{"name":"io.github.Synvoya/codeinspectus","slug":"synvoya-codeinspectus","title":"CodeInspectus","description":"Local-first MCP security scanner and CLI for AI-generated applications.","url":"https://mcp.market/server/synvoya-codeinspectus","rating":null,"grade":"C","score":58,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":44,"stars":47,"forks":9,"downloads_week":101,"last_push_at":"2026-09-07T06:52:41.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/Synvoya/codeinspectus","website":"https://codeinspectus.com","version":"3.2.0","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"codeinspectus","version":"3.2.0","transport":{"type":"stdio"}}],"tools":[{"name":"codeinspectus_compliance_report","description":"Produce a per-framework code-level control-coverage view for a prior scan (NIST CSF 2.0, ISO 27001:2022, SOC 2, CIS v8.1, Essential Eight, OWASP Web/LLM). Reports 'X of N code-visible controls have findings' with the code-visible subset as the explicit denominator. This is NOT a compliance audit, certification, or attestation \\u2014 code-level evidence only.","write_action":false,"price_micros":0,"input_schema":null},{"name":"codeinspectus_explain_finding","description":"Return a deep explanation and full remediation plan for a single finding id from a prior scan: what the weakness is, why it matters, concrete fix steps, and references.","write_action":false,"price_micros":0,"input_schema":null},{"name":"codeinspectus_generate_sbom","description":"Generate a CycloneDX or SPDX SBOM for the target project using Trivy plus the first-party offline Pub lockfile inventory, with native Pub fallback when Trivy is unavailable. Writes the SBOM file to the chosen output path and returns its location and component count. Offline.","write_action":false,"price_micros":0,"input_schema":null},{"name":"codeinspectus_list_rules","description":"List the active detectors and engine versions, the CodeInspectus detection-database version and date, Trivy vulnerability-DB freshness, bundled Pub advisory-database provenance/freshness, and the custom CodeInspectus AI-code rules and native detector packs currently shipped.","write_action":false,"price_micros":0,"input_schema":null},{"name":"codeinspectus_rescan","description":"Re-run a scan after fixes were applied and diff against a prior scan_id (or the most recent scan of the same path). Reports which findings are resolved, which remain, and which were newly introduced, plus fresh technology and native-pack execution coverage. Repository-trust artifacts are diffed separately with fail-closed resolved, remaining, introduced and not-rechecked states. Use this to verify","write_action":false,"price_micros":0,"input_schema":null},{"name":"codeinspectus_scan","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"codeinspectus_setup","description":"Inspect external-engine health and exact platform download sizes, save declined choices, or install selected Opengrep/Gitleaks/Trivy components after explicit confirmation. Plan is offline. Install writes only to ~/.codeinspectus, verifies immutable pins/publisher provenance, and never modifies the target repository.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":58,"grade":"C","scanned_at":"2026-09-20T00:28:58.185Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T00:28:58.172Z","components":{"code":{"score":3,"max":25,"notes":["30 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 13 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"exec.shell-true","severity":"medium","component":"code","title":"subprocess with shell=True","evidence":"detection-db/manifest.json: …\", \"name\": \"Command injection via shell=True (Python)\", \"kind\": \"sast\", …"},{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"detection-db/opengrep-rules/security-baseline/injection.yaml: …\"...\", shell=True) - pattern: os.system(\"...\" + ...) - pattern: os.system(f\".…"},{"id":"exec.eval","severity":"medium","component":"code","title":"eval / new Function used","evidence":"detection-db/opengrep-rules/security-baseline/injection.yaml: … - pattern-either: - pattern: eval($X) - pattern: new Function(..…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"codeinspectus","version":"3.2.0","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":6,"publishedAt":"2026-09-07T07:06:41.510Z","repositoryUrl":"git+https://github.com/Synvoya/codeinspectus.git","weeklyDownloads":101}],"repo":{"found":true,"owner":"Synvoya","repo":"codeinspectus","archived":false,"pushedAt":"2026-09-07T06:52:41Z","stars":47,"forks":9,"openIssues":5,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/16019863?v=4","ownerCreatedAt":"2015-11-25T16:05:35Z","license":"Apache-2.0"},"icon":{"url":"https://codeinspectus.com/favicon.ico","source":"site","width":48,"height":48},"presence":{"stars":47,"forks":9,"downloadsWeek":101,"license":"Apache-2.0","lastPushAt":"2026-09-07T06:52:41.000Z","score":44}}}},"grade_history":[],"reviews":[]}