REPOGEO REPORT · LITE
semgrep/mcp
Default branch main · commit cade7825 · scanned 5/31/2026, 12:06:17 PM
GitHub: 668 stars · 56 forks
Action plan is what to do next — copy-pasteable changes prioritized by impact. Category visibility is the real GEO test: when a user asks an AI a brand-free question that should surface semgrep/mcp, does the AI actually recommend you — or your competitors? Objective checks verify the metadata signals AI engines weight first. Self-mention check detects whether AI even knows you exist by name.
Action plan — copy-paste fixes
3 prioritized changes generated by gemini-2.5-flash. Mark items done after you ship the fix.
- highabout#1Update the repository description to reflect deprecation
Why:
CURRENTA MCP server for using Semgrep to scan code for security vulnerabilities.
COPY-PASTE FIXDEPRECATED: The Semgrep MCP server has moved to the main `semgrep` repository. This repo is no longer maintained. Refer to the main `semgrep` repo for current functionality.
- hightopics#2Add 'deprecated' topic to signal repository status
Why:
CURRENTmcp, semgrep
COPY-PASTE FIXmcp, semgrep, deprecated
- mediumreadme#3Update the main README heading to include deprecation status
Why:
CURRENT# Semgrep MCP Server
COPY-PASTE FIX# DEPRECATED: Semgrep MCP Server (Moved to main semgrep repo)
Category GEO backends resolved for this scan: google/gemini-2.5-flash, deepseek/deepseek-v4-flash
Category visibility — the real GEO test
Brand-free queries asked to google/gemini-2.5-flash. Did AI recommend you, or someone else?
Same questions for every model — switch tabs to compare answers and rankings.
- Snyk Code · recommended 1×
- Semgrep · recommended 1×
- SonarQube · recommended 1×
- Checkmarx SAST · recommended 1×
- Bandit · recommended 1×
- CATEGORY QUERYLooking for a static analysis solution to identify security vulnerabilities in my projects.you: not recommendedAI recommended (in order):
- Snyk Code
- Semgrep
- SonarQube
- Checkmarx SAST
- Bandit
- ESLint
- eslint-plugin-security
- eslint-plugin-scanjs-rules
AI recommended 8 alternatives but never named semgrep/mcp. This is the gap to close.
Show full AI answer
- CATEGORY QUERYWhat are options for a centralized code security scanning service?you: not recommendedAI recommended (in order):
- Snyk
- Veracode
- Checkmarx One
- Sonatype Nexus Lifecycle
- GitLab Ultimate Security Scanners
- Tenable.io
- Mend.io
AI recommended 7 alternatives but never named semgrep/mcp. This is the gap to close.
Show full AI answer
Objective checks
Rule-based audits of metadata signals AI engines weight most.
- Metadata completenesspass
- README presencepass
Self-mention check
Does AI even know your repo exists when asked about it directly?
- Compared to common alternatives in this category, what is the core differentiator of semgrep/mcp?passAI named semgrep/mcp explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- If a team adopts semgrep/mcp in production, what risks or prerequisites should they evaluate first?passAI named semgrep/mcp explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- In one sentence, what problem does the repo semgrep/mcp solve, and who is the primary audience?passAI named semgrep/mcp explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
Embed your GEO score
Drop this badge into the README of semgrep/mcp. It auto-updates whenever the report is rescanned and links back to the latest report — easy public proof that you care about AI discoverability.
[](https://repogeo.com/en/r/semgrep/mcp)<a href="https://repogeo.com/en/r/semgrep/mcp"><img src="https://repogeo.com/badge/semgrep/mcp.svg" alt="RepoGEO" /></a>Subscribe to Pro for deep diagnoses
semgrep/mcp — Lite scans stay free; this card itemizes Pro deep limits vs Lite.
- Deep reports10 / month
- Brand-free category queries5 vs 2 in Lite
- Prioritized action items8 vs 3 in Lite