Semgrep Cursor Plugin

May 7, 2026 ยท View on GitHub

This repo is where the Semgrep Cursor Plugin lives. The Semgrep Plugin includes a MCP server, hooks, and skills, which are used to scan agent-generated code for security vulnerabilities and provide recommendations for fixing them.

To use the Semgrep plugin:

  1. Install the plugin from the Cursor Plugin Marketplace

  2. Run the /setup-semgrep-plugin skill.