Semgrep

Scan code for security vulnerabilities and review Semgrep findings across your projects. Sign in with Semgrep to connect.

OAuthCode & CI7 tools
Tools

What Semgrep exposes.

Every tool below is one this server advertised the last time Omniio refreshed it, under the semgrep__ namespace. Your agent never loads them all — it searches, and gets the few that match.

7 tools
  • semgrep__get_abstract_syntax_tree2 arguments

    [DEPRECATED] Returns the Abstract Syntax Tree (AST) for the provided code.

  • semgrep__get_supported_languagesno arguments

    [DEPRECATED] Returns a list of supported languages by Semgrep.

  • semgrep__semgrep_findings12 arguments

    Fetches findings from the Semgrep AppSec Platform Findings API. This function retrieves security, code quality, and supply chain findings that have already been identified by previous Semgrep scans and uploaded to the Semgrep AppSec platform. It does NOT perform a new scan or analyze code directly. Instead, it queries the Semgrep API to access historical scan results for a given repository or set of repositories. DEFAULT BEHAVIOR: By default, this tool should filter by the current repository. The model should determine the current repository name and pass it in the 'repos' parameter to ensure findings are scoped to the relevant codebase. However, users may explicitly request findings from other repositories, in which case the model should respect that request. Use this function when a prompt requests a summary, list, or analysis of existing findings, such as: - "Please list the top 10 security findings and propose solutions for them." - "Show all open critical vulnerabilities in this repository." - "Summarize the most recent Semgrep scan results." - "Get findings from repository X" (explicitly requesting different repo) This function is ideal for: - Reviewing, listing, or summarizing findings from past scans. - Providing actionable insights or remediation advice based on existing scan data. Do NOT use this function to perform a new scan or check code that has not yet been analyzed by Semgrep. PRIORITY-INBOX FILTERS: The following filters narrow results to the higher-signal findings that are eligible for the priority inbox. They are exposed independently so combinations can be evaluated and tuned: - SAST: severities=['SEVERITY_CRITICAL', 'SEVERITY_HIGH'] and confidence=['CONFIDENCE_HIGH', 'CONFIDENCE_MEDIUM']; optionally source=['SOURCE_PRO'] (Pro engine only), dataflow_only=True (taint-mode only), or interfile_only=True (cross-file taint only). - SCA (supply chain): reachabilities=['REACHABILITY_REACHABLE']. - Secrets: issue_type='ISSUE_TYPE_SECRETS' with validation_states=['VALIDATION_STATE_CONFIRMED_VALID']. dataflow_only/interfile_only require an extra lookup per returned finding and are applied to the returned page after fetching, so total_findings reflects only the server-side filters.

  • semgrep__semgrep_rule_schemano arguments

    Get the schema for a Semgrep rule Use this tool when you need to: - get the schema required to write a Semgrep rule - need to see what fields are available for a Semgrep rule - verify what fields are available for a Semgrep rule - verify the syntax for a Semgrep rule is correct

  • semgrep__semgrep_scan_remote1 argument

    [DEPRECATED] Runs a Semgrep scan on provided code content.

  • semgrep__semgrep_scan_with_custom_rule2 arguments

    [DEPRECATED] Runs a Semgrep scan with a custom rule on provided code.

  • semgrep__semgrep_whoamino arguments

    Returns the identity of the current user. Use this tool when you need to get the identity of the current user.

Connecting

Three steps, and the last one is not yours.

01

Point a client at Omniio

One URL, authorized once by your client. If you already use Omniio, this step is done.

02

Switch Semgrep on

Authorize it from your library; the grant is yours and stays yours.

03

Ask for what you need

The agent searches, reads the one schema it picked, and runs it. You do not name the tool.

claude code
claude mcp add --transport http omniio https://mcp.omniio.dev
Code & CI

Others in the same category.

They share the endpoint, so having more than one on costs you nothing in context — the search decides which is relevant.

Browse the whole library