agentic-semgrep-rules
Semgrep rules for AI agent code in Python, TypeScript and JavaScript.
What it is
Semgrep rules for AI agent code: static analysis for LLM applications in Python, TypeScript and JavaScript that finds model output flowing into exec, shells, SQL, URLs, file paths and HTML (eval of model output, SSRF through tool URLs), user input written into system prompts, tools that let the model run anything, MCP server security checks (HTTP transports without authentication, servers bound to every interface), leaked provider keys, and unsafe model or config loading. For teams that ship LLM agents, MCP servers and tool-using assistants and want these mistakes caught in a pull request rather than found in an incident.
36 rules (23 Python, 13 TypeScript/JavaScript), every one with a tested fixture, CWE and OWASP LLM Top 10 (2025) mapping, and a message that says what is wrong and how to fix it.
pip install semgrep
semgrep --config https://raw.githubusercontent.com/basitalisandhu/agentic-semgrep-rules/main/agentic-semgrep-rules.yaml .
Install
pip install semgrep
# the single-file bundle, straight from GitHub (Semgrep accepts a URL only for a single file)
semgrep --config https://raw.githubusercontent.com/basitalisandhu/agentic-semgrep-rules/main/agentic-semgrep-rules.yaml .
# or the rules directory from a clone
git clone https://github.com/basitalisandhu/agentic-semgrep-rules
semgrep --config agentic-semgrep-rules/rules .
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, agentic-ai, ai-agents, ai-security, code-scanning, devsecops, github-actions, hacktoberfest, llm-security, mcp, owasp, prompt-injection, sast, security-automation, security-tools, semgrep, semgrep-rules, ssrf, static-analysis