Semgrep Static Analysis
Fast, pattern-based static analysis for security scanning and custom rule creation.
MCP Tools Available
If Semgrep MCP tools are available in your environment, prefer them for scanning:
semgrep_scan— Scan code files for security vulnerabilities using built-in rulesets. Pass absolute file paths and an optional config (e.g.,p/security-audit,auto).semgrep_scan_with_custom_rule— Scan code with a custom YAML rule you've written. Pass code content inline along with the rule.semgrep_findings— Fetch existing findings from the Semgrep AppSec Platform for a repository.semgrep_rule_schema— Get the full schema for writing Semgrep rules.get_supported_languages— List all languages Semgrep supports.
When MCP tools aren't available, fall back to the CLI commands below.
When to Use Semgrep
Ideal scenarios:
- Quick security scans (minutes, not hours)
- Pattern-based bug and vulnerability detection
- Enforcing coding standards and best practices
- Finding known vulnerability patterns (OWASP, CWE)
- Creating custom detection rules for your codebase
- Data flow analysis with taint mode
Installation (CLI)
Part 1: Running Scans
Quick Scan
Using Rulesets
Output Formats
Scan Specific Paths
Configuration
.semgrepignore
Suppress False Positives
Part 2: Creating Custom Rules
When to Create Custom Rules
- Detecting project-specific vulnerability patterns
- Enforcing internal coding standards
- Building security checks for custom frameworks
- Creating taint-mode rules for data flow analysis
Approach Selection
Prioritize taint mode for injection vulnerabilities. Pattern matching alone can't distinguish between eval(user_input) (vulnerable) and eval("safe_literal") (safe).
Quick Start: Pattern Matching
Quick Start: Taint Mode
Pattern Syntax Quick Reference
Testing Rules
Test-first is mandatory. Create test files with annotations:
Run tests:
Command Reference
Rule Creation Workflow
- Analyze the problem - Understand the bug pattern, determine taint vs pattern approach
- Create test cases first - Write
ruleid:andok:annotations before the rule - Analyze AST - Run
semgrep --dump-astto understand code structure - Write the rule - Start simple, iterate
- Test until 100% pass - No "missed lines" or "incorrect lines"
- Optimize patterns - Remove redundancies only after tests pass
Output structure:
Detailed References
Official Semgrep Documentation:
- Rule Syntax - Complete YAML structure, operators, and options
- Rule Schema - Full JSON schema specification
Local References:
- Workflow Guide [blocked] - Complete step-by-step rule creation process
- Quick Reference [blocked] - Pattern operators and taint components
Anti-Patterns to Avoid
Too broad:
Missing safe cases:
Rationalizations to Reject
CI/CD Integration
GitHub Actions
Resources
Rule Writing:
- Rule Syntax: https://semgrep.dev/docs/writing-rules/rule-syntax
- Pattern Syntax: https://semgrep.dev/docs/writing-rules/pattern-syntax
- Rule Schema: https://github.com/semgrep/semgrep-interfaces/blob/main/rule_schema_v1.yaml
General:
- Registry: https://semgrep.dev/explore
- Playground: https://semgrep.dev/playground
- Docs: https://semgrep.dev/docs/
- Trail of Bits Rules: https://github.com/trailofbits/semgrep-rules


