Semgrep is an open-source static analysis tool that uses AI to find and fix security vulnerabilities and bugs at the speed of code review. Its AI Assistant explains findings and generates fixes automatically. Used by Dropbox Figma and leading security teams to enforce coding standards.