MCP server
Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.
1 stars778 downloads/wk
Reviews
Write oneNobody has reviewed MCP yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
MCP tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it
- Code scan3 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 11 days ago15/15
- Maintainer identitynamespace and repository owner differ4/10
What the publisher says
From the MCP repository's README, as published. We do not edit it. Read it on GitHub
Jikida.io The hosted AI pentester for people who ship — not just security engineers. Pentest your live app, scan your repo, protect it with a WAF, and watch its uptime. One account. No Docker, no LLM key, free tier.
Why it beats Nuclei / Strix / Shannon ↓ · Install · MCP · SDKs · Compare
Install it, scan it, or plug it into your AI editor:
npx @jikida/init # add the SDK + protection to your app in 30 seconds
npx @jikida/scan # pentest any site or repo from your terminal
npx -y @jikida/mcp # security tools inside Claude Code, Cursor, Windsurf██ ██ ██ ██ ██ █████ ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ███ ██ ██ ██ ██ █████ ██ ██ pentest · repo scan · uptime · alerts https://jikida.io
→ scanning example.com … ✓ 41 checks · grade B (88/100)
CRITICAL Exposed .env file /.env CWE-538 CRITICAL Stripe secret key in JS /app.js:1204 CWE-312 HIGH Missing Content-Security-Policy CWE-693 MEDIUM Cookie without Secure flag session CWE-614
Every finding has a fix. Full report: https://app.jikida.io
Pentest & scan for developers, AI IDEs & vibe coders
Pentest and scan websites, web apps, code and GitHub for vulnerabilities and exposed keys. Secure vibe-coded apps, monitor uptime, SSL and domains, and rate-limit APIs. One platform.
Website & app pentest · Code & repo scan · Deep pentest · MCP for AI IDEs · Agentic & vibe-coded security · SDKs
Jikida.io is a developer-first security platform. The core is pentest and scanning: it pentests your live website and app, scans your code and connected GitHub/GitLab/Bitbucket repos for exposed secrets and vulnerable dependencies, runs a deeper authenticated pentest, and plugs into your AI IDE (Claude Code, Cursor, Windsurf) over MCP so it guides agentic and vibe-coded work to write secure code and catches mistakes before they ship. Uptime, SSL & domain monitoring, a managed WAF, and a compliance generator come bundled as complementary extras — installed in one line for Node, PHP/Laravel, Python, Go, Ruby, Java, .NET, Rust, Bun, or Deno.
Your security layer. Shipped in 30 seconds. One line — npx @jikida/init — and every SDK fails open, so if Jikida.io is ever down your app keeps serving.
Why Jikida beats the other security tools
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y @jikida/mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mcp -- npx -y @jikida/mcp
MCP: common questions
- Is MCP server safe?
- Yes, by our scan: it is graded A (86/100). Read the MCP safety report
- How do I install MCP?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does MCP need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is MCP maintained?
- The last commit was 11 days ago (2026-09-11). The latest release is v0.3.6.
- What can I use instead of MCP?
- Servers from other publishers that do the same job: Nel Veil MCP server, ScanLabsAI Security Scanner MCP server and Passiv Web Tools MCP server. Compare all MCP alternatives.
Alternatives to MCP
Same job from other publishers: the closest match first, then the best rated.
- Nel VeilFree passive security scanning - check any domain's DMARC, TLS, headers, and exposures.not reviewedGrowingA
ScanLabsAI Security ScannerScan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixesnot reviewedNewB- Passiv Web ToolsFree web tools for AI agents: HTML to Markdown, compliance scan, page profile, security headers.not reviewedNewB
- Prodcheck4,372 pre-production checks: security, performance, scale, integrations, post-launch.not reviewedGrowingA
TrentSecurity reviews, threat models over a repo or website, and remediation tracking, in your editor.not reviewedGrowingA