A developer-centric security toolkit that unifies multiple scanning engines (including a custom, AST-based Python scanner and Semgrep) to find OWASP
A developer-centric security toolkit that unifies multiple scanning engines (including a custom, AST-based Python scanner and Semgrep) to find OWASP Top 10 vulnerabilities. Designed for seamless integration into development workflows and. The vulnerability mcp server wraps that behind the Model Context Protocol, so an assistant can use it rather than through you.
Installation goes through your MCP client rather than a global install: point it at vulnerability-scanner on PyPI and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
{
"mcpServers": {
"vulnerability-scanner": {
"command": "uvx",
"args": ["vulnerability-scanner"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.