Labsco
Labsco/Repos/semgrep/cursor-plugin
REPO PACKAGE

semgrep cursor-plugin

COMMUNITY
semgrep · publisherFreegithub.com/semgrep/cursor-plugin
1skill
0ready to use

The single catalogued skill, setup-semgrep-plugin, installs Semgrep, authenticates it, and verifies compatibility — it is the onboarding step, not the scanner. The README says the plugin as a whole includes the MCP server, hooks, and this skill together, and that the actual work of scanning agent-generated code for vulnerabilities and returning fix recommendations is done by the server and hooks, not by anything this skill runs itself.

This is for someone using Cursor who wants agent-generated code checked against Semgrep's rules before it ships. Installing it means adding the plugin from the Cursor Plugin Marketplace first, then running the setup skill — there is no npx skills add path, and the skill assumes the rest of the plugin is already present rather than installing it.

READ THE FULL ANALYSIS

What the README does not say. It gives no license field, no version history, and no detail on what the MCP server's tools or the hooks actually check beyond the phrase "scan agent-generated code for security vulnerabilities and provide recommendations for fixing them" — no rule list, no example finding, no description of when a hook fires. That leaves this summary describing what the plugin claims to do, not what running it produces.

One more listing exists for this repository, but it is dead. A bare placeholder titled "Semgrep Skills," with no description and no content of its own, is not counted or described above.

semgrep/cursor-plugin | Labsco