Agent Security Scanner MCP
Security scanner MCP server that protects AI coding agents from generating vulnerable code. Uses tree-sitter AST analysis to detect OWASP Top 10 vulnerabilities, hardcoded secrets, and prompt injection attacks. Includes package hallucination detection across 4.3M packages (npm, PyPI, RubyGems, crates.io, pub.dev, CPAN, Raku). Works with Claude Desktop, Claude Code, Cursor, Cline, and any MCP-compatible client.
Full feature list (for detailed descriptions):
• 275+ security rules covering Python, JavaScript, TypeScript, Java, Go, Ruby, PHP, C/C++,
Rust, C#, Terraform, Kubernetes
• AST-based detection with tree-sitter (falls back to regex when unavailable)
• Taint analysis for tracking user input to dangerous sinks
• Package hallucination detection: verifies 4.3M+ packages across 7 ecosystems
• Prompt injection detection: blocks exfiltration, jailbreaks, and malicious instructions
• Automatic fix suggestions for common vulnerabilities
• Zero config: works instantly with npx
• CWE/OWASP metadata for compliance reporting