This repo is where the Semgrep Cursor Plugin lives. The Semgrep Plugin includes a MCP server, hooks, and skills, which are used to scan agent-generated code for security vulnerabilities and provide recommendations for fixing them.
To use the Semgrep plugin:
-
Install the plugin from the Cursor Plugin Marketplace
-
Run the
/setup-semgrep-pluginskill.
This plugin is managed by the mcp-marketplace-template repository. Changes should be made there and synced via automated PRs.