Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Codeinspectus
Codeinspectus logo
Health: ActiveRecent health check succeeded.Last checked 9/7/2026, 9:00:21 PM

Codeinspectus

User RatingsBe the first to rate and review this MCP server!
View Repository45 GitHub StarsTotal stargazers on GitHub for the source repository (45 stars).Visit Website
securitydeveloper-toolssastsbomai-code

Local MCP security scanner for AI-generated JavaScript and TypeScript with offline SAST, secrets, SCA, and AI-specific checks.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

This server is confirmed live β€” we successfully called its tools/list endpoint directly (see the verified badge above). We haven't yet sandbox-tested the stdio install command below specifically, which is a separate, ongoing check.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "synvoya-codeinspectus": {
      "command": "npx",
      "args": [
        "-y",
        "codeinspectus"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (6) Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

Synvoya/codeinspectus MCP server scans local repositories for security issues in AI-generated JavaScript and TypeScript code. It combines Opengrep, Gitleaks, Trivy, an offline Pub dependency scanner, and native detectors behind MCP tools that return CWE-keyed findings. Scans, rescans, explanations, compliance views, and SBOM generation run locally, with zero network egress during scanning and no repository modifications. Reach for it when an AI coding workflow needs repeatable security checks and fix verification before deployment.

Use cases

β€’Scan AI-generated JavaScript or TypeScript before deployment
β€’Rescan a repository to verify security fixes
β€’Explain a finding and produce remediation steps
β€’Generate a CycloneDX or SPDX software bill of materials
β€’Map scan findings to code-visible compliance controls

Key features

β€’Offline local scanning with zero scan-time network egress
β€’CWE-keyed findings across multiple security engines
β€’AI-code-specific native detectors
β€’Scan-to-fix-to-rescan comparison workflow
β€’CycloneDX and SPDX SBOM generation
β€’Framework-specific code-level coverage reports

Capabilities & Tool Schemas (6) ~1.4k tokensApproximate context cost of this server’s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Verified live Verified liveCaptured by calling this server’s live tools/list endpoint.

Inspect callable tools, capabilities, and parameters exposed to AI agents by Codeinspectus.

codeinspectus_scan

Run a full local security scan of a path: bundled engines (Opengrep SAST, Gitleaks secrets, Trivy SCA/IaC/license), CodeInspectus's offline native Pub SCA, plus AI-code-specific checks (client-side secret exposure, Supabase RLS/inverted-auth, prompt-injection sinks, API-boundary failures, and explicit runtime-control misconfiguration). Returns CWE-keyed findings with fix recommendations, detected repository technologies, explicit native-pack execution counts, compliance tags, and three-state repository evidence for supported runtime controls. Fully offline β€” zero network egress at scan time. Never writes to your code or repo.

codeinspectus_rescan

Re-run a scan after fixes were applied and diff against a prior scan_id (or the most recent scan of the same path). Reports which findings are resolved, which remain, and which were newly introduced, plus fresh technology and native-pack execution coverage. Use this to verify fixes. Never writes to your code or repo.

codeinspectus_compliance_report

Produce a per-framework code-level control-coverage view for a prior scan (NIST CSF 2.0, ISO 27001:2022, SOC 2, CIS v8.1, Essential Eight, OWASP Web/LLM). Reports 'X of N code-visible controls have findings' with the code-visible subset as the explicit denominator. This is NOT a compliance audit, certification, or attestation β€” code-level evidence only.

codeinspectus_explain_finding

Return a deep explanation and full remediation plan for a single finding id from a prior scan: what the weakness is, why it matters, concrete fix steps, and references.

codeinspectus_generate_sbom

Generate a CycloneDX or SPDX SBOM for the target project using Trivy plus the first-party offline Pub lockfile inventory, with native Pub fallback when Trivy is unavailable. Writes the SBOM file to the chosen output path and returns its location and component count. Offline.

codeinspectus_list_rules

List the active detectors and engine versions, the CodeInspectus detection-database version and date, Trivy vulnerability-DB freshness, bundled Pub advisory-database provenance/freshness, and the custom CodeInspectus AI-code rules and native detector packs currently shipped.

How Codeinspectus works

What Synvoya/codeinspectus MCP server does

Synvoya/codeinspectus MCP server provides a local security-scanning workflow for repositories, with particular coverage for AI-generated and β€œvibe-coded” applications. It normalizes results from Opengrep SAST, Gitleaks secret detection, Trivy dependency/IaC/license analysis, and a first-party offline Pub inventory into CWE-keyed findings. Native checks add coverage for issues such as client-side secrets, Supabase authorization and row-level security patterns, prompt-injection sinks, unsafe model output handling, API-boundary failures, and selected runtime-control configuration gaps.

