code-scanner-mcp
Code security scanner MCP server - scans secrets, dependencies, and insecure code patterns
Documentation
Code Security Scanner MCP Server
Scan your local codebase for security vulnerabilities, hardcoded secrets, and insecure coding patterns โ all from your AI assistant via MCP (Model Context Protocol).
Features
๐ Secrets Detection (24+ patterns)
- AWS Access Keys & Secret Keys
- GitHub tokens (personal, OAuth, app)
- Stripe API keys (live/test)
- Slack tokens & webhooks
- Google Cloud / Firebase credentials
- Database connection strings
- JWT tokens & private keys (RSA, DSA, EC)
- npm auth tokens, Telegram bot tokens, SendGrid API keys
- Generic API keys & password assignments
๐ฆ Dependency Vulnerability Scanning
Automatically detects and parses:
- `package.json` (npm/yarn/pnpm)
- `requirements.txt`, `Pipfile`, `pyproject.toml` (Python)
- `go.mod` (Go)
- `Cargo.toml` (Rust)
- `pom.xml`, `build.gradle` (Java)
Checks against a built-in database of 45+ CVEs across JavaScript, Python, Java, Go, and Rust ecosystems.
๐ก๏ธ Insecure Code Pattern Detection
- SQL Injection: String concatenation in queries, raw SQL builders
- XSS: innerHTML, dangerouslySetInnerHTML, v-html
- Command Injection: os.system, subprocess shell=True, eval/exec, child_process.exec
- Path Traversal: Unsanitized file paths
- Insecure Deserialization: pickle, yaml.load, marshal
- Configuration Issues: Debug mode, CORS wildcard, hardcoded JWT secrets
- Information Leakage: Stack trace exposure, directory listing
Tools
| Tool | Description |
|---|---|
| `scan_secrets` | Scan for hardcoded API keys, tokens, and passwords |
| `scan_dependencies` | Check dependencies against known vulnerability database |
| `scan_code_patterns` | Detect SQLi, XSS, command injection, and other patterns |
| `scan_file` | Comprehensive scan of a single file (secrets + code patterns) |
| `scan_directory` | Full project audit (secrets + dependencies + code patterns) |
Quick Start
Prerequisites
- Python 3.11+
- `pip install mcp pydantic`
Run with MCP Inspector
git clone https://github.com/214070779/code-scanner-mcp.git
cd code-scanner-mcp
pip install mcp pydantic
npx @modelcontextprotocol/inspector python3 server.pyConfigure in your AI Client
Add to your MCP settings:
{
"mcpServers": {
"code-scanner": {
"command": "python3",
"args": ["/path/to/code-scanner-mcp/server.py"]
}
}
}Example Usage
"Scan my project for security issues"
โ AI calls `scan_directory(path="./my-project")`
"Check this file for secrets before committing"
โ AI calls `scan_file(path="./src/config.ts")`
"Are there any vulnerable npm packages?"
โ AI calls `scan_dependencies(path=".")`
Supported Platforms
Development
# Clone and install
git clone https://github.com/214070779/code-scanner-mcp.git
cd code-scanner-mcp
pip install mcp pydantic
# Run tests
python3 -c "from server import mcp; print('OK:', list(mcp._tool_manager._tools.keys()))"
# Run with inspector
npx @modelcontextprotocol/inspector python3 server.pyLicense
MIT
Frequently asked questions
What is code-scanner-mcp?
code-scanner-mcp is Code security scanner MCP server - scans secrets, dependencies, and insecure code patterns
How do I install code-scanner-mcp?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is code-scanner-mcp open source?
Yes โ it is hosted on GitHub at https://github.com/214070779/code-scanner-mcp.
Related MCP tools
Cognee is the open-source AI memory platform for agents. Give your AI agents persistent long-term memory across sessions with a self-hosted knowledge graph engine.
Python SQL Parser and Transpiler
MCP server that interacts with Obsidian via the Obsidian rest API community plugin
Open-source meeting transcription API for Google Meet, Microsoft Teams & Zoom. Auto-join bots, real-time WebSocket transcripts, MCP server for AI agents. Self-host or use hosted SaaS.
A super light-weight embedded code search engine CLI (AST based) that just works - improves speed and efficiency for coding agent ๐ Star if you like it!
Official MiniMax Model Context Protocol (MCP) server that enables interaction with powerful Text to Speech, image generation and video generation APIs.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP