Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Guardvibe
Guardvibe logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 6:31:45 PM

Guardvibe

User RatingsBe the first to rate and review this MCP server!
View Repository5 GitHub StarsTotal stargazers on GitHub for the source repository (5 stars).Visit Website

Local security MCP scanning AI-generated web app code with 460+ rules, cross-file analysis, CVE detection, auto-fix, and pre-commit hooks.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "goklab-guardvibe": {
      "command": "npx",
      "args": [
        "-y",
        "guardvibe"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (39) Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

This security MCP provides deterministic, comprehensive analysis of AI-generated code for modern web stacks like Next.js, Supabase, Clerk, Stripe, and Prisma. It detects vulnerabilities including those published after an AI model's training cutoff by daily updating CVE rules. It performs cross-file taint and authorization coverage analysis, offers auto-fix suggestions, and integrates with developer workflows via pre-commit hooks and CI/CD SARIF exports. Use it to ensure AI-assisted code is secure during development and before deployment.

Use cases

β€’Scan AI-generated web app code for security vulnerabilities
β€’Detect vulnerable dependencies with up-to-date CVE intelligence
β€’Perform cross-file taint and authorization coverage analysis
β€’Automatically suggest and apply security fixes to code
β€’Block insecure code commits with pre-commit hooks

Key features

β€’462 security rules and 39 tools tailored for AI-generated code
β€’Daily CVE rule updates from GHSA, OSV.dev, and CISA KEV
β€’Cross-file taint analysis and auth coverage across routes
β€’Auto-fix tool returning concrete code patches
β€’Pre-commit hook and CI/CD integration with SARIF export
β€’Runs 100% locally with zero configuration and no cloud dependency

Capabilities & Tool Schemas (39) ~1.0k tokensApproximate context cost of this server’s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server β€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by Guardvibe.

check_code

Analyze a code snippet for security issues

check_project

Scan multiple files with security scoring (A-F)

scan_directory

Scan a project directory from disk

scan_staged

Pre-commit scan of git-staged files β€” **diff-aware** (blocks only newly-staged lines; `diff_aware:false` for whole files)

scan_dependencies

Check all dependencies for known CVEs (OSV) β€” annotates each vulnerable package with **reachability** (is it actually imported in your source?)

scan_secrets

Detect leaked secrets, API keys, tokens

Documentation Overview

GuardVibe

npm version License: Apache-2.0 Node.js CI npm provenance codecov

Security infrastructure your AI can't be. No matter how good your coding agent gets, it can't know the CVE published after its training cutoff, it can't deterministically guarantee the same check every run, it can't hold your whole repo in context, and it can't objectively review its own code. GuardVibe does all four β€” the deterministic, post-cutoff-current, whole-repo, author-independent verification layer for AI-written code.

  • πŸ—“οΈ Knows what your AI doesn't. CVE rules refreshed daily from GHSA / OSV.dev / CISA KEV β€” GuardVibe flags vulnerable dependencies published after your model's training cutoff. (93 CVE rules, npm run intel daily triage.)
  • 🎯 Deterministic, not probabilistic. Same code = same result, every run (content-hashed). Your AI guesses; GuardVibe doesn't.
  • πŸ—ΊοΈ Sees the whole repo. Cross-file taint + auth-coverage across every route β€” catches the unprotected endpoint your agent's narrow context missed.
  • πŸ” An independent second pair of eyes. The thing that wrote the code can't review itself. GuardVibe is the outside checker on AI-written code β€” in the loop while your AI codes (real-time edit hook), not after.
  • ⬅️ NEW: Starts before the first line of code. Every scanner on earth β€” including your agent reviewing itself β€” acts after the code exists. secure_prompt acts before: it analyzes the coding prompt itself, detects the stack and attack surfaces it implies, and embeds severity-ranked GuardVibe requirements into the prompt your AI executes. The vulnerability is prevented, not caught. Deterministic, zero LLM calls β€” and if the prompt is already secure, it passes through untouched.

The security MCP built for vibe coding. 468 security rules, 39 tools covering the entire AI-generated code journey β€” from the prompt itself to production deployment.

Works with Claude Code, Cursor, Gemini CLI, Codex, VS Code (Copilot), Windsurf, and any MCP-compatible coding agent.

Why a tool, when your AI is so good?

