AI pentester for PRs β finds exploitable bugs and hands your coding agent the fix.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Finds security bugs. Ships fixes.
Niro works like an autonomous, two-person team living in your repo β two roles with one goal: real security bugs, found and closed with proof.
Niro sets the stage first β it stands up your app (or points at a target you provide), seeds test state, and creates the users and data an attacker needs, so you skip most of the environment setup. Then the two-person team goes to work:
Most security tools hand you a backlog of maybes and walk away. Niro doesn't stop at proven findings β in fix mode it turns each into a focused pull request. You review the diffs and decide what ships.
Fixing a security bug is a relay across three teams β today's tools each cover one slice, so people stitch the rest together:
A program manager chases the handoffs, and it's never one clean pass. The pentester needs another test tenant, back to eng. A finding won't reproduce, it ping-pongs between security and dev. A fix ships, security has to re-test. Weeks pass, a dozen people touch it, and the code has already moved on.
Niro collapses that relay into one agent-driven run. Its attacker agent does the security team's job, its developer agent does the dev team's β and it automates the setup engineering used to own. You still set the scope, review the diffs, and decide what merges; Niro handles the back-and-forth in between β so three teams' effort lands in a few hours as review-ready pull requests, grouped by root cause so each is small enough to actually review.
From your project root, check the prerequisites, then install Niro and start a fix run:
niro fix opens the selected agent CLI interactively with Niro's first message
already submitted. The agent CLI applies its own sandbox and approval policy;
not every operation necessarily prompts. For an intentionally unattended run,
--autonomous grants the agent CLI full current-user host access without
approval prompts. Read the agent CLI privilege and threat
model before using it. Niro opens review-ready fix
PRs; you decide what to merge.
See Run Niro for report-only and scoped runs, supported agent CLIs, CI, and interactive developer agent workflows.
Setup done, Niro works your running app the way a real attacker would β and doesn't stop until each bug is proven:
Proven bugs are grouped by root cause into focused, review-ready PRs β one per cause, each with its own validation evidence.
AI makes code faster to ship and harder to trust. Niro is built to earn that trust back:
--autonomous and the full host authority it
grants is documented in the agent CLI threat
model.scope.yaml, enforced at the network layer.Niro Enterprise is planned separately for organization-scale governance, audit, compliance, deployment, and commercial support.
Niro Community Edition is free-of-charge, proprietary software distributed as a prebuilt binary. Source code is not provided, and "Community Edition" does not mean open source or source available. This public repository is the documentation and binary-distribution surface; it does not contain Niro product source code.
You may install and use Niro, keep backup copies, and mirror the unmodified binary inside your organization under the Niro Community Edition License Agreement. Public redistribution, resale, modification, and reverse engineering are not permitted. Third-party components remain under their own licenses; see NOTICE.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/niro)<a href="https://allmcps.com/mcp/niro"><img src="https://allmcps.com/api/badge/niro?style=directory" alt="Niro on AllMCPs" /></a>