Prerequisites
- A Semgrep account
- Semgrep CLI installed and signed in
Setup
2
Create a
hooks.json file at ~/.codeium/windsurf/hooks.json and paste the following configuration:3
Restart Windsurf to apply hook configuration.
post_write_code event fires after Cascade writes or modifies any file.
What rules does this setup use?
This integration scans with the rules enabled for your Semgrep organization through your Policies. See Rules and configuration for how this differs from the Claude Code remote plugin.Next steps
- Enterprise deployment for authentication and organization-wide rollout
- Semgrep Guardian overview
- Rules and configuration