About this integration
Local-first MCP security scanner and CLI for AI-generated applications.
- Transport
- stdio
- Authentication
- none
- Initial setup
- none
- Runtime
- unattended
- Evidence
- documented
- Version
- 3.2.0
- Package
- codeinspectus
- Last compatibility test
- Not independently tested
Connect your agent
codeinspectusPublisher README and executable npm manifest reviewed offline. Scanner engines, optional downloads, target repositories, and MCP tools were not executed; documented detection coverage and security claims were not independently tested or audited.
Capabilities: Local source, secret, dependency, and configuration scanning, Finding explanation and scan-to-rescan comparison, SBOM and sealed evidence bundle generation, Baselines, history, and code-visible compliance reports
Connected profiles
Additional details
io.github.Synvoya/codeinspectus
Source ↗ · Checked 2026-09-173.2.0
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17npm
Source ↗ · Checked 2026-09-17codeinspectus
Source ↗ · Checked 2026-09-203.2.0
Source ↗ · Checked 2026-09-20MCP clients launch the local server over piped stdio. Scans are documented as local with no network egress, while optional scanner-engine installation is a separate approval-gated setup action.
Source ↗ · Checked 2026-09-20The publisher explicitly documents no account requirement and no authentication credential for local scanning. Optional component downloads require operator approval but not service authentication.
Source ↗ · Checked 2026-09-20Configure an MCP client to run npx with -y and codeinspectus over stdio; the publisher recommends a longer client tool timeout for large scans.
Source ↗ · Checked 2026-09-20Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-20