Directory / Semgrep
Semgrep
Verified
Fast static analysis you can teach, including AI-assisted rules.
Semgrep is a static analysis engine: pattern rules, a registry, CI integration, and a commercial app. It is a deterministic verification layer that agents can also write rules for. That combination is why it belongs here.
- Model independence
- Multi-model
- Deployment
- Cloud, Self-hosted
- Open source
- Yes
- License
- LGPL-2.1 (engine); Semgrep App is commercial
- Pricing model
- Mixed
- Added / updated
- 19 Aug 2026 / 19 Aug 2026
semgrep.dev · Docs · Source
Editorial take
Semgrep is the gate that does not need a judge model. Agents love to “fix” findings by deleting the rule — protect the config. The open engine is the listing; Team/Enterprise app is extra.
Strengths
- Deterministic, fast, CI-native analysis.
- Open engine you can run offline.
- Rules can encode factory invariants the LLM must not violate.
Limitations
- Not an agent. Will not implement the feature.
- App vs OSS feature split.
- Rule quality is still engineering work.