Semgrep Skill Review: AI Code Security Scanner for Claude Code (2026)
A. Frans
Published May 20, 2026
Table of Contents
- 01What Semgrep is
- 02Quick verdict
- 03Install
- 04What it catches in real code
- 05What it misses
- 06Where Semgrep wins vs Snyk
- 07Where Snyk wins vs Semgrep
- 08Where Trail of Bits Security wins vs Semgrep
- 09Setup pitfalls
- 10Comparison with GitHub Advanced Security
- 11Real example: shipping a fix in 11 minutes
- 12Should you install it
- 13Pricing
- 14Security note
- 15FAQ
- 16Bottom line
I installed Semgrep on a Claude Code repo with 47K lines of TypeScript and Python and ran it cold. It flagged 23 issues. Twelve were real. Eleven were noise. That's the kind of false-positive rate I can live with for an open-source static analyzer.
This review covers what the Semgrep skill does, how to install it, what it catches in practice, what it misses, and whether you should pick it over Snyk or Trail of Bits.
What Semgrep is
Semgrep is a static analysis engine that scans source code for vulnerability patterns. It's been around since 2017, and the Claude Code skill wraps the Semgrep CLI with an MCP server so Claude can read scan results, suggest fixes, and re-scan after edits.
The AI part isn't generation. Semgrep doesn't write code. It pattern-matches against 2,500+ known vulnerability rules across 30+ languages and lets Claude reason about the findings.
Quick verdict
- Use Semgrep if you want a free, language-agnostic SAST tool with a maintainable rule set
- Use Snyk if you also need dependency vulnerability scanning and you have budget
- Use Trail of Bits Security skill if you want methodology-driven code review by category (auth, crypto, input validation), not pattern scanning
These don't compete head-on. Most security-conscious teams I've seen run two of the three.
Install
The Semgrep skill installs via Claude Code's plugin marketplace:
/plugin marketplace add semgrep/semgrep-claude
/plugin install semgrep@semgrep-claude
Then from any Claude Code session in a project root:
/semgrep scan
The first scan downloads the registry rules (about 30 seconds the first time, cached after). Subsequent scans run in 10-90 seconds for a typical mid-size repo.
Configuration goes in .semgrep.yml at the repo root. Most teams I've seen start with the default p/auto ruleset and tune from there.
What it catches in real code
On my test repo (47K LOC mixed TypeScript and Python):
Caught (12 real findings):
- SQL injection via string concatenation in a Python ORM query
- 3 hardcoded API keys in test fixtures (not great, but the test database is sandboxed)
- A JWT signature verification with
algorithms=['none'](critical) - 2 React
dangerouslySetInnerHTMLcalls with unsanitized user input - 4 instances of weak crypto (MD5 for password hashing)
- 1 race condition in a Node.js file-write pattern
False positive examples (11 noise):
- 6 flags on Express CORS configuration that was correctly scoped
- 2 flags on rate-limit middleware that Semgrep didn't recognize
- 3 "potential" XSS flags on JSX where the input was already sanitized one function up
False positives are the cost of pattern-based scanning. Semgrep gives you tools to suppress them (# nosem comments, custom rules, ignore patterns), but the first cleanup pass takes 30-60 minutes on a real codebase.
What it misses
No SAST tool catches everything. After running Semgrep, I pointed Trail of Bits Security at the same repo and Trail of Bits found 3 issues Semgrep didn't:
1. A multi-step authorization flaw (multi-file logic, not a single pattern) 2. An order-of-operations bug in a token refresh flow 3. A race condition between two services that shared a database row
These are the kinds of issues that require reasoning about flow, not matching patterns. Semgrep can't reason. Claude on top of Semgrep can, sometimes, if you prompt it right ("look at the auth flow across these 4 files for ordering issues").
Where Semgrep wins vs Snyk
- Free for unlimited code scanning. Snyk's free plan caps at 200 tests per month.
- Open rule set. Anyone can write rules. There are 8,000+ community rules outside the official set.
- Faster on large repos. On 1M LOC repos, Semgrep finishes a scan 3-5x faster than Snyk Code.
Where Snyk wins vs Semgrep
- Dependency scanning is included. Semgrep only scans your source code, not third-party packages.
- IDE integration is more polished. Snyk's VS Code plugin gives better in-line feedback than Semgrep's CLI-only flow.
- Compliance reporting is built in. Snyk produces auditor-ready PDF reports. Semgrep dumps JSON.
If you have budget and need both SAST and SCA (dependency scanning), Snyk is the smaller cognitive load. If you need only source code analysis or you have a strict budget, Semgrep wins.
Where Trail of Bits Security wins vs Semgrep
- Methodology, not patterns. Trail of Bits asks "is the auth flow correct" instead of "does this match a known bad pattern."
