grim-mcp runs on your own machine — the client starts it, so there is no endpoint to ping.
Security audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.
Today is the operative word: we check grim-mcp every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add grim-mcp -- npx -y grim-mcp
{
"mcpServers": {
"grim-mcp": {
"args": [
"-y",
"grim-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.grim-mcp]
command = "npx"
args = ["-y", "grim-mcp"]
{
"mcpServers": {
"grim-mcp": {
"args": [
"-y",
"grim-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"grim-mcp": {
"args": [
"-y",
"grim-mcp"
],
"command": "npx"
}
}
}
Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.
Audit GitHub repos for security, compliance, and EU AI Act exposure from Claude or Cursor.
Pre-deploy security auditor for AI agent code — the risks generic SAST misses.
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
Agentic SDLC governance and security controls for AI coding agents working with GitHub.
Create and manage secure sandboxes for running AI agent code
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
Dead code, security, secrets detection and code quality for Python, TypeScript, Go.
Answers built from our own checks of this server.