@mondoohq/xgrep
v0.45.0
Published
A fast, Semgrep-compatible code scanner written in Go. Supports pattern matching, taint analysis, and autofix across 20+ programming languages.
Downloads
8,690
Maintainers
Readme
@mondoohq/xgrep
A fast, Semgrep-compatible code scanner written in Go.
xgrep scans codebases using Semgrep YAML rule syntax and tree-sitter for language-aware, AST-based pattern matching. It optimizes for accuracy — when it reports a vulnerability, it should be real and exploitable — and adds code-intelligence and AI-agent features on top of scanning.
This npm package ships prebuilt xgrep binaries for Linux, macOS, and Windows
(amd64 and arm64; the macOS binaries are signed and notarized).
Install
Install globally to add the xgrep command to your PATH — the recommended way
to use it interactively:
npm install -g @mondoohq/xgrep
xgrep scan .Or add it as a project dev dependency:
npm install --save-dev @mondoohq/xgrepPrefer zero-install? Run any command below through npx @mondoohq/xgrep …
instead of xgrep … (handy for one-offs and CI). Pin a version
(@mondoohq/xgrep@<version>) for reproducible builds.
Quick start
xgrep ships with a built-in rule corpus, so no rules file is needed to get started:
# Scan the current directory with the built-in rules. `xgrep scan` with no path
# defaults to the current directory.
xgrep scan
# Choose a category (default: security, secrets)
xgrep scan --category correctness .
# Machine-readable output
xgrep scan --json .
xgrep scan --sarif . # GitHub Code Scanning
xgrep scan --gitlab -o gl-sast-report.json . # GitLab SAST
# Bring your own rules: point -f at a rule file or a directory of rules
xgrep scan -f rules.yaml src/A scan target can also be a remote git repository — xgrep clones it (shallow, default branch) into a temp directory and scans it, no manual clone needed:
xgrep scan github.com/mondoohq/xgrep # host/owner/repo shorthand
xgrep scan https://github.com/mondoohq/xgrep # or a full HTTPS/SSH URL
xgrep scan github.com/mondoohq/xgrep --ref v1.2.0 # a branch, tag, or commitAdd it to CI
Scaffold a ready-to-commit CI workflow for your provider (GitHub Actions, GitLab, or Azure Pipelines) — it installs xgrep and runs a diff-aware scan on every pull request:
xgrep ci --initAI-agent skills (Claude Code)
Claude Code skills for triaging findings, fixing them, and navigating code with the code graph are published in the mondoohq/skills marketplace. Install the ones you want:
/plugin marketplace add mondoohq/skills
/plugin install xgrep-triage@mondoohq/skillsThey also install into Codex, Gemini CLI, and Cursor — see the skills README.
xgrep fix also drives an agent directly (--agent codex, or a custom command)
if you'd rather not install the skills. See the
documentation for the full scan → triage →
fix workflow.
