このMCPでできること
Audits repositories and posted source for production risks, secrets, dependency vulnerabilities, and other code-quality findings, with fix verification.
ツール
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repoUrl'], 'properties': {'repoUrl': {'type': 'string', 'minLength': 1, 'description': "GitHub repository URL or owner/repo. A private repo needs a githubToken, unless the account has installed nittim's GitHub App at nittim.com for it."}, 'fullScan': {'type': 'boolean', 'description': 'True buys the wider Full Audit tier: every eligible source file, priced by pass count.'}, 'payInstead': {'type': 'boolean', 'description': 'True pays credits now instead of queuing for the daily free-audit budget to reopen, skipping the covered (Audit) entitlement even when it would otherwise be free.'}, 'deployedUrl': {'type': 'string', 'description': "Optional URL of this repository's live deployment, for an origin the account owner actually operates. When set, the audit adds one bounded, READ-ONLY fetch pass against it and reports drift between the deployed artifact and the audited commit. Redirects are never followed; private addresses are refused."}, 'githubToken': {'type': 'string', 'description': "Optional read-only GitHub token for a private repo. Without one, only public repos are reachable â\x80\x94 unless the account has installed nittim's GitHub App at nittim.com for this repo, in which case a private repo works with no token at all."}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes."}, 'content': {'type': 'string', 'description': "The file's full text."}, 'encoding': {'type': 'string', 'description': "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected â\x80\x94 text only in v1."}}}, 'maxItems': 1000, 'minItems': 1, 'description': 'Source files as { path, content }[] â\x80\x94 not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.'}, 'fullScan': {'type': 'boolean', 'description': 'True buys the wider Full Audit tier over the files you post, priced by pass count.'}, 'uploadGrant': {'type': 'string', 'description': 'Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.'}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'section': {'enum': ['money', 'tiers', 'loop', 'disputes', 'all'], 'type': 'string', 'description': 'Which page: money, tiers, loop, disputes, or all (the default).'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['auditId', 'stance', 'evidence'], 'properties': {'title': {'type': 'string', 'description': "The finding's exact title â\x80\x94 required if findingKey is omitted."}, 'stance': {'enum': ['dispute', 'confirm'], 'type': 'string', 'description': "'dispute' = this finding is wrong. 'confirm' = this finding is genuinely real."}, 'auditId': {'type': 'string', 'format': 'uuid', 'pattern': '^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$', 'description': 'The audit UUID, from its report link.'}, 'evidence': {'type': 'object', 'required': ['file', 'explanation'], 'properties': {'file': {'type': 'string', 'minLength': 1, 'description': 'The file path your evidence points to.'}, 'lines': {'type': 'string', 'description': "Line range, e.g. '42-58'."}, 'snippet': {'type': 'string', 'description': 'A short excerpt of the actual code supporting your stance.'}, 'explanation': {'type': 'string', 'minLength': 1, 'description': 'Why this finding is wrong or confirmed real, in your own words.'}}, 'description': 'What you can see in the repo that supports your stance.'}, 'dimension': {'type': 'string', 'description': "The finding's dimension, e.g. 'security' â\x80\x94 required if findingKey is omitted."}, 'findingKey': {'type': 'string', 'description': "The finding's stable key from the digest, if you have it (preferred over dimension+title)."}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'bytes'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'."}, 'bytes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': "The file's byte size. This shape has no `content` â\x80\x94 nothing is uploaded."}}}, 'minItems': 1, 'description': 'A manifest of paths and sizes only, in place of `repoUrl` â\x80\x94 the same set you would post. Over the cap the answer names it and how to trim. Send one or the other.'}, 'repoUrl': {'type': 'string', 'minLength': 1, 'description': 'GitHub repository URL or owner/repo. Mutually exclusive with `files` â\x80\x94 send one.'}, 'fullScan': {'type': 'boolean', 'description': 'Price Full Audit (every eligible file, or a refusal with the reason when the selection is too large) instead of the default Audit.'}, 'githubToken': {'type': 'string', 'description': "Optional GitHub personal access token (read-only) for a private repo. Without one, a signed-in account with nittim's GitHub App installed at nittim.com for this repo still prices it â\x80\x94 no token needed."}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['id'], 'properties': {'id': {'type': 'string', 'format': 'uuid', 'pattern': '^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$', 'description': 'The UUID of the saved audit, from the /report/{id} URL.'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['content'], 'properties': {'content': {'type': 'string', 'maxLength': 100000, 'minLength': 1, 'description': "The text to judge â\x80\x94 code, a document, another model's output. Up to ~100KB."}, 'context': {'type': 'string', 'description': 'Optional â\x80\x94 background the judge should know, e.g. what this content is for.'}, 'criteria': {'type': 'string', 'description': "Optional â\x80\x94 what to judge it against, e.g. 'correctness and security'."