SkillAgentSearch skills...

codeinspectus

Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.

Install / Use

claude mcp add Synvoya -- npx -y github:Synvoya/codeinspectus

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

78/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop
Cursor
OpenAI Codex

Our assessment of codeinspectus

codeinspectus scores 78/100 on our quality scale, 946th of 1,077 Security skills we index.

Its MCP Server is 59 KB long, well organised into 22 sections with 9 code examples: long enough that it reads more like full documentation than a focused instruction file, which agents can find harder to follow.

It has 47 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
21/30
Structure
20/20
Description
15/15
Adoption
7/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 26 days ago, so codeinspectus is actively maintained.
  • Our last check on 2026-09-28 found the source still online.
  • It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

codeinspectus compared with similar skills

All 4 of these similar skills score higher than codeinspectus; compare them before choosing.

SkillScoreStarsUpdatedFormat
codeinspectus (this skill)by Synvoya784726d agoMCP Server
Agent-Reachby Panniantong10089.0k17d agoCLAUDE.md
headroomby headroomlabs-ai10074.3ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md
Scraplingby D4Vinci10085.3k2d agoMCP Server

Frequently asked questions

How do I install codeinspectus?
Run claude mcp add Synvoya -- npx -y github:Synvoya/codeinspectus. The install tabs above show the steps for each supported agent.
Which AI agents does codeinspectus work with?
It is written for Claude Code, Claude Desktop, Cursor and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
Is codeinspectus safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is Apache-2.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is codeinspectus still maintained?
The repository was last updated 26 days ago, so codeinspectus is actively maintained.

CodeInspectus, by Synvoya

License: Apache 2.0 Node.js npm downloads MCP-ready Local-first No telemetry Official MCP Registry codeinspectus MCP server GitHub stars

A local-first, privacy-preserving security MCP server and CLI. Any AI coding agent (Claude Code, Cursor, Codex, Windsurf, Cline, Aider) can invoke CodeInspectus to scan AI-generated / "vibe-coded" code for real vulnerabilities, map findings to compliance frameworks as honest code-level coverage, and drive a scan → fix → rescan loop — fully on your machine, with no account and zero network egress at scan time.

CodeInspectus demo

Reproduce the V2.1 proof: the codeinspectus@2.1.0 package scans an immutable public Rich commit, finds one high-confidence GitHub Actions expression-injection pattern, applies GitHub's documented intermediate-env remediation in a temporary clone, confirms it as 1 resolved, 0 remaining, 0 introduced, 0 not rechecked, then creates and verifies sealed evidence for both states. Run the reproduction script or read the scanner-derived case study. The recorded pre-publication run used the exact V2.1 tarball; the script defaults to npm after publication. The case uses the ai scanner class to isolate stable native behavior; use a normal full scan for broad repository coverage.

If CodeInspectus is useful, star the repository so other AI-app builders can find it.

CodeInspectus orchestrates three best-in-class OSS engines behind one normalized, CWE-keyed schema, and adds its own AI-code-specific checks that generic scanners miss:

