KosmoKrator

data

Semgrep MCP Gateway for AI Agents

Expose Semgrep tools to Claude Code, Cursor, Codex, and other MCP clients through the local KosmoKrator MCP gateway.

Semgrep MCP Gateway

Expose Semgrep to MCP clients with `kosmokrator mcp:serve --integration=semgrep`.

If the client has never used KosmoKrator before, install it first, then register this integration as a stdio MCP server.

Install KosmoKrator
curl -fsSL https://raw.githubusercontent.com/OpenCompanyApp/kosmokrator/main/install.sh | bash
Install gateway entry
kosmokrator mcp:gateway:install --integration=semgrep --write=deny --json
MCP configuration
{
  "mcpServers": {
    "kosmokrator-semgrep": {
      "type": "stdio",
      "command": "kosmo",
      "args": [
        "mcp:serve",
        "--integration=semgrep",
        "--write=deny"
      ]
    }
  }
}
Serve manually
kosmokrator mcp:serve --integration=semgrep --write=deny

Client Notes

Use one scoped MCP gateway entry, then adapt the config location to the client or framework.

Claude Code Connect local KosmoKrator integrations to Claude Code through one scoped MCP gateway entry. Claude Code can launch the local kosmo binary directly from the project MCP config.
Cursor Expose selected local integrations to Cursor through KosmoKrator without configuring each service as its own MCP server. Use the same KosmoKrator install and integration credentials that power terminal and headless runs.
Codex Use KosmoKrator as a local MCP proxy for Codex so coding sessions can reach selected integrations with explicit write policy. Keep write access denied or ask-based unless the workspace is trusted.
OpenAI Agents SDK Attach KosmoKrator integration tools to OpenAI Agents SDK workflows through a local MCP gateway. Use headless JSON commands for CI-style execution and MCP for agent tool discovery.
Claude Agent SDK Give Claude Agent SDK workflows access to KosmoKrator integrations through a local MCP server. Use a narrow integration list so the agent does not load unrelated tools.
Vercel AI SDK Use KosmoKrator as a local integration gateway for Vercel AI SDK agents and scripts. Prefer CLI JSON calls when a workflow only needs one deterministic integration operation.
LangChain Bridge LangChain agents to local KosmoKrator integration tools through MCP or headless CLI calls. Keep the gateway scoped to the integration and operation class needed by the chain.
LangGraph Run KosmoKrator integration calls from LangGraph nodes while preserving local credentials and permissions. Headless CLI calls fit repeatable graph edges; MCP fits exploratory agent nodes.
CrewAI Expose KosmoKrator integrations to CrewAI workers as scoped local tools. Use per-worker integration scopes to avoid giving every worker every tool.
Generic MCP Clients Connect any stdio-compatible MCP client to local KosmoKrator integration tools. Start with read-only write policy and expand only for trusted projects.

MCP Tool Names

KosmoKrator exposes integration tools through the gateway with stable names.

MCP toolSource functionType
integration__semgrep__semgrep_misc_service_get_bootstrap_sms_vpc semgrep.semgrep_misc_service_get_bootstrap_sms_vpc Read read
integration__semgrep__semgrep_deployments_service_list_deployments semgrep.semgrep_deployments_service_list_deployments Read read
integration__semgrep__semgrep_supply_chain_service_list_dependencies semgrep.semgrep_supply_chain_service_list_dependencies Write write
integration__semgrep__semgrep_supply_chain_service_list_repositories_for_dependencies semgrep.semgrep_supply_chain_service_list_repositories_for_dependencies Write write
integration__semgrep__semgrep_supply_chain_service_list_lockfiles_for_dependencies semgrep.semgrep_supply_chain_service_list_lockfiles_for_dependencies Write write
integration__semgrep__semgrep_policies_service_list_policies semgrep.semgrep_policies_service_list_policies Read read
integration__semgrep__semgrep_policies_service_list_policy_rules semgrep.semgrep_policies_service_list_policy_rules Read read
integration__semgrep__semgrep_policies_service_update_policy semgrep.semgrep_policies_service_update_policy Write write
integration__semgrep__semgrep_supply_chain_service_create_sbom_export semgrep.semgrep_supply_chain_service_create_sbom_export Write write
integration__semgrep__semgrep_supply_chain_service_get_sbom_export semgrep.semgrep_supply_chain_service_get_sbom_export Read read
integration__semgrep__semgrep_scans_service_get_scan semgrep.semgrep_scans_service_get_scan Read read
integration__semgrep__semgrep_scans_service_search_scans semgrep.semgrep_scans_service_search_scans Write write
integration__semgrep__semgrep_secrets_service_list_secrets_path semgrep.semgrep_secrets_service_list_secrets_path Read read
integration__semgrep__semgrep_ticketing_service_delete_ticket semgrep.semgrep_ticketing_service_delete_ticket Write write
integration__semgrep__semgrep_ticketing_service_link_ticket semgrep.semgrep_ticketing_service_link_ticket Write write
integration__semgrep__semgrep_ticketing_service_unlink_ticket semgrep.semgrep_ticketing_service_unlink_ticket Write write
integration__semgrep__semgrep_findings_service_list_findings semgrep.semgrep_findings_service_list_findings Read read
integration__semgrep__semgrep_projects_service_list_projects semgrep.semgrep_projects_service_list_projects Read read
integration__semgrep__semgrep_projects_service_get_project semgrep.semgrep_projects_service_get_project Read read
integration__semgrep__semgrep_projects_service_update_project semgrep.semgrep_projects_service_update_project Write write
integration__semgrep__semgrep_projects_service_delete_project semgrep.semgrep_projects_service_delete_project Write write
integration__semgrep__semgrep_projects_service_toggle_project_managed_scan semgrep.semgrep_projects_service_toggle_project_managed_scan Write write
integration__semgrep__semgrep_projects_service_add_project_tags semgrep.semgrep_projects_service_add_project_tags Write write
integration__semgrep__semgrep_projects_service_delete_project_tags semgrep.semgrep_projects_service_delete_project_tags Write write
integration__semgrep__semgrep_ticketing_service_create_ticket semgrep.semgrep_ticketing_service_create_ticket Write write
integration__semgrep__semgrep_triage_service_bulk_triage semgrep.semgrep_triage_service_bulk_triage Write write
integration__semgrep__semgrep_misc_service_ping semgrep.semgrep_misc_service_ping Read read

Write Access

Start with --write=deny for read-only MCP clients. Use --write=ask or --write=allow only when the client and workspace are trusted.