Scan
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
- Transport
- Not stated
- Package
- —
- Registry id
- com.project-feldspar/scan
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
It is a free repository discovery scan. It checks dependency advisories against OSV.dev, looks for secret patterns, and performs config checks. It uses pure pattern matching and lockfile parsing, and does not involve an LLM.
It supports scanning repositories on GitHub, GitLab, Codeberg, and Bitbucket only. Scans take roughly 10 to 90 seconds, with a rate limit of 5 scans per hour per IP. The scanner is available as a single MIT-licensed Python file and a composite GitHub Action.
A deep audit is offered for $49 and consists of three review passes. Agents and IDEs can use it as an MCP server.
Summary drafted from the project's own website. Every sentence is backed by text on that page and was reviewed before publishing.