secure-semgrep

secure-semgrep runs Semgrep with bundled security rules for AI-agent code, shell scripts and server-side requests, plus Semgrep's maintained rule packs for the languages you use, in one command: npx secure-semgrep ./src. It needs semgrep installed and exits 1 on findings.

Install and run

npx secure-semgrep ./src                       # ai + bash rules, p/default, p/security-audit
npx secure-semgrep -L react -L node -L py .    # add packs for your stack
npx secure-semgrep -L ssrf .                   # opt in to the SSRF rules
npx secure-semgrep -e .                        # review mode: report, exit 0
npx secure-semgrep -N .                        # bundled rules only, no registry packs

Needs semgrep 1.0+ (brew install semgrep or pipx install semgrep) and bash 4+. SEMGREP_BIN overrides the semgrep on PATH.

Bundled rules

AI and agent code (rules/ai)

  • Model provider SDKs (OpenAI, Anthropic, Gemini, Cohere, Mistral, Hugging Face): hardcoded API keys, user input in the system prompt, no max-tokens limit, missing refusal, moderation or safety checks.
  • Model output passed to code execution; LangChain dangerous execution; unbounded agent loops.
  • MCP servers: command injection, credentials in responses, SSRF, tool poisoning, typosquatted tool names.
  • Claude Code settings that bypass permissions, auto-enable MCP servers or override the API URL; editor settings that point at an executable; hidden Unicode in AI config.
  • Agent hooks: wget | bash, DNS exfiltration, path traversal, sensitive-file access, unconditional allow.
  • SKILL.md files: prompt injection, data exfiltration, sensitive-file access, base64 payloads.

Shell (rules/bash)

curl | bash, curl ... | eval, IFS tampering, persistence installs and unquoted-expansion footguns.

SSRF (rules/ssrf, opt-in with -L ssrf)

A request whose URL is not a fixed string and does not pass through a guard function; a client that follows redirects automatically for such a URL; TLS verification turned off. JavaScript/TypeScript, Python and Rust. All are warnings.

Loadouts

LoadoutSemgrep config
ai, bashBundled, always on
ssrfBundled, opt-in
pyp/python
js, tsp/javascript, p/typescript
reactp/typescript + p/javascript + p/react
nodep/javascript + p/nodejs
rustp/rust
allEvery pack-based loadout

Registry packs are fetched from the Semgrep registry at scan time, so they are not vendored into the package. secure-semgrep pack -L react shows what a scan will load; secure-semgrep check validates the bundled rules.

CI

- run: pipx install semgrep
- run: npx secure-semgrep -L react -L node .

Exit codes

0 no findings, or review mode (-e); 1 findings; 2 usage error. Other codes pass through from Semgrep.

What it does not do

  • It is static analysis: it matches code patterns and does not run the code. A finding is a question, not a verdict.
  • It does not look for malware indicators such as auto-run editor tasks or disguised payloads; that is am-i-hacked's job.
  • Registry packs need network access to the Semgrep registry. Use -N for bundled rules only, and Semgrep's own --metrics option (pass it after --) to control Semgrep's telemetry.

Facts

Plain bash wrapper with zero npm runtime dependencies, MIT licensed. Source and rules: apps/secure-semgrep.