Skip to main content

Vorlox — MCP security scanning for your hosted organisation

Project description

Vorlox CLI

Scan the MCP servers in your hosted Vorlox organisation from a terminal or a CI pipeline.

uv tool install vorlox     # or: pipx install vorlox
vorlox login
vorlox scan --hosted <server-id>

Commands

Command What it does
vorlox login Store an API key (prompted, never echoed, never an argv flag)
vorlox logout Remove the stored key
vorlox auth status Show which credential is active, without printing it
vorlox scan --hosted <id> Scan a server in your organisation
vorlox findings List findings, newest first

CI

Set VORLOX_API_KEY instead of running vorlox login. It takes precedence over a stored credential, so a pipeline is never affected by whoever last logged in on the runner.

export VORLOX_API_KEY=vlx_live_...
vorlox scan --hosted <server-id> --fail-on high

Exit codes: 0 passed, 1 a finding met or exceeded --fail-on, 2 the scan could not run.

Before the CLI can scan a server

A person must add the server in the Vorlox dashboard and confirm they are authorised to scan it. An API key cannot do this for itself — a pipeline must not be able to manufacture the authorisation for the target it then scans. The server's page shows its ID once it is confirmed.

Your key needs the scans:write scope to scan, and findings:read to read findings. Create keys in Settings → API keys.

Scope

This package talks to the hosted Vorlox API over HTTPS. Scanning a local MCP server from your own machine is not part of it.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vorlox-0.1.1-py3-none-any.whl (24.0 kB view details)

Uploaded Python 3

File details

Details for the file vorlox-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: vorlox-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 24.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for vorlox-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 4927527c22217522f4363c5f735eb3f80e9e95e7e83c3c9181d005094cf4f854
MD5 c62085d0237f57a6134a051e891ad3e8
BLAKE2b-256 24bf5e4a3d0c8cb2014d21871b5871213009826473c7a221b7880559d9c6cbae

See more details on using hashes here.

Provenance

The following attestation bundles were made for vorlox-0.1.1-py3-none-any.whl:

Publisher: publish-pypi.yml on fahaadabdullah6-dev/vorlox-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page