Codeinspectus
UnclaimedLocal-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
Set up this server
01 / Choose your client
02 / Before you connect
Authentication is not specified. Check the project instructions before connecting.
Project instructions03 / Add the configuration
claude mcp add --transport stdio 'codeinspectus' -- 'npx' '-y' 'codeinspectus' 'repair-engines'04 / Check it in your client
Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.
More in Databases
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
6 of 6 tools
Documented tools (6)
From project documentation. A server handshake does not verify each tool’s description or behavior.
codeinspectus_compliance_report
Per-framework code-level control coverage (not certification).
codeinspectus_explain_finding
Deep explanation + full remediation for one finding.
codeinspectus_generate_sbom
CycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose).
codeinspectus_list_rules
Active detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machine setup/repair state.
codeinspectus_rescan
Re-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coverage.
codeinspectus_scan
Full local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coverage, remediations, framework tags, and three-state repository evidence for supported runtime controls.
Tool change history
FAQ
Questions about Codeinspectus MCP Server
- How do I connect Codeinspectus MCP Server to Claude?
- Run `claude mcp add codeinspectus -- npx -y codeinspectus repair-engines` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
- Is Codeinspectus MCP Server free?
- The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Codeinspectus MCP Server do?
- Codeinspectus MCP Server documents 6 tools to the agent, including codeinspectus_compliance_report, codeinspectus_explain_finding, codeinspectus_generate_sbom. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.