All integrations
Semgrep logo
// Tentacle Tool · SAST

Cracken + Semgrep

Cracken runs Semgrep across your source to trace tainted input from entry point to dangerous sink. It tests whether that same path holds in the running application.

Get started
// 01

Connecting Semgrep

Connect with

Nothing for the Community (OSS) edition; a Semgrep App Token for the Pro edition, used at install time to run semgrep login

Cadence

Runs on demand — installed per Tentacle, then invoked during an operation

Requires

Linux or macOS Tentacle; a paid Semgrep plan for the Pro edition (Community edition is free)

// 02

What Cracken gets from Semgrep

  • Findings, each with a rule/check id and message

  • Severity

  • File path with start/end line

  • The matched code

  • A taint dataflow trace for taint-tracking rules

// 03

What Semgrep does not do

Static analysis only — it flags code paths but does not execute the code or confirm the flagged path is reachable at runtime; the Pro edition additionally requires a Semgrep App Token.

// 04

How Cracken uses Semgrep

  1. 01

    Install Semgrep on a Tentacle

  2. 02

    Put the code in scope on that Tentacle

  3. 03

    Test the sinks against the running app

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Does my source code leave my environment when Cracken runs Semgrep?

Semgrep scans code already on a Tentacle you control, so the repository never moves and Cracken's agent reads only the findings text.

Can Cracken use our Semgrep Pro subscription?

Yes; choosing Pro when installing Semgrep on a Tentacle asks for a Semgrep App token that signs it into your account.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Semgrep context.

See how Cracken runs Semgrep on a Tentacle you host, and proves what it finds end to end.