Prerequisites
- A Semgrep account
- Claude Code installed (
claudecommand)
Setup (remote plugin)
Install the Guardian plugin from the Claude Marketplace:claude) to log in to Semgrep.
The plugin registers a post-tool hook so Claude Code scans every file it writes.
For Windows machines: Windows Subsystem for Linux (WSL) is required. Native Windows is unsupported.
Run Semgrep Guardian locally
The remote server is the recommended default. If you need to run Semgrep locally instead, you can install the local plugin from thesemgrep/guardian-local repo.
2
Start a Claude Code instance:
3
Open the plugin manager:
4
Go to Discover. Search for Semgrep, and then click Install.
5
Load the plugin:
What rules does this setup use?
- Remote plugin (default): scans with the fixed
guardian-defaultruleset. Rules enabled in your organization’s Policies do not apply. - Local plugin: scans with the rules enabled for your Semgrep organization through your Policies.
Next steps
- Enterprise deployment for OAuth credentials and organization-wide rollout
- Semgrep Guardian overview
- Rules and configuration