
Cracken + Semgrep
Cracken runs Semgrep across your source to trace tainted input from entry point to dangerous sink. It tests whether that same path holds in the running application.
Connecting Semgrep
- Connect with
Nothing for the Community (OSS) edition; a Semgrep App Token for the Pro edition, used at install time to run semgrep login
- Cadence
Runs on demand — installed per Tentacle, then invoked during an operation
- Requires
Linux or macOS Tentacle; a paid Semgrep plan for the Pro edition (Community edition is free)
What Cracken gets from Semgrep
Findings, each with a rule/check id and message
Severity
File path with start/end line
The matched code
A taint dataflow trace for taint-tracking rules
What Semgrep does not do
Static analysis only — it flags code paths but does not execute the code or confirm the flagged path is reachable at runtime; the Pro edition additionally requires a Semgrep App Token.
How Cracken uses Semgrep
- 01
Install Semgrep on a Tentacle
- 02
Put the code in scope on that Tentacle
- 03
Test the sinks against the running app
- 04
Confirm the Tentacle is ready
Frequently asked questions
Does my source code leave my environment when Cracken runs Semgrep?
Semgrep scans code already on a Tentacle you control, so the repository never moves and Cracken's agent reads only the findings text.
Can Cracken use our Semgrep Pro subscription?
Yes; choosing Pro when installing Semgrep on a Tentacle asks for a Semgrep App token that signs it into your account.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
Attack with real Semgrep context.
See how Cracken runs Semgrep on a Tentacle you host, and proves what it finds end to end.





