MCP Codeaudit runs on your own machine — the client starts it, so there is no endpoint to ping. 23 installs a week from npm.
Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.
The linked repository no longer exists on GitHub — it was deleted or made private.
Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcp-codeaudit -- npx -y @infoinlet/mcp-codeaudit
{
"mcpServers": {
"mcp-codeaudit": {
"args": [
"-y",
"@infoinlet/mcp-codeaudit"
],
"command": "npx"
}
}
}
[mcp_servers.mcp-codeaudit]
command = "npx"
args = ["-y", "@infoinlet/mcp-codeaudit"]
{
"mcpServers": {
"mcp-codeaudit": {
"args": [
"-y",
"@infoinlet/mcp-codeaudit"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"mcp-codeaudit": {
"args": [
"-y",
"@infoinlet/mcp-codeaudit"
],
"command": "npx"
}
}
}
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Pre-deploy security auditor for AI agent code — the risks generic SAST misses.
Security scan for AI-generated code: injection, SSRF, secrets, weak crypto, unsafe deserialization.
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
Scans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.
AI security layer: code scanning, PII detection, prompt injection, secrets, CVEs
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Git hosting for AI agents: repos, changes, focused diffs, reviews, issues, code search.
Answers built from our own checks of this server.