The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Cleaner Code listing page.
AI code security scanner as a Model Context Protocol (MCP) server. Detects hidden threats in AI-generated code that traditional linters miss.
Website: codesafer.org · MCP Clients: Claude Code, Cursor, VS Code + Copilot, Cline
AI coding assistants generate code fast — but who's checking it for hidden threats?
Recent supply-chain attacks show that malicious code can hide in ways human reviewers and traditional linters routinely miss:
.cursorrules, CLAUDE.md, and other AI config filespackage.jsoneval + base64, reverse shells, packed payloadsCodeSafer scans for all of these before the code runs on your machine.
CodeSafer runs as a local MCP server. Your AI client (Claude Code, Cursor, etc.) calls its tools when reviewing or generating code, and findings are returned inline.
Hybrid detection:
Nothing leaves your machine. The AI analysis runs locally against a tokenizer server.
| Capability | Details |
|---|---|
| Invisible character detection | 30+ Unicode variants including Zero-Width Space, Mongolian Vowel Separator |
| BiDi / Trojan Source | Full CVE-2021-42574 coverage |
| Homoglyph detection | Cyrillic/Greek/Latin confusables (CVE-2021-42694) |
| Unicode steganography | Glassworm-style whitespace payloads |
| Rules file backdoors | Scans .cursorrules, CLAUDE.md, .claude/, Cursor rules |
| Dependency scanning | Typosquatting + suspicious install scripts in package.json |
| Obfuscation detection | eval + base64, reverse shells, packed payloads |
| AI deep analysis | CodeBERT transformer classifier with confidence scores |
| MCP native | 6 MCP tools, stdio transport |
| Local-first | No code uploaded — runs entirely on your machine |
CodeSafer exposes six tools to your MCP client:
| Tool | Purpose |
|---|---|
scan_file | Scan a single file for hidden malicious code patterns |
scan_directory | Recursively scan a directory across all source files |
scan_rules_file | Scan an AI configuration/rules file for prompt injection and Rules File Backdoor attacks |
check_dependencies | Check package.json for typosquatting, suspicious install scripts, and dependency risks |
ai_analyze | Deep AI analysis using the trained CodeBERT model (classifies chunks as malicious/benign with confidence) |
explain_finding | Get detailed explanation of a specific threat category, with attack scenarios and remediation |
Claude Code (~/.claude.json or project .mcp.json):
Cursor (.cursor/mcp.json):
Restart your client, and CodeSafer tools will appear in the tool picker.
Once configured, ask your AI client things like:
.cursorrules for a rules-file backdoor."src/auth.ts."The client will call the appropriate MCP tool and return findings with severity, line numbers, and remediation guidance.
CodeSafer is free to use. Static analysis (scan_file, scan_directory, scan_rules_file, check_dependencies, explain_finding) has no limits.
AI deep analysis (ai_analyze) includes 10 free runs per session. Paid plans for higher AI quotas are available at codesafer.org.
CodeSafer detects threats across 9 categories:
.cursorrules, CLAUDE.md, etc.eval + base64, packed payloads, reverse shellsISC — see the LICENSE file for details.