradicted (1)
“Analyzes code locally on your machine or build environment; code is never uploaded by default”
Choose where my data is stored (region/residency)noneproof ↗
Undersold (20)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Delegate tasks to a built-in AI assistant inside the productpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Define rules that trigger actions automatically on eventsfullproof ↗
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findingspartialproof ↗
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it landsfullproof ↗
Scan projects across all the major languages and package ecosystems my organization usespartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Read the product's source under an open licensepartialproof ↗
Prevent my data from being used to train AI modelspartialproof ↗
Have AI draft remediation pull requests for security findings that I review and mergepartialproof ↗
Apply suggested or automatic code fixes for findings instead of only reading reportspartialproof ↗
Define custom detection rules for my organization's internal token and secret formatspartialproof ↗
Claims outside our story set (2)
Real capability claims found in Semgrep’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Findings are transparent - rules and matching syntax can be inspected to understand detection”
source ↗“New Shift Program helps users migrate off legacy AppSec tools like Checkmarx or Snyk”
source ↗
Business model
Semgrep CE engine is LGPL-2.1 open source; the AppSec Platform is free for small teams and priced per contributor on paid plans, with custom enterprise agreements.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt 100% (30d, checked every 6h since Sep 8 '26)