}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}, 'modelUnderTest': {'enum': ['anthropic', 'openai', 'unspecified'], 'type': 'string', 'description': "Optional â\x80\x94 which vendor family produced `content`, if it is itself a model's output. The judge that runs is always a different family than this names. Use 'unspecified' for anything that is not model output, or when the family is unknown."}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'keyName': {'type': 'string', 'maxLength': 80, 'description': "Optional display name for the key that will be minted, e.g. 'my-cursor-key'. Defaults to 'API key'."}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'bytes'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'."}, 'bytes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': "The file's size in bytes. No content."}}}, 'maxItems': 1000, 'minItems': 1, 'description': 'Paths and sizes only â\x80\x94 the same set you would post. Never file content.'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repo_hash', 'repo_size_bucket', 'passes'], 'properties': {'mode': {'enum': ['one_shot', 'serial'], 'type': 'string', 'description': "Optional: 'one_shot' (every lens sweeps the whole tree first, then one fix wave, then a short convergence loop) or 'serial' (one lens or area per pass, fixing between passes)."}, 'swept': {'type': 'boolean', 'description': 'Optional: was the CLASS swept â\x80\x94 a guard, lint rule or exhaustiveness check that makes a new instance loud â\x80\x94 rather than only the instances a pass named? Never derived, never changes the reward. On a repeat report, omitting it keeps the last answer; `false` withdraws it.'}, 'passes': {'type': 'array', 'items': {'type': 'object', 'required': ['n', 'fixed', 'clean'], 'properties': {'n': {'type': 'integer', 'maximum': 9007199254740991, 'description': "This pass's number, starting at 1.", 'exclusiveMinimum': 0}, 'clean': {'type': 'boolean', 'description': 'True iff this pass found nothing new.'}, 'fixed': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'How many findings this pass fixed.'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['category'], 'properties': {'low': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}, 'high': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}, 'medium': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}, 'category': {'enum': ['security', 'privacy', 'reliability', 'code_quality', 'ai_risk', 'performance', 'devops', 'data', 'business', 'devex', 'accessibility', 'observability', 'maintainability'], 'type': 'string'}, 'critical': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}, 'maxItems': 13, 'description': 'Findings this pass named â\x80\x94 one entry per category with something to report; omit a category that found nothing. Each count defaults to 0 when omitted.'}}, 'additionalProperties': False}, 'maxItems': 100, 'minItems': 1, 'description': 'One entry per pass you actually ran, in order.'}, 'repo_hash': {'type': 'string', 'pattern': '^[0-9a-f]{64}$', 'description': "sha256 of the repository's canonical identity (the lowercased 'owner/repo', or a stable local fingerprint) â\x80\x94 never the repo name itself. nittim never sees the name."}, 'client_name': {'type': 'string', 'maxLength': 64, 'description': 'Your own name â\x80\x94 omit to read it from the MCP connection instead.'}, 'convergence': {'enum': ['converged', 'cap_reached'], 'type': 'string', 'description': "Optional: 'converged' (two consecutive clean passes) or 'cap_reached' (stopped for any other reason). Omit if unsure â\x80\x94 the read from `passes` is derived either way."}, 'client_version': {'type': 'string', 'maxLength': 64, 'description': 'Your own version string, if you have one.'}, 'repo_size_bucket': {'enum': ['xs', 's', 'm', 'l', 'xl'], 'type': 'string', 'description': 'A rough size bucket for the repo you looped over.'}, 'first_wave_lenses': {'type': 'integer', 'maximum': 100, 'description': "Optional, with mode 'one_shot' only: how many lenses ran in parallel on pass 1.", 'exclusiveMinimum': 0}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repoUrl', 'moduleKey'], 'properties': {'repoUrl': {'type': 'string', 'minLength': 1, 'description': 'GitHub repository URL or owner/repo. A private repo needs a githubToken.'}, 'moduleKey': {'type': 'string', 'minLength': 1, 'description': "The module's key, e.g. 'secret-scan', 'dependency-cve', 'security', 'privacy', 'gdpr'."}, 'githubToken': {'type': 'string', 'description': 'Optional read-only GitHub token. Without one, only public repos are reachable.'}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes."}, 'content': {'type': 'string', 'description': "The file's full text."}, 'encoding': {'type': 'string', 'description': "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected â\x80\x94 text only in v1."}}}, 'maxItems': 1000, 'minItems': 1, 'description': 'Source files as { path, content }[] â\x80\x94 not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.'}, 'uploadGrant': {'type': 'string', 'description': 'Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.'}}}
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['auditId', 'findingKey'], 'properties': {'ref': {'type': 'string', 'description': "A commit SHA or branch to check instead of the repository's current HEAD. Must be the audited commit or newer."}, 'auditId': {'type': 'string', 'format': 'uuid', 'pattern': '^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$', 'description': 'The audit UUID, from its report link.'}, 'findingKey': {'type': 'string', 'minLength': 1, 'description': "The finding's stable key, as printed beside it in the report's findings list."}}}
最近のツール変更
類似のMCPサーバー
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…