このMCPでできること
Scans repositories and local changes for security issues, secrets and dependency-related risks, and can create verified GitHub remediation pull requests.
ツール
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['owner', 'repo', 'token', 'file', 'line', 'finding_type', 'title', 'severity', 'description', 'recommendation'], 'properties': {'ref': {'type': 'string', 'default': 'main', 'pattern': '^[a-zA-Z0-9/_.-]{1,200}$', 'maxLength': 200, 'description': 'Git ref (branch/SHA)'}, 'file': {'type': 'string', 'maxLength': 500, 'description': 'File path containing the vulnerability (relative, no traversal)'}, 'line': {'type': 'integer', 'maximum': 100000, 'description': 'Line number of the finding', 'exclusiveMinimum': 0}, 'repo': {'type': 'string', 'pattern': '^[a-zA-Z0-9._-]{1,100}$', 'maxLength': 100, 'description': 'GitHub repository name'}, 'owner': {'type': 'string', 'pattern': '^[a-zA-Z0-9._-]{1,100}$', 'maxLength': 100, 'description': 'GitHub repository owner'}, 'title': {'type': 'string', 'maxLength': 300, 'description': 'Finding title from scan results'}, 'token': {'type': 'string', 'maxLength': 200, 'description': 'GitHub token with repo write access'}, 'severity': {'enum': ['critical', 'warning', 'info'], 'type': 'string', 'description': 'Finding severity'}, 'description': {'type': 'string', 'maxLength': 2000, 'description': 'Finding description'}, 'finding_type': {'type': 'string', 'maxLength': 100, 'description': "Finding type e.g. 'command_injection', 'sql_injection'"}, 'recommendation': {'type': 'string', 'maxLength': 2000, 'description': 'Recommended fix from scan results'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['owner', 'repo'], 'properties': {'file': {'type': 'string', 'maxLength': 500, 'description': 'Filter findings to a specific file path'}, 'repo': {'type': 'string', 'pattern': '^[a-zA-Z0-9._-]{1,100}$', 'maxLength': 100, 'description': 'GitHub repository name'}, 'owner': {'type': 'string', 'pattern': '^[a-zA-Z0-9._-]{1,100}$', 'maxLength': 100, 'description': 'GitHub repository owner'}, 'severity': {'enum': ['critical', 'warning', 'info'], 'type': 'string', 'description': 'Filter by severity level'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['files'], 'properties': {'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'maxLength': 500, 'description': 'Relative file path'}, 'content': {'type': 'string', 'maxLength': 200000, 'description': 'Full file content to check'}}}, 'maxItems': 50, 'description': 'Files staged for commit (path + content)'}, 'context': {'type': 'string', 'maxLength': 500, 'description': 'What these changes do (helps with triage)'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['owner', 'repo', 'pull_number', 'token'], 'properties': {'repo': {'type': 'string', 'pattern': '^[a-zA-Z0-9._-]{1,100}$', 'maxLength': 100, 'description': 'GitHub repository name'}, 'owner': {'type': 'string', 'pattern': '^[a-zA-Z0-9._-]{1,100}$', 'maxLength': 100, 'description': 'GitHub repository owner'}, 'token': {'type': 'string', 'maxLength': 200, 'description': 'GitHub access token with repo read permissions'}, 'pull_number': {'type': 'integer', 'maximum': 1000000, 'description': 'Pull request number to scan', 'exclusiveMinimum': 0}}}
最近のツール変更
類似のMCPサーバー
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…