"More rules" was never the moat β€” a strong model already knows most security rules by heart. What it can't do is be deterministic, know the CVE published after its training cutoff, hold your whole repo in context, or objectively review the code it just wrote. Those four gaps are structural; they don't close as models improve. GuardVibe is the layer that fills them β€” running while your AI codes, not in a separate audit later. And since v3.19, it runs before your AI codes too: secure_prompt rewrites the task itself so the security requirements are in the prompt, not in the post-mortem.

Why GuardVibe

Most security tools are built for enterprise security teams. GuardVibe is built for you β€” the developer using AI to build and ship web apps fast.

  • 468 security rules, 39 tools purpose-built for the stacks AI agents generate
  • Zero setup friction β€” npx guardvibe and you're scanning
  • No account required β€” runs 100% locally, no API keys, no cloud
  • Understands your stack β€” not generic SAST, but rules that know Next.js, Supabase, Stripe, Clerk, and the tools you actually use
  • CVE version intelligence β€” detects 93 known vulnerable package versions in package.json, refreshed every day from GHSA / OSV.dev / CISA KEV
  • AI agent & MCP security β€” detects MCP server vulnerabilities, tool-description prompt injection (OWASP MCP Top 10), model-controlled sandbox-disable flags, excessive AI permissions, indirect prompt injection
  • Auto-fix suggestions β€” fix_code tool returns concrete patches and structured edits the AI agent can apply mechanically. Coverage: hardcoded credentials β†’ env-var migration; public-prefix LLM keys (NEXT_PUBLIC_/VITE_/EXPO_PUBLIC_/REACT_APP_) β†’ prefix removal; CORS wildcards β†’ env allowlist; dangerouslyAllowBrowser flags β†’ drop; sandbox bypass flags (unsafe/noSandbox/allowEval) β†’ drop; agent loops β†’ add maxSteps; raw-HTML React props β†’ <ReactMarkdown>; missing auth checks β†’ insert auth guard; SQL injection β†’ parameterized queries; missing rate limiters / CSRF / security headers β†’ snippet templates.
  • Pre-commit hook β€” block insecure code before it reaches your repo
  • CI/CD ready β€” GitHub Actions workflow with SARIF upload to Security tab
  • Agent-friendly output β€” JSON format for AI agents, Markdown for humans, SARIF for CI/CD
  • Plugin system β€” extend with community or premium rule packs

New in v3.1.x

  • Daily threat-intel pipeline β€” rule set tracks GHSA / OSV.dev / CISA KEV every day. Latest shipments (v3.1.24 β†’ v3.1.26) added VG1069 node-ipc protestware detection, VG1070 CI npm provenance / --ignore-scripts hardening, VG1071 axios proxy-auth redirect credential leak, VG1072 hono setCookie attribute injection, VG1073 drizzle sql.raw interpolation, VG1074 Miasma @redhat-cloud-services namespace compromise IOC (RHSB-2026-006), and VG1075 Session messenger exfil endpoint IOC (filev2.getsession.org). The hono override floor is pinned to ^4.12.21. Earlier in the v3.1.2x line: Next.js May 2026 13-advisory cluster, Drizzle ORM SQL identifier injection (CVE-2026-39356), Clerk clerkFrontendApiProxy SSRF (CVE-2026-34076), tRPC experimental_nextAppDirCaller prototype pollution (CVE-2025-68130), MikroORM SQL injection, angular-expressions filter RCE, @tanstack/* Mini Shai-Hulud supply-chain attack, Kysely JSON-path traversal, @nyariv/sandboxjs sandbox escape, OpenClaude dangerouslyDisableSandbox model-controlled flag, Strapi content-type builder SQL injection, LangSmith untrusted prompt-manifest deserialization, and more
  • OWASP MCP Top 10 alignment β€” VG1068 flags MCP / AI tool definitions whose description, instructions, or systemPrompt fields carry prompt-injection markers (ignore previous instructions, you are now, jailbreak mode, system prompt:, override safety, …); pair with VG1063 which catches dangerouslyDisableSandbox: true in agent runtimes
  • Inline suppress β€” // guardvibe-ignore VG001 silences individual findings per-line
  • CLI-first approach β€” npx guardvibe audit, npx guardvibe scan, npx guardvibe doctor all work standalone without MCP
  • Embedded remediation plan β€” remediation_plan generates a section-by-section fix checklist after every audit
  • Score reflects all sections β€” security score now factors code, dependencies, config, secrets, auth coverage, and taint analysis
  • Gitignored secrets excluded β€” files matched by .gitignore are automatically skipped during secret scanning
  • Taint sanitizer recognition β€” dataflow analysis recognizes common sanitizers (DOMPurify, escape functions, parameterized queries) and stops propagation

How GuardVibe Compares

GuardVibe is purpose-built for the AI coding workflow. Traditional tools are excellent for enterprise CI/CD pipelines β€” GuardVibe fills a different gap.

