Codeinspectus — Security skill for Claude Code
Local-first MCP security scanner for AI-generated apps.
How to install Codeinspectus
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Synvoya/codeinspectus and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Codeinspectus does
Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
Alternatives in Security
- Security Scan Report — Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 High: 50 Safe skills: 100 18.1k ★
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
README
CodeInspectus, by Synvoya
[](LICENSE) [](package.json) [](https://www.npmjs.com/package/codeinspectus)    [](https://registry.modelcontextprotocol.io/v0/servers?search=io.github.Synvoya%2Fcodeinspectus) [](https://glama.ai/mcp/servers/Synvoya/codeinspectus) [](https://github.com/Synvoya/codeinspectus)
**A local-first, privacy-preserving security MCP server and CLI.** Any AI coding agent (Claude Code, Cursor, Codex, Windsurf, Cline, Aider) can invoke CodeInspectus to scan AI-generated / "vibe-coded" code for real vulnerabilities, map findings to compliance frameworks as honest code-level coverage, and drive a **scan → fix → rescan** loop — fully on your machine, with **no account** and **zero network egress at scan time**.

**Reproduce the V2.1 proof:** the `codeinspectus@2.1.0` package scans an immutable public Rich commit, finds one high-confidence GitHub Actions expression-injection pattern, applies GitHub's documented intermediate-`env` remediation in a temporary clone, confirms it as **1 resolved, 0 remaining, 0 introduced, 0 not rechecked**, then creates and verifies sealed evidence for both states. Run the [reproduction script](scripts/reproduce-v2.1-case-study.mjs) or read the [scanner-derived case study](example
Related Skills
Vibe Audit
Security scanner for AI-built apps. Catches hardcoded secrets, injection vulnerabilities, missing rate limits,
Git Gud Security
Security scanner for repos, apps, and things built with Claude (skills, plugins, MCP servers). Runs as a Claud
DeepSafe Scan — Agent Instructions
This is the deepsafe-scan security scanner for AI agent environments. Works with: OpenClaw, Claude Code, Curso
Loongsuite Pilot
Local-first telemetry collector for AI coding agents — unified OpenTelemetry events for Claude Code, Codex, Cu
Bastet Agent OS
Local-first control plane for AI-agent teams — orchestrates Claude Code, Codex, Grok, agy & Hermes into gated
Code Validator
Static security scanner purpose-built for AI-generated code (Claude Code, GitHub Copilot, ChatGPT, Cursor). De
Related Agents
AI Code Security Auditor
Security reviewer for AI-generated and vibe-coded apps — hunts the hardcoded secrets, broken row-level securit
Security AI Generated Code Auditor
Security reviewer for AI-generated and vibe-coded apps — hunts the hardcoded secrets, broken row-level securit
Cook Audit
jeff audit stage (conditional: runs when the plan flags a security-relevant surface, or when the mechanical sc