Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Cleaner Code
Cleaner Code logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 12:50:11 PM

Cleaner Code

User RatingsBe the first to rate and review this MCP server!
View Repository1 GitHub StarsTotal stargazers on GitHub for the source repository (1 stars).Visit Website

Local MCP server scanning AI-generated code for hidden security threats using static rules and CodeBERT AI analysis.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for goldmembrane/cleaner-code, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

This MCP server detects hidden threats in AI-generated source code that traditional linters often miss. It combines eight static analysis scanners targeting known attack patterns with a CodeBERT-based deep learning model to identify obfuscated or novel malicious code. It runs locally to ensure code privacy and integrates with AI clients to provide inline security findings and remediation guidance. Use it to scan files, directories, AI config rules, and dependencies before running or deploying code.

Use cases

β€’Scan source files for invisible Unicode and Trojan Source attacks
β€’Analyze AI configuration files for rules file backdoors
β€’Check package.json dependencies for typosquatting and suspicious scripts
β€’Perform deep AI analysis to detect obfuscated or novel malicious code
β€’Explain detected security threats with remediation advice

Key features

β€’Detects 30+ invisible Unicode variants including Zero-Width Space
β€’Identifies BiDi/Trojan Source attacks (CVE-2021-42574)
β€’Finds homoglyphs using Cyrillic/Greek confusables (CVE-2021-42694)
β€’Scans for Glassworm-style Unicode steganography in whitespace
β€’Checks dependencies for typosquatting and suspicious install scripts
β€’Hybrid detection combining static analysis and CodeBERT AI classification

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Cleaner Code.

Extracted Tool Capabilities
Detects 30+ invisible Unicode variants including Zero-Width Space
Identifies BiDi/Trojan Source attacks (CVE-2021-42574)
Finds homoglyphs using Cyrillic/Greek confusables (CVE-2021-42694)
Scans for Glassworm-style Unicode steganography in whitespace
Checks dependencies for typosquatting and suspicious install scripts
Hybrid detection combining static analysis and CodeBERT AI classification

Documentation Overview

CodeSafer (cleaner-code)

AI code security scanner as a Model Context Protocol (MCP) server. Detects hidden threats in AI-generated code that traditional linters miss.

npm license: ISC Node

Website: codesafer.org Β Β·Β  MCP Clients: Claude Code, Cursor, VS Code + Copilot, Cline


Why CodeSafer?

AI coding assistants generate code fast β€” but who's checking it for hidden threats?

Recent supply-chain attacks show that malicious code can hide in ways human reviewers and traditional linters routinely miss:

  • Invisible Unicode characters injected into identifiers (30+ variants)
  • BiDi / Trojan Source attacks that reorder how code is displayed vs. executed (CVE-2021-42574)
  • Homoglyphs β€” Cyrillic characters masquerading as Latin (CVE-2021-42694)
  • Glassworm-style Unicode steganography hiding payloads in whitespace
  • Rules file backdoors planted in .cursorrules, CLAUDE.md, and other AI config files
  • Typosquatted dependencies in package.json
  • Obfuscation patterns β€” eval + base64, reverse shells, packed payloads

CodeSafer scans for all of these before the code runs on your machine.


How it works

CodeSafer runs as a local MCP server. Your AI client (Claude Code, Cursor, etc.) calls its tools when reviewing or generating code, and findings are returned inline.

Hybrid detection:

  1. 8 static analysis scanners β€” deterministic rules for known attack categories (fast, zero false-negatives on the patterns they cover).
  2. CodeBERT deep analysis β€” transformer model classifies code chunks as malicious/benign with confidence scores. Catches obfuscated or novel patterns that static rules miss.

Nothing leaves your machine. The AI analysis runs locally against a tokenizer server.


Features

CapabilityDetails
Invisible character detection30+ Unicode variants including Zero-Width Space, Mongolian Vowel Separator
BiDi / Trojan SourceFull CVE-2021-42574 coverage
Homoglyph detectionCyrillic/Greek/Latin confusables (CVE-2021-42694)
Unicode steganographyGlassworm-style whitespace payloads
Rules file backdoorsScans .cursorrules, CLAUDE.md, .claude/, Cursor rules
Dependency scanningTyposquatting + suspicious install scripts in package.json
Obfuscation detectioneval + base64, reverse shells, packed payloads
AI deep analysisCodeBERT transformer classifier with confidence scores
MCP native6 MCP tools, stdio transport
Local-firstNo code uploaded β€” runs entirely on your machine

MCP Tools

CodeSafer exposes six tools to your MCP client:

ToolPurpose
scan_fileScan a single file for hidden malicious code patterns
scan_directoryRecursively scan a directory across all source files
scan_rules_fileScan an AI configuration/rules file for prompt injection and Rules File Backdoor attacks
check_dependenciesCheck package.json for typosquatting, suspicious install scripts, and dependency risks
ai_analyzeDeep AI analysis using the trained CodeBERT model (classifies chunks as malicious/benign with confidence)
explain_findingGet detailed explanation of a specific threat category, with attack scenarios and remediation

Installation

Prerequisites

  • Node.js 18 or later
  • An MCP-compatible client (Claude Code, Cursor, VS Code + Copilot, Cline)

From source

bash
git clone https://github.com/goldmembrane/cleaner-code.git
cd cleaner-code
npm install
npm run build

Configure your MCP client

Claude Code (~/.claude.json or project .mcp.json):

config.json
{
  "mcpServers": {
    "codesafer": {
      "command": "node",
      "args": ["/absolute/path/to/cleaner-code/dist/index.js"]
    }
  }
}

Cursor (.cursor/mcp.json):

config.json
{
  "mcpServers": {
    "codesafer": {
      "command": "node",
      "args": ["/absolute/path/to/cleaner-code/dist/index.js"]
    }
  }
}

Restart your client, and CodeSafer tools will appear in the tool picker.