CapabilityGuardVibeTraditional SASTDependency Scanners
Runs inside AI agents (MCP)NativeNot supportedNot supported
Zero config setupnpx guardvibeAccount + config requiredBuilt-in (limited)
Vibecoding stack rules (Next.js, Supabase, Clerk, tRPC, Hono)100+ dedicatedGeneric patternsNot applicable
AI/LLM security (prompt injection, MCP, tool abuse)68 rulesExperimental/NoneNone
AI host security (CVE-2025-59536, CVE-2026-21852)guardvibe doctorNot supportedNot supported
Auto-fix suggestions for AI agentsfix_code toolCLI autofixNot supported
CVE version detection93 packages, refreshed dailyExtensiveExtensive
Compliance mapping (SOC2, PCI-DSS, HIPAA)Built-inPaid tierNone
SARIF CI/CD exportYesYesLimited
Rule count468 (focused, 68 AI-native)5000+ (broad)N/A

When to use GuardVibe: You're building with AI agents and want security scanning integrated into your coding workflow β€” no dashboard, no account, no CI setup.

When to use traditional tools: You need deep AST analysis, enterprise dashboards, org-wide policy enforcement, or coverage across hundreds of languages.

Quick Start

Claude Code

Terminal
npx guardvibe init claude

Creates .mcp.json MCP config (pinned to current version), .claude/settings.json auto-scan hooks, and CLAUDE.md security rules. Restart Claude Code after setup.

Cursor

Terminal
npx guardvibe init cursor

Creates .cursor/mcp.json and .cursorrules with security rules. Restart Cursor after setup.

Gemini CLI

Terminal
npx guardvibe init gemini

Creates ~/.gemini/settings.json MCP config and GEMINI.md security rules.

Codex (OpenAI)

bash
codex mcp add guardvibe -- npx -y guardvibe

VS Code (GitHub Copilot)

Create .vscode/mcp.json in your project:

config.json
{
  "servers": {
    "guardvibe": {
      "command": "npx",
      "args": ["-y", "guardvibe"]
    }
  }
}

Note: VS Code uses "servers", not "mcpServers".

Windsurf

Add to ~/.codeium/windsurf/mcp_config.json:

config.json
{
  "mcpServers": {
    "guardvibe": {
      "command": "npx",
      "args": ["-y", "guardvibe"]
    }
  }
}

All platforms at once

Terminal
npx guardvibe init all       # Claude + Cursor + Gemini

Pre-commit hook

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Sast MCP Server logoSast MCP Server

    SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scan→patch→re-scan→verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira).

    πŸ”’ Security2 views
    Compare vs Sast MCP Server β†’
  • MCP Shield logoMCP Shield

    Security scanner for MCP servers. Detects backdoors, exfiltration code, obfuscation, dangerous code execution, prompt injection, and supply chain risks before you install. Four tools: scan npm packages, scan local directories, check prompt injection, and audit supply chain trust score. npx @muhannad-hash/mcp-shield

    πŸ”’ Security2 views
    Compare vs MCP Shield β†’
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    πŸ”’ Security3 views
    Compare vs Jadx AI MCP β†’
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    πŸ”’ Security2 views
    Compare vs Agentward β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
5
Stargazers on the source repository.
npm downloads
1.7k
Package downloads in the last 30 days.
Last commit
29d ago
Most recent push to the default branch.
Tools exposed
39
Callable tools this server registers over MCP.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Guardvibe

GuardVibe runs 100% locally with zero configuration; however, daily CVE rule updates require internet access when running the update command.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewGuardvibe AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/goklab-guardvibe?style=directory)](https://allmcps.com/mcp/goklab-guardvibe)
HTML Embed
<a href="https://allmcps.com/mcp/goklab-guardvibe"><img src="https://allmcps.com/api/badge/goklab-guardvibe?style=directory" alt="Guardvibe on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedAug 14, 2026
11/11 checks healthy over the last 34d
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars5
GitHub Star CountTotal stargazers on GitHub representing community popularity (5 stars).
Last commit29d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Aug 14, 2026
npm downloads1,719/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
63Quality signal: Good Β· 63/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools28/30
Adoption & activity9/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 28d ago via OSV.dev Β· guardvibe (npm)

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Guardvibe β†’Install in Claude DesktopInstall in CursorInstall in VS Code