secure-semgrep
secure-semgrep runs Semgrep with bundled security rules for AI-agent code, shell scripts and server-side requests, plus Semgrep's maintained rule packs for the languages you use, in one command: npx secure-semgrep ./src. It needs semgrep installed and exits 1 on findings.
Install and run
npx secure-semgrep ./src # ai + bash rules, p/default, p/security-audit
npx secure-semgrep -L react -L node -L py . # add packs for your stack
npx secure-semgrep -L ssrf . # opt in to the SSRF rules
npx secure-semgrep -e . # review mode: report, exit 0
npx secure-semgrep -N . # bundled rules only, no registry packs
Needs semgrep 1.0+ (brew install semgrep or pipx install semgrep) and bash 4+. SEMGREP_BIN overrides the semgrep on PATH.
Bundled rules
AI and agent code (rules/ai)
- Model provider SDKs (OpenAI, Anthropic, Gemini, Cohere, Mistral, Hugging Face): hardcoded API keys, user input in the system prompt, no max-tokens limit, missing refusal, moderation or safety checks.
- Model output passed to code execution; LangChain dangerous execution; unbounded agent loops.
- MCP servers: command injection, credentials in responses, SSRF, tool poisoning, typosquatted tool names.
- Claude Code settings that bypass permissions, auto-enable MCP servers or override the API URL; editor settings that point at an executable; hidden Unicode in AI config.
- Agent hooks:
wget | bash, DNS exfiltration, path traversal, sensitive-file access, unconditional allow. SKILL.mdfiles: prompt injection, data exfiltration, sensitive-file access, base64 payloads.
Shell (rules/bash)
curl | bash, curl ... | eval, IFS tampering, persistence installs and unquoted-expansion footguns.
SSRF (rules/ssrf, opt-in with -L ssrf)
A request whose URL is not a fixed string and does not pass through a guard function; a client that follows redirects automatically for such a URL; TLS verification turned off. JavaScript/TypeScript, Python and Rust. All are warnings.
Loadouts
| Loadout | Semgrep config |
|---|---|
ai, bash | Bundled, always on |
ssrf | Bundled, opt-in |
py | p/python |
js, ts | p/javascript, p/typescript |
react | p/typescript + p/javascript + p/react |
node | p/javascript + p/nodejs |
rust | p/rust |
all | Every pack-based loadout |
Registry packs are fetched from the Semgrep registry at scan time, so they are not vendored into the package. secure-semgrep pack -L react shows what a scan will load; secure-semgrep check validates the bundled rules.
CI
- run: pipx install semgrep
- run: npx secure-semgrep -L react -L node .
Exit codes
0 no findings, or review mode (-e); 1 findings; 2 usage error. Other codes pass through from Semgrep.
What it does not do
- It is static analysis: it matches code patterns and does not run the code. A finding is a question, not a verdict.
- It does not look for malware indicators such as auto-run editor tasks or disguised payloads; that is am-i-hacked's job.
- Registry packs need network access to the Semgrep registry. Use
-Nfor bundled rules only, and Semgrep's own--metricsoption (pass it after--) to control Semgrep's telemetry.
Facts
Plain bash wrapper with zero npm runtime dependencies, MIT licensed. Source and rules: apps/secure-semgrep.