  • Opengrep — SAST / OWASP Top 10 (SARIF)
  • Gitleaks — secrets
  • Trivy — dependency CVEs (SCA), IaC misconfig, secrets, license, SBOM
  • CodeInspectus Pub — first-party, exact-version Dart/Flutter dependency matching and CycloneDX/SPDX inventory from pubspec.lock, backed by a bundled offline OSV Pub snapshot
  • CodeInspectus native checks — client-side secret/bundle exposure, Supabase RLS / inverted-auth (the CVE-2025-48757 class), prompt-injection sinks, model-produced tool arguments reaching Node, Python, or narrowly supported Go, Java, C#, PHP, Rust, and Ruby shell sinks without a visible guard, general model output reaching JavaScript eval/Function or import-proven shell-string APIs, conventional Next.js and import-proven Express admin API handlers missing visible authentication or server-side authorization, Supabase Edge Functions with explicit anonymous deployment but no request authentication or privileged-operation authorization, client-writable user_metadata authorization, and unsanitized model/user output rendered via dangerouslySetInnerHTML (XSS / LLM05), plus explicit API-boundary leaks, raw request-to-database writes, sensitive logging, and evidence-gated security-header/CSP/Referrer-Policy/Permissions-Policy/session-cookie/Supabase-CAPTCHA configuration checks. Separate first-party packs cover six narrow Flutter/Dart source failure modes and eight bounded Android/iOS repository-configuration failures, plus four React Native and two Expo framework-specific mobile failures. A bounded Python AI/API pack covers ten narrow Django, Flask, FastAPI, Starlette, Jinja, OpenAI, Anthropic, LangChain, and OS-command source failures. Separate Go, Java, and C# AI packs each contribute one exact official OpenAI SDK tool-argument-to-shell rule; the PHP pack contributes one equivalent rule for the community-maintained openai-php/client ecosystem, and the Rust pack contributes one bounded rule for the community-maintained async-openai ecosystem. A Ruby pack contributes one equivalent rule for the exact official openai gem. A Firebase configuration pack contributes three literal public-write rules for Firestore, Cloud Storage, and Realtime Database. A GitHub Actions pack contributes two workflow rules for direct untrusted-context shell interpolation and exact pull_request_target checkout-and-execute chains.

The shipped manifest contains 94 curated detections: 72 first-party native rule IDs (29 JavaScript/TypeScript, 6 Flutter/Dart, 4 Android, 4 iOS, 4 React Native, and 2 Expo, plus 10 Python AI/API, 1 Go AI, 1 Java AI, 1 C# AI, 1 PHP AI, 1 Rust AI, 1 Ruby AI, 3 Firebase configuration, 2 GitHub Actions workflow, and 2 JavaScript baseline SAST rules), 18 Opengrep-owned SAST rules, and 4 custom Gitleaks rules. All 20 Opengrep YAML rules remain physically active: the two native-owned rules reconcile exact results and fall back to Opengrep on mismatch or native unavailability. Opengrep, Gitleaks, and Trivy are optional, managed, additive engines.

CodeInspectus explains each engine's coverage, license, platform-specific size, and required action before asking permission. After approval it downloads the official, SHA-pinned engine binaries, stores them outside the npm package, and calls them as local subprocesses. It does not fork them.

Why CodeInspectus?

AI-generated apps often ship with security mistakes that generic scanners miss: exposed client-side secrets, weak Supabase auth patterns, unsafe HTML rendering, prompt-injection sinks, and risky AI/vector-store integrations.

CodeInspectus combines proven local scanners with AI-app-specific rules, then exposes the workflow through an MCP server so coding agents can scan, explain, and help fix issues before shipping.

Install

Prerequisite: Node.js ≥22. Node 24 LTS is recommended. No separate engine or Cosign installation is required. CodeInspectus can bootstrap a SHA-pinned Cosign verifier inside ~/.codeinspectus/ after approval; signature verification remains fail-closed. On Linux, the current upstream Opengrep assets require glibc. Alpine/musl remains supported for native CodeInspectus rules, Gitleaks, and Trivy, but setup marks Opengrep unavailable before any download and reports aggregate scan coverage as partial when it is selected.

The official @contentauth/c2pa-node validator is an optional peer because its upstream package downloads a platform-native binding during its own lifecycle script. Normal CodeInspectus installs do not install that peer. Install it explicitly alongside CodeInspectus when local C2PA validation is required; otherwise candidate assets report partial content_provenance coverage.

# Interactive: inspect coverage, licenses, and sizes; then approve all or choose components.
npx codeinspectus setup

# Automation after an operator has reviewed the plan:
npx codeinspectus setup --status
npx codeinspectus setup --all
npx codeinspectus setup --select opengrep,gitleaks

On a terminal, a first bare npx codeinspectus run opens this guided setup. MCP clients continue to start over piped stdio and expose codeinspectus_setup: agents must request a plan, show it, ask permission, then call install with confirm_downloads=true. Declined choices are saved so users are not repeatedly prompted; setup --reset clears them.

