CodeInspectus MCP Server

Local-first MCP security scanner for AI-generated web apps.

Local serverstdioPython

What is the CodeInspectus MCP server?

CodeInspectus MCP server exists for a simple reason — assistants are far more useful when they can act on CodeInspectus directly instead of describing what you should do. Local-first MCP security scanner for AI-generated web apps.

What you get

If CodeInspectus is useful, star the repository so other AI-app builders can find it.

What the assistant can call

Once CodeInspectus is connected, these are the calls the assistant has available:

  • codeinspectus_scan — Full local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coverage
  • codeinspectus_rescan — Re-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coverage
  • codeinspectus_compliance_report — Per-framework code-level control coverage (not certification)
  • codeinspectus_explain_finding — Deep explanation + full remediation for one finding
  • codeinspectus_generate_sbom — CycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose)
  • codeinspectus_list_rules — Active detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machine

Configuration and credentials

You will need 3 environment variables: SCAN_ID, OLD_SCAN_ID, NEW_SCAN_ID. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

Setting it up

The server ships on npm as codeinspectus, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.

Choosing this one

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. CodeInspectus's toolset — codeinspectus_scan, codeinspectus_rescan, codeinspectus_compliance_report and 3 more — is a fair guide to whether it matches your workflow. It is maintained by Synvoya; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against CodeInspectus's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Before you rely on it

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the codeinspectus mcp server does with a few real requests.

Available tools

ToolWhat it does
codeinspectus_scanFull local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coverage, remediations, framework tags, and three-state repository evidence for sup
codeinspectus_rescanRe-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coverage.
codeinspectus_compliance_reportPer-framework **code-level control coverage** (not certification).
codeinspectus_explain_findingDeep explanation + full remediation for one finding.
codeinspectus_generate_sbomCycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose).
codeinspectus_list_rulesActive detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machine setup/repair state.

How to install the CodeInspectus MCP server

{
  "mcpServers": {
    "codeinspectus": { "command": "npx", "args": ["-y", "codeinspectus"] }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

VariableDescriptionRequired
SCAN_IDConfiguration value read at startup.Optional
OLD_SCAN_IDConfiguration value read at startup.Optional
NEW_SCAN_IDConfiguration value read at startup.Optional

Example prompts to try

  • Use CodeInspectus to codeinspectus scan.
  • Use CodeInspectus to codeinspectus rescan.
  • Use CodeInspectus to codeinspectus compliance report.

Frequently asked questions

It connects CodeInspectus to MCP-compatible AI assistants such as Claude and Cursor, exposing 6 tools (codeinspectus_scan, codeinspectus_rescan, codeinspectus_compliance_report, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with CodeInspectus directly.