The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Gadriel AI Security Harness listing page.
Security scanning for the code Copilot writes: SAST, secrets, dependencies (SCA/SBOM), containers and configuration, including AI-specific risks like prompt injection and the OWASP LLM Top 10 — 3,000+ rules, scanned on your machine. Gadriel plugs into Copilot as an MCP server plus repository instructions, prompts, and reviewer agents.
Part of the Gadriel AI Security Harness, alongside VS Code, Claude Code, Codex, and Cursor.
Easiest — the VS Code extension. Install
Gadriel AI Security Harness
from the Marketplace. It registers the gadriel MCP server for Copilot
automatically and adds a Gadriel: Scan Repository command — no config to
edit.
Or add the MCP server yourself. The server is published to the
GitHub MCP Registry as
io.github.Gadriel-ai/gadriel, so it shows up in VS Code's MCP: Browse
Servers and Copilot Chat's @mcp search — add it in a click. To wire it
per-repo instead, drop this .vscode/mcp.json into your project (needs Node for
npx, or npm install -g gadriel):
Add the Copilot guidance (optional). Copy the .github/ directory into your
repo so Copilot knows how to use Gadriel:
| Path | What |
|---|---|
.github/copilot-instructions.md | repo-wide guidance, auto-applied |
.github/instructions/*.instructions.md | 17 topic rules, scoped by applyTo |
.github/prompts/*.prompt.md | /gadriel-scan, /gadriel-fix, /gadriel-status, … |
.github/agents/*.agent.md | 8 reviewer agents |
In Copilot Chat (agent mode), just ask: "Run a Gadriel security scan on this
repo and summarize the findings," or invoke a prompt like /gadriel-scan. The
gadriel MCP tools — validate_file, findings_for_path, fix_finding,
validate_buffer, and more — are available to Copilot directly.
gadriel MCP
server through managed MCP policy.app.gadriel.ai (a random device id — no
hostname, username, or keys); set GADRIEL_NO_ANONYMOUS_AUTH=1 to skip. See
the privacy policy.The registry listing is (re)published by .github/workflows/publish-mcp.yml
(GitHub OIDC — an org namespace can only be published from CI in a Gadriel-ai
repo). After a new gadriel npm release, bump server.json and the
.vscode/mcp.json pin, then re-run that workflow.
This repository is Apache-2.0. The gadriel scanner it runs is
proprietary, under the Gadriel terms.