Agent Plugins Marketplace
All plugins

semgrep

v1.0.0-ghast.1

Analyze code and investigate security findings with the MCP server built into the official Semgrep CLI.

Agent Plugins1 Skill1 MCP serverstdio

By Ghast AILicense: MIT0 GitHub starsUpdated 2 weeks ago

Directory evidence

Runtimes
Agent Plugins
Parsed components
2 skill or MCP entries
Source updated
Sep 8, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology

Get the plugin

git clone https://github.com/Trapezohe/ghast-plugins

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/semgrep/.

This listing currently publishes only the generic Agent Plugins format. Automatic install commands for other clients are not generated yet.

Plugin files

plugins/semgrep/
├── plugin.json
├── skills/semgrep/SKILL.md
└── mcp.json

Included Skills1

semgrepskills/semgrep/SKILL.md

Use Semgrep in Ghast. Analyze code and investigate security findings with the MCP server built into the official Semgrep CLI. 通过 Semgrep 官方 CLI 内置 MCP 分析代码并排查安全发现。

MCP servers1

semgrepstdio
command
uvx
args
--python 3.12 semgrep==1.176.1 mcp

Plugin manifests1

plugins/semgrep/plugin.json
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "semgrep",
  "version": "1.0.0-ghast.1",
  "description": "Analyze code and investigate security findings with the MCP server built into the official Semgrep CLI.",
  "author": {
    "name": "Ghast AI",
    "url": "https://ghast.trapezohe.ai"
  },
  "homepage": "https://github.com/semgrep/semgrep/tree/develop/cli/src/semgrep/mcp",
  "license": "MIT",
  "extensions": {
    "ai.trapezohe.ghast": {
      "officialConnectorSource": "https://github.com/semgrep/semgrep/tree/develop/cli/src/semgrep/mcp",
      "connectorPublisher": "Semgrep",
      "category": "developer-tools",
      "icon": "./assets/icon.svg",
      "displayName": "Semgrep",
      "descriptions": {
        "en": "Analyze code and investigate security findings with the MCP server built into the official Semgrep CLI.",
        "zh-CN": "通过 Semgrep 官方 CLI 内置 MCP 分析代码并排查安全发现。"
      },
      "mcpServerExtensions": {
        "semgrep": {
          "credentialEnv": {
            "SEMGREP_APP_TOKEN": "$VAULT:semgrep-token"
          }
        }
      }
    }
  }
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[semgrep on Agent Plugins Marketplace](https://pluginsmp.com/plugins/semgrep)