openapi-security-contract-lint
Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in th
A89/100grade A
Adoption
New
0 stars
Reviews
Write oneNobody has reviewed openapi-security-contract-lint yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Tools
Tool lists for local packages are only visible after install.
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- Code scan6 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Overall 89/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
Runs npx -y @readystack/openapi-security-contract-lint on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add openapi-security-contract-lint -- npx -y @readystack/openapi-security-contract-lint
Alternatives to openapi-security-contract-lint
Same job from other publishers, ranked by rating then adoption.
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB
dns-doctorScan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.not reviewedGrowingA- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedGrowingB
- secobserve-mcpMCP server for SecObserve: triage findings, import scan reports and SBOMs, generate VEX.not reviewedGrowingB
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewedGrowingA