Semgrep for your agents.
Connect Semgrep once and every agent you run inside Even (Claude Code, Codex, OpenCode, Even Agents) can use it: 9 curated tools, discovered on demand, with your key stored on your machine and every call going direct to Semgrep.
What agents can do with Semgrep
Curated for agents: the calls that matter, with schemas and descriptions written for tool use, not an endpoint dump.
semgrep_list_deploymentsList deployments (orgs) the token can access.
semgrep_list_projectsList projects in a deployment.
semgrep_list_findingsList findings (findings and issues) for a project. Use status and severity to filter.
semgrep_get_projectGet details for a specific project by ID.
semgrep_start_scanTrigger a new scan on a specific project.
semgrep_get_scanGet the status and results of a specific scan by ID.
semgrep_list_rulesList all rules available in a deployment.
semgrep_get_ruleGet the content and metadata of a specific rule by ID.
semgrep_list_tagsList all tags used across findings.
Connect it in a minute
The connect flow is agent-driven: Even opens the key page in its own browser and collects the key through a secure native field. It never passes through the chat.
- Paste the prompt below into any agent running inside Even, or click Connect in Even's catalog.
- Log in to Semgrep and go to Settings > Tokens.
- Click 'Create a new token', name it, and copy the resulting token.
- Paste the token.
- Paste the key into Even's secure field. Even verifies it and your agents are live.
Connect Semgrep to Even: call connect_begin("semgrep") on the even-connect MCP and walk me through it.
List security scanning projects and deployments, retrieve findings with severity filtering.
More Even Connect services
One MCP server, a handful of meta-tools, every service below. Agents search for the right tool at run time, so context stays lean.