AI Scanner MCP Server

Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.

Local serverstdio

What is the AI Scanner MCP server?

AI Scanner MCP server exists for a simple reason — assistants are far more useful when they can act on AI Scanner directly instead of describing what you should do. Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.

What you get

MCP server for ai-scanner - let AI agents scan codebases for LLM usage, AI frameworks, and exposed secrets.

Setting it up

Installation goes through your MCP client rather than a global install: point it at ai-scanner-mcp on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

What the assistant can call

Once AI Scanner is connected, these are the calls the assistant has available:

  • scan_directory — Full scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levels
  • check_secrets — Security check — pass/fail scan for exposed credentials only. Perfect for pre-commit checks
  • ai_inventory — AI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection)
  • Cursor — The Cursor tool exposed by this server
  • Windsurf — The Windsurf tool exposed by this server

Before you rely on it

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the ai scanner mcp server does with a few real requests.

Choosing this one

Among the AI and media services options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. AI Scanner's toolset — scan_directory, check_secrets, ai_inventory and 2 more — is a fair guide to whether it matches your workflow. It is maintained by Aakashbhardwaj27; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Available tools

ToolWhat it does
scan_directoryFull scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levels
check_secretsSecurity check — pass/fail scan for exposed credentials only. Perfect for pre-commit checks
ai_inventoryAI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection)
CursorThe Cursor tool exposed by this server.
WindsurfThe Windsurf tool exposed by this server.

How to install the AI Scanner MCP server

{
  "mcpServers": {
    "ai-scanner": {
      "command": "npx",
      "args": ["-y", "ai-scanner-mcp"]
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Example prompts to try

  • Use AI Scanner to scan directory.
  • Use AI Scanner to check secrets.
  • Use AI Scanner to ai inventory.

Frequently asked questions

It connects AI Scanner to MCP-compatible AI assistants such as Claude and Cursor, exposing 5 tools (scan_directory, check_secrets, ai_inventory, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with AI Scanner directly.