- Lower false-positive rate on architectural issues, though worse on syntactic vulnerabilities.
- Better for security reviews of code you're considering shipping, not as a daily CI tool.
I run Semgrep in CI (every push) and the Trail of Bits Security skill before a major release. Different rhythms.
Setup pitfalls
- Default ruleset is too broad for first-time users. Start with
p/typescriptorp/pythoninstead ofp/auto. - Don't add
# nosemcomments to suppress critical findings. That's how you bury real issues. - Configure on the first run. Default scan output dumps to stdout in JSON, which is overwhelming. Use
--output-format=textfor human reading.
The skill ships with sensible defaults, but the first 30 minutes of tuning matters more than the tool choice.
Comparison with GitHub Advanced Security
If you're already paying for GitHub Enterprise, you have CodeQL via Advanced Security. The question is whether Semgrep adds anything.
In my testing on the same 47K LOC repo, CodeQL caught 9 of the 12 real findings Semgrep caught, plus 2 that Semgrep missed (both around tainted data flow through async functions). Semgrep caught 4 that CodeQL missed (mostly secret detection and config patterns).
Verdict: they're complementary. CodeQL is stronger on flow analysis. Semgrep is stronger on pattern coverage breadth and is faster to add custom rules.
If budget is a constraint, Semgrep covers most of the value for a $0 marginal cost. If you already have GitHub Advanced Security at $49/user/mo, run both. The overlap is real but the gaps are real too.
Real example: shipping a fix in 11 minutes
Last week I ran /semgrep scan on a Next.js project and got a single critical finding: a SQL injection in a dashboard search endpoint. The query used template literals to interpolate a user-controlled filter parameter into a Prisma raw query.
In Claude Code, I pasted the finding into the conversation and asked Claude to suggest a parameterized fix. Claude rewrote the query using Prisma's $queryRaw template tag (which auto-parameterizes), I tested it locally, the fix went out in a deploy 11 minutes after the scan started.
Without Semgrep, that bug would have shipped to production. The endpoint had been in the codebase for 6 months. Without Claude, the fix would have taken 30 minutes of looking up Prisma's parameterization docs. Together they shortened the loop from "vulnerability in prod" to "patched" by an order of magnitude.
That's the practical case for SAST + AI agent. Not magic, just compressed loops.
Should you install it
If you write code for a living and don't have any SAST running, install Semgrep this afternoon. The 30-second install vs the cost of one shipped SQL injection is not a close call.
If you already run another SAST tool (Snyk, Trail of Bits, GitHub Advanced Security), the marginal value of Semgrep is real but smaller. The rule sets overlap. Run it for a week, see how many new findings appear, and decide.
If you write only TypeScript and use Vercel/Next.js, Semgrep covers the framework patterns well but doesn't catch Vercel-specific deployment issues. Pair with a Vercel-specific tool if that's your stack.
Pricing
The CLI and skill are free. Semgrep AppSec Platform (the SaaS dashboard) starts at $40/month per developer. Most solo developers and small teams never need the platform. The CLI plus a CI integration covers 90% of the use case.
Security note
Static analyzers run with read access to your code, not your runtime. Lower risk than skills that touch your database or AWS account. Still worth checking: 1. The skill is installed from the official semgrep/semgrep-claude repo 2. You're not running --config=auto against repos with sensitive secrets that might get sent to a registry 3. Your CI runner doesn't ship scan output to a public endpoint
FAQ
Does Semgrep work offline? Yes, once the ruleset is cached. The first run needs internet to fetch rules.
Does it scan binaries or compiled code? No. Source only. Use a separate tool (Snyk Container or similar) for binary or container scanning.
Can I write custom rules? Yes. Rule syntax is YAML-based pattern matching. The docs walk through writing a custom rule in about 15 minutes.
Does Semgrep scan IaC (Terraform, CloudFormation)? Yes, with the p/terraform ruleset. Coverage is decent but Checkov is more thorough for IaC specifically.
Is the Claude Code skill open source? Yes. Apache 2.0. Check the repo at github.com/semgrep/semgrep-claude before installing.
How often should I run scans? On every push for CI. Locally, every 1-2 days during heavy development.
Bottom line
Semgrep is the strongest free SAST tool in 2026, and the Claude Code skill makes it accessible without leaving your editor. The false-positive rate is real but tunable. The miss rate on flow-based issues is real and not tunable. Pair Semgrep with a methodology-driven tool for those.
If you ship code to production and you don't have any static analyzer running, today is a good day to fix that.
For more security skills, see our full skill list for cybersecurity professionals.
Share this article
📄Related Articles
Get More AI Tool Guides
New comparisons and guides every week. Join thousands of professionals staying ahead of the AI curve.