Codeinspectus
未申請Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
01 / クライアントを選択
03 / 設定を追加
claude mcp add --transport stdio 'codeinspectus' -- 'npx' '-y' 'codeinspectus' 'repair-engines'04 / クライアントで確認
クライアントの MCP 設定で接続とツール一覧を確認してください。設定のコピーだけでは接続成功は確認できません。
Databasesの他のサーバー
ディレクトリ全体を見る未申請リスティング
このMCPサーバーはあなたのものですか?
このリスティングは公開情報から自動的にインデックスされました。申請することで、ページの編集、互換性の設定、成長ツールのアンロックができます。2分以内に完了します。
このサーバーを申請するセキュリティプロファイル
申請済みおよび認証済みのサーバーは毎週の静的スキャンを受け、コードが到達できる範囲(外部サービス、環境変数、シェルコマンド、エージェント設定フォルダ)と既知のアドバイザリを持つ依存関係が表示されます。このリスティングを申請すると利用できます。 セキュリティプロファイルの仕組み
6 件中 6 件
ドキュメントに記載されたツール (6)
プロジェクトのドキュメントに基づきます。サーバーのハンドシェイクは、各ツールの説明や動作を検証するものではありません。
codeinspectus_compliance_report
Per-framework code-level control coverage (not certification).
codeinspectus_explain_finding
Deep explanation + full remediation for one finding.
codeinspectus_generate_sbom
CycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose).
codeinspectus_list_rules
Active detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machine setup/repair state.
codeinspectus_rescan
Re-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coverage.
codeinspectus_scan
Full local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coverage, remediations, framework tags, and three-state repository evidence for supported runtime controls.