Local-first MCP security scanner for AI-generated web apps.
CodeInspectus MCP server exists for a simple reason — assistants are far more useful when they can act on CodeInspectus directly instead of describing what you should do. Local-first MCP security scanner for AI-generated web apps.
If CodeInspectus is useful, star the repository so other AI-app builders can find it.
Once CodeInspectus is connected, these are the calls the assistant has available:
codeinspectus_scan — Full local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coveragecodeinspectus_rescan — Re-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coveragecodeinspectus_compliance_report — Per-framework code-level control coverage (not certification)codeinspectus_explain_finding — Deep explanation + full remediation for one findingcodeinspectus_generate_sbom — CycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose)codeinspectus_list_rules — Active detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machineYou will need 3 environment variables: SCAN_ID, OLD_SCAN_ID, NEW_SCAN_ID. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.
The server ships on npm as codeinspectus, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. CodeInspectus's toolset — codeinspectus_scan, codeinspectus_rescan, codeinspectus_compliance_report and 3 more — is a fair guide to whether it matches your workflow. It is maintained by Synvoya; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against CodeInspectus's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| codeinspectus_scan | Full local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coverage, remediations, framework tags, and three-state repository evidence for sup |
| codeinspectus_rescan | Re-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coverage. |
| codeinspectus_compliance_report | Per-framework **code-level control coverage** (not certification). |
| codeinspectus_explain_finding | Deep explanation + full remediation for one finding. |
| codeinspectus_generate_sbom | CycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose). |
| codeinspectus_list_rules | Active detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machine setup/repair state. |
{
"mcpServers": {
"codeinspectus": { "command": "npx", "args": ["-y", "codeinspectus"] }
}
}Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| SCAN_ID | Configuration value read at startup. | Optional |
| OLD_SCAN_ID | Configuration value read at startup. | Optional |
| NEW_SCAN_ID | Configuration value read at startup. | Optional |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.