Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.
AI Scanner MCP server exists for a simple reason — assistants are far more useful when they can act on AI Scanner directly instead of describing what you should do. Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.
MCP server for ai-scanner - let AI agents scan codebases for LLM usage, AI frameworks, and exposed secrets.
Installation goes through your MCP client rather than a global install: point it at ai-scanner-mcp on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
Once AI Scanner is connected, these are the calls the assistant has available:
scan_directory — Full scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levelscheck_secrets — Security check — pass/fail scan for exposed credentials only. Perfect for pre-commit checksai_inventory — AI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection)Cursor — The Cursor tool exposed by this serverWindsurf — The Windsurf tool exposed by this serverAmong the AI and media services options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. AI Scanner's toolset — scan_directory, check_secrets, ai_inventory and 2 more — is a fair guide to whether it matches your workflow. It is maintained by Aakashbhardwaj27; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| scan_directory | Full scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levels |
| check_secrets | Security check — pass/fail scan for exposed credentials only. Perfect for pre-commit checks |
| ai_inventory | AI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection) |
| Cursor | The Cursor tool exposed by this server. |
| Windsurf | The Windsurf tool exposed by this server. |
{
"mcpServers": {
"ai-scanner": {
"command": "npx",
"args": ["-y", "ai-scanner-mcp"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Build a programmable telecommunications stack for connecting telephony services with the Internet via a cloud-based utility.
Search built for AI, not humans — semantic web search that returns model-ready content, plus code context.
Answers, not links — delegate questions to Perplexity's search-grounded models and get cited responses back.
Give your assistant a voice — text-to-speech, voice cloning and audio tools from the ElevenLabs API.
Give your assistant a real code sandbox — isolated cloud VMs for actually running the code it writes.
The ML hub in your context window — search models, datasets, papers and run Spaces from the official server.