Feldspar free repository security scan is answering right now. Last checked 3 min ago. It exposes 2 tools. Last commit 5 Sep 2026.
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
We read the source, 16 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
r = subprocess.run(argv)
env = dict(os.environ)
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 3 min ago.
claude mcp add scan --transport http https://project-feldspar.com/mcp
{
"mcpServers": {
"scan": {
"url": "https://project-feldspar.com/mcp"
}
}
}
[mcp_servers.scan]
url = "https://project-feldspar.com/mcp"
{
"mcpServers": {
"scan": {
"url": "https://project-feldspar.com/mcp"
}
}
}
{
"mcpServers": {
"scan": {
"url": "https://project-feldspar.com/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
audit_pricing
scan_repository
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://project-feldspar.com/mcp | streamable-http | answering | 83 ms | 3 min ago |
Validates AI-generated Python: syntax, lint, security scan and deterministic repair.
FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality
Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
PQC scanner for GitHub repos and smart contracts. Detects quantum-vulnerable ECDSA/RSA.
Security scanning for websites, public repositories, and Open CLAW skills.
Code intelligence for LLMs. Analyze, search, and retrieve code from any public git repository.
Answers built from our own checks of this server.