Skip to main content

secscan-mcp

CI PyPI Python

A portable MCP server for security scanning — works with any AI coding assistant that supports the Model Context Protocol: Cursor, VS Code, Claude Desktop, Windsurf, Zed, Continue, and more.

Scan codebases for hardcoded secrets, SAST issues, vulnerable dependencies, and IaC misconfigurations — one install, one normalized report format.

The built-in custom scanner works with no extra tools. Install optional CLIs for broader coverage (below).

Quick start

Requires Python 3.11+. If pip install secscan-mcp says "No matching distribution found", your default python3 is likely too old — use python3.11 -m pip install secscan-mcp or install Python 3.11+ first.

1. Install from PyPI:

pip install secscan-mcp
# or explicitly:
python3.11 -m pip install secscan-mcp

Or run without installing (requires uv):

uvx secscan-mcp

For MCP config with uvx, use "command": "uvx" and "args": ["secscan-mcp"] — see setup guide.

Install from source
git clone https://github.com/openjkai/secscan_mcp.git
cd secscan_mcp && pip install .

2. Add to your IDE — pick your client:

IDE / client Config file Guide
Cursor ~/.cursor/mcp.json setup →
VS Code .vscode/mcp.json setup →
Claude Desktop OS-specific (see guide) setup →
Claude Code ~/.claude/settings.json setup →
Windsurf ~/.codeium/windsurf/mcp_config.json setup →
Others Full setup guide

Minimal config (works in Cursor, Claude Desktop, Windsurf):

{
  "mcpServers": {
    "secscan": {
      "command": "uvx",
      "args": ["secscan-mcp"]
    }
  }
}

If you installed with pip install secscan-mcp, you can use "command": "secscan-mcp" instead.

3. Verify — ask your agent: "Call list_available_scanners and scan_secrets on this project."

MCP tools

Tool Purpose
list_available_scanners Which engines are installed on this machine
scan_secrets Hardcoded credentials and secrets (optionally scan git commit history)
scan_code SAST (semgrep, bandit)
scan_dependencies Vulnerable packages (osv-scanner)
scan_iac IaC misconfigurations (checkov)
scan_all All available scanners, one unified report
explain_finding Remediation hints for a rule_id

Most scan tools accept path (directory to scan) and optional severity_threshold (critical, high, medium, low, info).

scan_secrets also accepts include_git_history (boolean). When true, scans past git commits for secrets removed from the working tree but still present in history — no extra tools required beyond git.

Optional scanners

Install any of these to extend coverage. Missing CLIs are skipped — the server still runs.

Engine Category Install (example)
gitleaks secrets brew install gitleaks
semgrep SAST pip install semgrep
bandit SAST (Python) pip install bandit
osv-scanner dependencies brew install osv-scanner
checkov IaC pip install checkov

After installing, run list_available_scanners again to confirm.

Example prompts

  • "Call list_available_scanners and tell me what's installed."
  • "Run scan_secrets with include_git_history on this repo — check if any secrets were ever committed."
  • "Run scan_all with severity_threshold high and summarize the findings."
  • "Explain the rule internal-api-key."

Configuration

Environment variables (optional):

Variable Default Description
SECSCAN_DEFAULT_TIMEOUT_SECONDS 300 Per-engine scan timeout
SECSCAN_MAX_FINDINGS 500 Max findings per report
SECSCAN_GIT_MAX_COMMITS 500 Max commits scanned in git history mode

Pass via MCP config env block — see setup guide.

Development

make install-dev   # editable install + dev tools
make check         # lint + typecheck + test

See docs/CONTRIBUTING.md and PLAN.md.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

secscan_mcp-0.2.0.tar.gz (24.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

secscan_mcp-0.2.0-py3-none-any.whl (26.9 kB view details)

Uploaded Python 3

File details

Details for the file secscan_mcp-0.2.0.tar.gz.

File metadata

  • Download URL: secscan_mcp-0.2.0.tar.gz
  • Upload date:
  • Size: 24.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for secscan_mcp-0.2.0.tar.gz
Algorithm Hash digest
SHA256 ff011b7476ca6b8998460d279161442073bc84bb17a2b73f505e7c85c831b55a
MD5 48ecef3eb1acf27dfc795b8a518b8769
BLAKE2b-256 03029d5303c1afff6d23de209a5108c2e137804c81aa28ae90569f05ac37cbbc

See more details on using hashes here.

Provenance

The following attestation bundles were made for secscan_mcp-0.2.0.tar.gz:

Publisher: release.yml on openjkai/secscan_mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file secscan_mcp-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: secscan_mcp-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 26.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for secscan_mcp-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 7f0c8f4f511084d17b86ba435d43a6a86fc4a94ab3aa18d17365711dd43443f6
MD5 06704f69d72491133c4214a56f4f2cf7
BLAKE2b-256 b3bb0217487050749fe765184b7bcfa5db6461c13a8c0004cb4cef7bd9944a1a

See more details on using hashes here.

Provenance

The following attestation bundles were made for secscan_mcp-0.2.0-py3-none-any.whl:

Publisher: release.yml on openjkai/secscan_mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page