{"repo":"Synvoya/codeinspectus","free":true,"listed":false,"github":"https://github.com/Synvoya/codeinspectus","clone":"git clone https://github.com/Synvoya/codeinspectus.git","description":"Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.","language":"TypeScript","stars":41,"topics":["ai-generated-code","ai-security","appsec","devsecops","gitleaks","local-first","mcp","opengrep","security","static-analysis"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"CodeInspectus, by Synvoya A local-first, privacy-preserving security MCP server and CLI. Any AI coding agent (Claude Code, Cursor, Codex, Windsurf, Cline, Aider) can invoke CodeInspectus to scan AI-generated / \"vibe-coded\" code for real vulnerabilities, map findings to compliance frameworks as honest code-level coverage, and drive a scan → fix → rescan loop — fully on your machine, with no account and zero network egress at scan time . Reproduce the V2.1 proof: the codeinspectus@2.1.0 package scans an immutable public Rich commit, finds one high-confidence GitHub Actions expression-injection pattern, applies GitHub's documented intermediate- env remediation in a temporary clone, confirms it as 1 resolved, 0 remaining, 0 introduced, 0 not rechecked , then creates and verifies sealed evidence for both states. Run the reproduction script or read the scanner-derived case study. The recorded pre-publication run used the exact V2.1 tarball; the script defaults to npm after publication. The case uses the ai scanner class to isolate stable native behavior; use a normal full scan for broad repository coverage. If CodeInspectus is useful, star the repository so other AI-app builders can find it. CodeInspectus orchestrates three best-in-class OSS engines behind one normalized, CWE-keyed schema, and adds its own AI-code-specific checks that generic scanners miss: - Opengrep — SAST / OWASP Top 10 (SARIF) - Gitleaks — secrets - Trivy — dependency CVEs (SCA), IaC misconfig, secrets, license","default_branch":null,"files":null,"tree":[],"storefront":"/r/Synvoya","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Synvoya/codeinspectus/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}