Deterministic, zero-token security scanner your AI agent calls to find and re-verify issues.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
AI security team in a CLI. Find vulnerabilities before hackers do β free, local, no signup.
AI coding assistants write insecure code constantly β hardcoded secrets, SQL injection, missing auth. Solo developers ship it because they don't have a security team.
Scout is that team. Static analysis catches the most common mistakes AI assistants make β leaked keys, string-built SQL, shell=True, missing security headers. No API keys, no config, no cost.
Zero-install β try it in one command with uv (no venv, ~1s cold start):
Or install it permanently:
Using NCC ScoutSuite too? It also installs a
scoutcommand, and whichever package you installed last owns the name. Scout additionally installsscoutsecβ same tool, collision-proof name:scoutsec scan ./my-project.
One scan, four views β choose with --format (-f):
The same engine powers all of them β Scout finds the problem; your own AI (which already knows your codebase) applies the fix.
scout scan exits 1 when findings at or above --fail-on (default: high) exist, so your pipeline fails on real problems:
The GitHub Action wraps install + scan + SARIF upload, so findings show up as PR annotations via GitHub Code Scanning:
Prefer plain steps? The same thing by hand (the job still needs security-events: write):
Catch findings before they're ever committed:
The hook runs scout scan . --no-ai --fail-on high from your repo root on every commit, so your [tool.scout] config applies. Tune the threshold with args: ["--fail-on", "critical"]. When it fails, Scout writes security-report.md with the details β worth adding to your .gitignore.
Silence a false positive with a trailing comment on the flagged line:
Bare scout: ignore silences every finding on that line. The scoped form silences only the named scanner (secrets, injection, headers, deps, custom) or finding id (e.g. injection/eval_usage β the id field in --format json). Findings that can't carry an inline comment β the app-wide CSRF check has no meaningful line, and lockfile findings live in generated JSON β are handled by turning the scanner off via [tool.scout] scanners (below) or accepting them into a baseline (below).
Skip paths with --exclude (repeatable; relative to the scan root, globs allowed):
Or set project defaults in pyproject.toml β Scout reads [tool.scout] from the scanned project:
CLI flags win: --exclude replaces the config list, --engine replaces engines, and --fail-on overrides fail_on.
Teach Scout project-specific patterns with a YAML file β an id, a regex, a message, a severity:
Rules are deliberately grep-with-metadata β need metavariables or taint analysis? That's what --engine semgrep is for. A malformed rule warns on stderr and is skipped; it can never break the scan. Custom findings work everywhere native ones do: scout: ignore[custom], baselines, severity gating, JSON/SARIF.
Scout can orchestrate industrial OSS engines and merge their findings into its report, JSON, and SARIF output β same phased remediation plan, wider coverage:
--engine codeql runs the same query suite GitHub code scanning uses, so a Scout report can carry full semantic-analysis findings β expect it to take minutes, not seconds (database extraction is CodeQL's design, not Scout overhead).
Engines are strictly opt-in: the default scan stays zero-dependency and fully deterministic. A requested engine that isn't installed is skipped with a one-line note β never a crash. Engine findings that land on a line a native scanner already flagged are dropped in favor of Scout's own fix guidance.
scout-vscode/ wraps the CLI as a VS Code extension: saving a Python/JS/TS file scans just that file (sub-second) and shows findings as inline squiggles, with taint-traced ones marked reachable from user input. A Scout: Scan Workspace command fills the Problems panel for the whole project. It shells out to scoutsec, so your [tool.scout] config applies unchanged.
Don't want to fix years of findings before turning the CI gate on? Accept the current state, then fail only on new findings:
Commit .scout-baseline.json. Finding identity is content-based β the rule, the file, and a hash of the flagged line, deliberately no line numbers β so baselined findings stay accepted when unrelated edits shift them up or down a file. Changing the flagged line itself brings the finding back for review.
A secret committed and later removed is still compromised β a scan of today's code can't see it:
Findings are anchored to the commit that introduced them (config.py @ 1a2b3c4d5e6f) β rotate anything it reports; deleting the line doesn't un-leak the credential. Needs git on PATH; scans history instead of the working tree.
