Connect Semgrep
Agents scan a file or snippet for security bugs and bad patterns, and read findings from Semgrep AppSec Platform; you connect by pasting a Semgrep token.
Static analysis: security bugs and bad patterns in code.
Once Semgrep is connected, an agent can run a security check on a file or code snippet you paste, scan with a named ruleset or a custom rule you describe, and pull findings from your Semgrep AppSec Platform organization. Each finding comes with its rule id and a one-line explanation of the risk.
Before you start
- A Semgrep account at semgrep.dev with an organization. The free Community plan works for scans.
- You must be an admin of that Semgrep organization: only admins can create tokens.
- You must be an owner or admin of the woble workspace.
- Semgrep calls mcp.semgrep.ai experimental, so tools may change or fail occasionally.
Connect it
- Open Marketplace, choose the Integrations tab, find Semgrep and press Add.
- In another tab sign in to Semgrep AppSec Platform and open Settings, then the Tokens tab. Check the right organization is selected at the top left.
- Press Create new token and tick the Web API scope. Agent (CI) is not needed here.
- Copy the token. Semgrep shows it once.
- Back in woble, paste it into the Semgrep token field and press Save.
- The card says Connected and the agent panel lists the Semgrep tools (security check, scan, custom rule scan, findings).
Or ask an agent
Type @ruby connect Semgrep in any chat. The same connect card appears in the conversation. Only owners and admins can complete it.
Try it
- "@atlas run a security check on this function and tell me which rules fire" (paste the code under the message).
- "@atlas list the high severity Semgrep findings from the last week for the api repo."
If it does not connect
- Findings return 404 or "not found": the token has only the Agent (CI) scope. Create a new token with Web API ticked.
- Token revoked or rotated in Settings → Tokens: press Test connection in Marketplace → Connected. If it fails, Remove and add it again with a fresh token.
- Token created in the wrong organization: findings show another org's repositories. Switch organization in Semgrep before creating the token.
Disconnect
Marketplace → Connected → Semgrep → Remove. The token is deleted from woble and agents lose the Semgrep tools immediately. Also delete the token in Semgrep under Settings → Tokens so it cannot be used elsewhere.
More in this category
GitHubRepos, issues, pull requests, Actions and code search.
LinearIssues, projects and cycles for product teams.
Jira and ConfluenceAtlassian issues, boards and pages.
SentrySearch, triage and analyse issues, traces and releases.
SupabaseTables, SQL, migrations, edge functions and logs of your projects.
Neon PostgresProjects, branches and SQL on serverless Postgres.