The server does not modify source files or repositories. Scan output can include remediation recommendations, detected technologies, engine execution counts, compliance tags, and evidence states for supported runtime controls.

How it works

The main workflow is scan, fix, and rescan. codeinspectus_scan analyzes a path and returns the current findings. codeinspectus_rescan compares a later scan with a previous scan ID, or with the latest scan for the same path, and identifies resolved, persistent, newly introduced, and not-rechecked findings. This makes Synvoya/codeinspectus MCP server suitable for checking whether an agent’s proposed remediation actually changed the security result.

codeinspectus_explain_finding expands one finding into an explanation, impact description, concrete remediation steps, and references. codeinspectus_compliance_report maps a prior scan to code-visible controls in NIST CSF 2.0, ISO 27001:2022, SOC 2, CIS v8.1, Essential Eight, and OWASP Web/LLM frameworks. These reports describe code-level coverage only; they are not audits, certifications, or attestations.

codeinspectus_generate_sbom writes a CycloneDX or SPDX SBOM to a selected output path using Trivy and the offline Pub lockfile inventory. codeinspectus_list_rules reports active detectors, engine versions, database freshness, and shipped native rule packs.

Setup and configuration

Node.js 22 or newer is required, with Node 24 LTS recommended. The package is available as codeinspectus on npm. Initial setup can inspect available components and obtain approval before downloading the optional managed engine binaries. Those binaries are SHA-pinned, verified, and stored under ~/.codeinspectus/, outside the npm package. Setup can also refresh the offline Trivy vulnerability database when it is missing or older than seven days.

After setup, scans perform no network I/O. Opengrep requires glibc on Linux; Alpine/musl can still use the native rules, Gitleaks, and Trivy, but Opengrep may be marked unavailable and overall coverage may be partial. MCP clients communicate with the server over piped stdio. Setup state is exposed in responses so an agent can identify missing, repair-required, stale, or unsupported components.

Tools and capabilities

The Synvoya/codeinspectus MCP server includes:

  • Full local scans covering SAST, secrets, dependencies, IaC, licenses, native Pub analysis, and AI-code-specific detectors.
  • Differential rescans for validating fixes and detecting regressions.
  • Detailed finding explanations with remediation guidance and references.
  • Code-level framework control coverage reports.
  • CycloneDX or SPDX SBOM generation with component counts and an output location.
  • Rule, engine, and database status inspection.

The shipped manifest contains 94 curated detections, including JavaScript/TypeScript, Flutter/Dart, mobile, Python, Go, Java, C#, PHP, Rust, Ruby, Firebase, and GitHub Actions coverage. Exact language and framework coverage is bounded by the native packs and rules shipped with the installed version.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • MCP Security Audit logoMCP Security Audit

    A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

    πŸ”’ Security4 views
    Compare vs MCP Security Audit β†’
  • Mobb Vibe Shield MCP logoMobb Vibe Shield MCP

    Mobb Vibe Shield identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

    πŸ”’ Security2 views
    Compare vs Mobb Vibe Shield MCP β†’
  • Depguard logoDepguard

    Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies β€” the SBOM serializer is implemented natively against the public CycloneDX schema.

    πŸ”’ Security4 views
    Compare vs Depguard β†’
  • Security Scanner AI MCP logoSecurity Scanner AI MCP

    Security Scanner Ai automation via MCP. Includes scan dependencies, check headers, scan secr...

    πŸ”’ Security5 views
    Compare vs Security Scanner AI MCP β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
45
Stargazers on the source repository.
npm downloads
1.4k
Package downloads in the last 30 days.
Last commit
4d ago
Most recent push to the default branch.
Tools exposed
6
Callable tools this server registers over MCP.
Directory activity
6 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Codeinspectus

Use Node.js 22 or newer and run the npm package with `npx codeinspectus`; the README also documents `npx codeinspectus setup` for interactive engine setup. MCP clients start it over piped stdio.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewCodeinspectus AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/synvoya-codeinspectus?style=directory)](https://allmcps.com/mcp/synvoya-codeinspectus)
HTML Embed
<a href="https://allmcps.com/mcp/synvoya-codeinspectus"><img src="https://allmcps.com/api/badge/synvoya-codeinspectus?style=directory" alt="Codeinspectus on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
AuthNo auth required
LicenseApache-2.0
ClientsCursor, Windsurf, Cline / VS Code
Last updatedSep 7, 2026
10/11 checks healthy over the last 32d
Views6
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars45
GitHub Star CountTotal stargazers on GitHub representing community popularity (45 stars).
Last commit4d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 7, 2026
npm downloads1,446/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
68Quality signal: Great Β· 68/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools30/30
Adoption & activity10/15
Community engagement1/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 15d ago via OSV.dev Β· codeinspectus (npm)

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Codeinspectus β†’Install in Claude DesktopInstall in CursorInstall in VS Code