Honest scope: Gitleaks and TruffleHog do deep, fast history auditing as their core job β Scout's pass is the built-in convenience, not a replacement.
| Scanner | Detects | Severity |
|---|---|---|
secrets | AWS/Google keys, GitHub/GitLab tokens, Anthropic & OpenAI keys, Slack/npm/PyPI tokens, Stripe keys, DB URLs, private keys, passwords | CRITICAL |
injection | SQL injection, NoSQL operator injection, command injection, eval()/Function/vm, XSS | CRITICAL |
injection (taint-gated) | Path traversal (file reads/writes, sendFile), SSRF (fetch/requests/axios), insecure deserialization (pickle/yaml.load/unserialize), open redirect (redirect(...)) β fire only when user input reaches the sink | HIGH |
injection (keyword-gated) | Weak randomness for tokens/secrets (Math.random/random.* used for a token/password/OTP) | MEDIUM |
headers | Missing security headers (Express/Flask/Django/FastAPI), wildcard CORS, missing CSRF | LOWβMEDIUM |
deps | Known vulnerabilities in pip + npm dependencies (via OSV.dev) | HIGH |
Deep analysis β injection (SQL/command/XSS) and security headers β targets Python and JS/TS, where the detection patterns are idiom-specific. Both languages get intra-file taint tracking (Python via the stdlib AST, JS/TS via a lexical pass): findings carry a reachable verdict when a sink traces back to user input (request.*, req.body, location.hash, β¦), ORM/NoSQL sinks fire only on taint evidence, and XSS sinks fed by provable in-file constants are dropped instead of reported. The same taint engine powers path traversal (open/fs.readFile/sendFile), SSRF (requests/fetch/axios), insecure deserialization (pickle/yaml.load/unserialize), and open redirect (redirect(...)) detection β all gated on reachability, so open("config.json") and axios.get("https://api.example.com") never fire. Weak randomness for tokens/secrets (Math.random/random.*) is keyword-gated instead β flagged only alongside a token/password/OTP name. Secret detection is language-agnostic: it runs on every common source and config file Scout collects (Go, Java, Ruby, PHP, C/C++, Rust, shell, .env, Dockerfile, docker-compose, Terraform, β¦), so a hardcoded key is caught whatever language leaked it. Dependency scanning covers requirements.txt and package-lock.json.
Scout's injection scanner is measured against 104 real CVEs from the OpenSSF CVE Benchmark β real vulnerable commits in real JS/TS projects, no synthetic test cases. Full methodology, caveats, and reproduction steps live in benchmarks/; results are versioned per release, and this README only ever cites numbers present in a committed results file.
Honest reading of the v0.1.16 results: overall recall is 27.4% at 3.2% precision β both up release over release (16.5% / 1.3% in v0.1.9). Command injection is the standout at 41.7% recall, now edging past CodeQL's published 40% on this corpus, from recognizing child_process.exec(cmd, callback) member calls β including commands built as [a, b].join(' ') (a v0.1.16 regex-correctness fix that also stopped mis-flagging regexp.exec(), so recall and precision rose together); SQL/NoSQL injection holds at 25% (matching CodeQL) via the JS taint pass. Precision also benefits from skipping minified/bundled files β a vuln in a generated bundle is the dependency scanner's job. Adding --engine semgrep lifts overall recall further (see the semgrep results). The false-positive counts are an upper bound by benchmark convention β every unlabeled real exec()/sink call counts against Scout. These numbers are published to invite fair comparison and to be improved release over release, not to impress. For how these figures sit against CodeQL, ESLint, and published research on the same corpus, see benchmarks/COMPARISON.md.
The path-traversal + SSRF (v0.1.12) and deserialization + open-redirect + weak-randomness (v0.1.13) detectors are new vulnerability classes (CWE-22/918/502/601/330). The injection figures above are unchanged by them (verified: identical TP/FP/FN). These classes are scored separately against 39 added CVEs. Path traversal went from a 0% baseline (v0.1.13) to 46.9% recall (v0.1.14) after two first-principles broadenings β the request URL/path (req.url) joined the taint sources, and fs.stat/access/exists joined the file-path sinks β now ahead of even the semgrep pass on this class. SSRF, open redirect, and deserialization stay at an honest 0%: reading their CVE flows, the blocker is unrecognized sinks/sources (a res.setHeader('Location', β¦) redirect, a bare request({uri}) client) and taint through object literals β not function boundaries β and chasing an 11-CVE tail with that breadth would risk more false positives than it's worth. See benchmarks/COMPARISON.md.
v0.1.15 adds cross-function taint tracking for Python (intra-file): a tainted argument to a local helper now taints that helper's parameter, so a request.args value flowing through a route handler into os.system in a service function is tracked to the sink. This is a real-world win for layered Python apps that the JS-only OpenSSF corpus can't measure β like weak randomness, it stays proven by unit tests rather than a benchmark number.
