mcp-server-semgrep
Version:
MCP Server for Semgrep Integration - static code analysis with AI
28 lines (27 loc) • 898 B
YAML
rules:
- id: detected-pgp-private-key-block
pattern-regex: '-----BEGIN PGP PRIVATE KEY BLOCK-----'
languages: [regex]
message: >-
Something that looks like a PGP private key block is detected. This is a potential
hardcoded secret that could be leaked if this code is committed.
Instead, remove this code block from the commit.
severity: ERROR
metadata:
cwe:
- 'CWE-798: Use of Hard-coded Credentials'
source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json
category: security
technology:
- secrets
confidence: LOW
owasp:
- A07:2021 - Identification and Authentication Failures
references:
- https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures
cwe2022-top25: true
cwe2021-top25: true
subcategory:
- audit
likelihood: LOW
impact: MEDIUM