Setup first checks local state without network access. It downloads only missing, mismatched, or newly pinned binaries, verifies them against the immutable lockfile shipped in the npm package, and atomically installs them under ~/.codeinspectus/. It refreshes the offline Trivy vulnerability DB only when it is missing, lacks rescan provenance, or is more than seven days old. Rule-only CodeInspectus upgrades therefore download nothing. After setup, scans perform zero network I/O.

Every scan and codeinspectus_list_rules response includes structured engine_setup state: ready, repair_required, db_refresh_recommended, or unsupported_platform. MCP agents are instructed to explain non-ready state and obtain approval through codeinspectus_setup. There is no silent npm postinstall download. repair-engines remains available for advanced/manual use; the older install-engines command remains a compatibility alias.

If a Trivy DB was installed before 0.3.2, scan output tells your agent that CVE rescan tracking is not yet enabled. The agent should run npx codeinspectus repair-engines once; this re-fetches the DB through the verified install path and records its provenance. Until then, vanished CVEs conservatively report not_rechecked; current scan findings remain complete and unaffected.

Re-verify your pinned binaries any time:

npx codeinspectus verify-engines

CLI, CI, and local evidence workflows

codeinspectus scan . --format sarif --output results.sarif
codeinspectus scan . --format csv --output findings.csv
codeinspectus scan . --format sarif --output results.sarif --fail-on-severity high
codeinspectus scan . --baseline SCAN_ID --fail-on-new-severity high
codeinspectus scan . --diff origin/main --head HEAD
codeinspectus scan . --working-tree --base HEAD
codeinspectus bundle create SCAN_ID --output-dir /outside/repository/scan-results
codeinspectus bundle verify /outside/repository/scan-results
codeinspectus bulk scan /absolute/path/to/local-repositories --concurrency 2
codeinspectus history scan . --from BASE_SHA --to HEAD_SHA --since 2026-07-01 --until 2026-07-30 --max-commits 20
codeinspectus issue export SCAN_ID CI-0001 --adapter github --visibility private

Git-scoped scans retain full repository context, tag changed versus supporting-context findings, and report exact resolved revisions and explicit completeness limits. They never checkout, reset, stage, or modify the repository. See docs/GIT-SCOPED-SCANS.md.

Sealed bundles retain redacted JSON, SARIF, Markdown, coverage, provenance and an additive canonical scan record with content hashes for every artifact. Verification is mandatory before bundle export or comparison. See docs/SEALED-SCAN-BUNDLES.md.

CSV is a deterministic spreadsheet-safe projection of the canonical JSON model. It always retains an explicit scan/coverage row, even with zero findings, and neutralizes formula-triggering cells. See docs/CSV-EXPORT.md for the stable column contract.

The V2 TypeScript SDK is available from codeinspectus/sdk. It is a bounded, shell-free wrapper around the exact installed local CLI and exports versioned finding, coverage, history, baseline, triage and bundle types without duplicating scanner logic. See docs/TYPESCRIPT-SDK.md.

Bulk mode scans already-existing repositories under one explicit local parent with bounded concurrency, per-repository isolation and an atomic resumable manifest. It never clones or requires a GitHub account. See docs/BULK-SCANNING.md.

Repository-history mode is separately opt-in and requires exact revision, UTC date and commit-count bounds. It scans isolated immutable snapshots, marks shallow or truncated history partial, and never describes an old finding as current or a historical secret as active. See [docs/REPOSITORY-HISTORY.md](docs/REPOSITORY-H

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars47
CategorySecurity
Updated26d ago
Forks10

Languages

TypeScript

Trust signals

97/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info
codeinspectus — MCP Server: Install & Safety Check | SkillAgent