The report includes:
The core scan is always static, deterministic, offline, and zero-token β same scan, same findings, no API key. That is the default and it never changes.
If you want an extra false-positive filter, Scout can optionally send only the flagged snippet (never whole files) of each heuristic finding to an AI provider, which can downgrade its severity or dismiss it as a false positive. Dependency (OSV) and project-level findings are deterministic facts and are never second-guessed. Any provider error leaves findings untouched β the pass fails open, so it can never hide a real issue.
It is off by default. Enable it per run:
Provider resolution is --model > SCOUT_AI_PROVIDER env > none. Override the model per provider with SCOUT_AI_MODEL. --no-ai forces the pass off regardless of config. Install the SDKs with pip install "scout-security[ai]" (Ollama needs no extra).
Run Scout as an MCP tool your coding agent can call in a scan β fix β rescan loop β deterministic, offline, zero-token, no inference cost. Scout finds it; your agent fixes it; Scout re-verifies.
(GitHub strips cursor:// deep links, so the Cursor badge goes via the site's one-click button.)
The one-command path β the plugin bundles the MCP server, so no separate claude mcp add is needed:
That registers the scan_path tool and a /scout-scan [path] command. Requires uv on your PATH β the plugin launches the server with uvx (first run downloads the package; later runs hit the cache). No uv? Use the manual setup below with pip install "scout-security[mcp]" and "command": "scout-mcp" instead.
Every MCP host takes the same server definition β zero-install via uv:
No uv? pip install "scout-security[mcp]", then use "command": "scout-mcp" with no args.
Where that definition goes:
| Host | Where |
|---|---|
| Claude Code | The plugin above, or claude mcp add scout -- uvx --from "scout-security[mcp]" scout-mcp |
| Cursor | .cursor/mcp.json in your project, or ~/.cursor/mcp.json for all projects |
| Claude Desktop | claude_desktop_config.json (Settings β Developer β Edit Config) |
| Cline | cline_mcp_settings.json (MCP Servers β Configure MCP Servers) |
| Windsurf | ~/.codeium/windsurf/mcp_config.json |
| VS Code (native MCP) | .vscode/mcp.json β same server object, but under a "servers" key instead of "mcpServers" |
It exposes one tool β scan_path(path) β returning the same Layer-3 JSON as --format json (findings with file, line, severity, stable id, explanation, and fix guidance). Point the agent's fix loop at it and call again to confirm the issue is gone.
The whole idea in one line: Scout finds deterministically β your AI fixes β Scout re-verifies. Same scan, same findings, zero tokens on every pass β so re-checking a fix never costs inference. Pick the surface that matches how you work; all three run the same engine.
Open security-prompts.md and paste a block into your assistant. Each one is self-contained β the finding, the fix, and an instruction to sweep the rest of your code for the same class of issue. After it edits, re-verify:
Wire up the MCP server, then hand the agent the loop:
Scan this project with Scout, fix every finding, then scan again β repeat until it reports zero.
The agent calls scan_path, applies fixes, and calls again. Scout is the deterministic, zero-token verifier inside the loop, so each re-check is free.
Turn the loop into a gate β the build fails until findings are fixed:
See Use as a CI Gate for the GitHub Action and Pre-commit Hook to catch findings before they're committed. Adopting on an existing repo? A baseline accepts today's findings and fails only on new ones.
Add one import in scout/scanners/__init__.py β done.
Full docs and interactive guide: https://varpost.github.io/Scout/
MIT β free forever.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/scout-security)<a href="https://allmcps.com/mcp/scout-security"><img src="https://allmcps.com/api/badge/scout-security?style=directory" alt="Scout Security on AllMCPs" /></a>