Usage

Once configured, ask your AI client things like:

  • "Scan this file for hidden security issues."
  • "Check the dependencies in package.json for typosquatting."
  • "Scan .cursorrules for a rules-file backdoor."
  • "Run a deep AI analysis of src/auth.ts."
  • "Explain what a Trojan Source attack is and how to fix the finding above."

The client will call the appropriate MCP tool and return findings with severity, line numbers, and remediation guidance.


Free tier & Plans

CodeSafer is free to use. Static analysis (scan_file, scan_directory, scan_rules_file, check_dependencies, explain_finding) has no limits.

AI deep analysis (ai_analyze) includes 10 free runs per session. Paid plans for higher AI quotas are available at codesafer.org.


Detection categories

CodeSafer detects threats across 9 categories:

  1. Invisible Unicode characters β€” 30+ variants including Zero-Width Space, Zero-Width Joiner
  2. BiDi / Trojan Source attacks β€” CVE-2021-42574
  3. Homoglyphs β€” Cyrillic/Greek characters masquerading as Latin (CVE-2021-42694)
  4. Unicode steganography β€” Glassworm patterns in whitespace
  5. Rules file backdoors β€” malicious instructions in .cursorrules, CLAUDE.md, etc.
  6. Dependency risks β€” typosquatting and suspicious install scripts
  7. Obfuscation patterns β€” eval + base64, packed payloads, reverse shells
  8. Static analysis findings β€” 8 deterministic scanners
  9. AI deep analysis β€” CodeBERT transformer for novel and obfuscated threats

Project structure

Code
cleaner-code/
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ index.ts           # MCP server entry point
β”‚   β”œβ”€β”€ api-server.ts      # Optional HTTP API server
β”‚   β”œβ”€β”€ types.ts           # Scanner interfaces
β”‚   β”œβ”€β”€ utils.ts           # File collection, summary formatting
β”‚   └── scanner/
β”‚       β”œβ”€β”€ invisible.ts       # Invisible Unicode scanner
β”‚       β”œβ”€β”€ bidi.ts            # BiDi / Trojan Source scanner
β”‚       β”œβ”€β”€ homoglyph.ts       # Homoglyph scanner
β”‚       β”œβ”€β”€ encoding.ts        # Encoding / charset scanner
β”‚       β”œβ”€β”€ obfuscation.ts     # Obfuscation pattern scanner
β”‚       β”œβ”€β”€ steganography.ts   # Unicode steganography scanner
β”‚       β”œβ”€β”€ rules-backdoor.ts  # Rules file backdoor scanner
β”‚       β”œβ”€β”€ dependency.ts      # Dependency risk scanner
β”‚       └── ai-analyzer.ts     # CodeBERT deep analyzer
β”œβ”€β”€ ml/                    # ML model assets and tokenizer
β”œβ”€β”€ functions/             # Cloud function deployments
β”œβ”€β”€ deploy/                # Deployment manifests
└── web/                   # Landing page assets

License

ISC β€” see the LICENSE file for details.


Links

  • Website: codesafer.org
  • Model Context Protocol: modelcontextprotocol.io
  • Report issues: GitHub Issues

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    πŸ”’ Security3 views
    Compare vs Apktool MCP Server β†’
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    πŸ”’ Security3 views
    Compare vs Jadx AI MCP β†’
  • Mobb Vibe Shield MCP logoMobb Vibe Shield MCP

    Mobb Vibe Shield identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

    πŸ”’ Security2 views
    Compare vs Mobb Vibe Shield MCP β†’
  • ModelSafetyMCP logoModelSafetyMCP

    MCP server for scanning machine learning model artifacts for unsafe serialization, malicious model patterns, risky packaging, URL-based artifact scanning, and directory-level triage using ModelScan, PickleScan, and heuristic inspection.

    πŸ”’ Security2 views
    Compare vs ModelSafetyMCP β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
1
Stargazers on the source repository.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Cleaner Code

No, all analysis runs locally on your machine; no code is uploaded.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewCleaner Code AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/goldmembrane-cleaner-code?style=directory)](https://allmcps.com/mcp/goldmembrane-cleaner-code)
HTML Embed
<a href="https://allmcps.com/mcp/goldmembrane-cleaner-code"><img src="https://allmcps.com/api/badge/goldmembrane-cleaner-code?style=directory" alt="Cleaner Code on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
Last updatedAug 7, 2026
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars1
GitHub Star CountTotal stargazers on GitHub representing community popularity (1 stars).
40Quality signal: Fair Β· 40/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools19/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Cleaner Code β†’Install in Claude DesktopInstall in CursorInstall in VS Code