Synvoya

Codeinspectus — Security skill for Claude Code

Security community

Local-first MCP security scanner for AI-generated apps.

How to install Codeinspectus

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Synvoya/codeinspectus and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Codeinspectus does

Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.

Alternatives in Security

  • Security Scan Report — Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 High: 50 Safe skills: 100 18.1k ★
  • Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
  • Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★

README

CodeInspectus, by Synvoya

[![License: Apache 2.0](https://img.shields.io/badge/License-Apache%202.0-green.svg)](LICENSE) [![Node.js](https://img.shields.io/badge/node-%3E%3D22-brightgreen.svg)](package.json) [![npm downloads](https://img.shields.io/npm/dm/codeinspectus)](https://www.npmjs.com/package/codeinspectus) ![MCP-ready](https://img.shields.io/badge/MCP-ready-blue.svg) ![Local-first](https://img.shields.io/badge/local--first-yes-brightgreen.svg) ![No telemetry](https://img.shields.io/badge/telemetry-none-brightgreen.svg) [![Official MCP Registry](https://img.shields.io/badge/Official_MCP_Registry-listed-blue.svg)](https://registry.modelcontextprotocol.io/v0/servers?search=io.github.Synvoya%2Fcodeinspectus) [![codeinspectus MCP server](https://glama.ai/mcp/servers/Synvoya/codeinspectus/badges/score.svg)](https://glama.ai/mcp/servers/Synvoya/codeinspectus) [![GitHub stars](https://img.shields.io/github/stars/Synvoya/codeinspectus?style=social)](https://github.com/Synvoya/codeinspectus)

**A local-first, privacy-preserving security MCP server and CLI.** Any AI coding agent (Claude Code, Cursor, Codex, Windsurf, Cline, Aider) can invoke CodeInspectus to scan AI-generated / "vibe-coded" code for real vulnerabilities, map findings to compliance frameworks as honest code-level coverage, and drive a **scan → fix → rescan** loop — fully on your machine, with **no account** and **zero network egress at scan time**.

![CodeInspectus demo](assets/codeinspectus-demo.gif)

**Reproduce the V2.1 proof:** the `codeinspectus@2.1.0` package scans an immutable public Rich commit, finds one high-confidence GitHub Actions expression-injection pattern, applies GitHub's documented intermediate-`env` remediation in a temporary clone, confirms it as **1 resolved, 0 remaining, 0 introduced, 0 not rechecked**, then creates and verifies sealed evidence for both states. Run the [reproduction script](scripts/reproduce-v2.1-case-study.mjs) or read the [scanner-derived case study](example