npm ai-scanner-mcpstdioMITupdated 5mo ago
MCP server for ai-scanner - let AI agents scan codebases for LLM usage, AI frameworks, and exposed secrets.
O que dá para fazer com AI Scanner?
An MCP server that exposes ai-scanner as tools for AI agents. Works with Claude Code, Claude Desktop, Cursor, Windsurf, and any MCP-compatible client.
Tools
| Tool | Description |
|---|---|
scan_directory |
Full scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levels |
check_secrets |
Security check — pass/fail scan for exposed credentials only. Perfect for pre-commit checks |
ai_inventory |
AI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection) |
Setup
Claude Code
claude mcp add ai-scanner npx ai-scanner-mcp
Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"ai-scanner": {
"command": "npx",
"args": ["ai-scanner-mcp"]
}
}
}
Config file location:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
Cursor
Add to .cursor/mcp.json in your project:
{
"mcpServers": {
"ai-scanner": {
"command": "npx",
"args": ["ai-scanner-mcp"]
}
}
}
Windsurf
Add to ~/.windsurf/mcp.json:
{
"mcpServers": {
"ai-scanner": {
"command": "npx",
"args": ["ai-scanner-mcp"]
}
}
}
Example Usage
Once connected, you can ask your AI agent:
- "Scan this project for any exposed API keys"
- "Check if there are any hardcoded secrets before I commit"
- "What AI SDKs and frameworks does this codebase use?"
- "Run a security scan on ./src and tell me if it's safe to push"
- "Give me an AI inventory of this project"
Tool Details
scan_directory
Full scan with all detection categories. Parameters:
| Parameter | Type | Default | Description |
|---|---|---|---|
directory |
string | required | Path to scan |
ai_only |
boolean | false |
Skip generic secrets (Stripe, GitHub, etc.) |
scan_env |
boolean | false |
Include .env files |
include_endpoints |
boolean | true |
Detect LLM API endpoint URLs |
include_models |
boolean | true |
Detect model name references |
check_secrets
Security-focused pass/fail check. Parameters:
| Parameter | Type | Default | Description |
|---|---|---|---|
directory |
string | required | Path to scan |
ai_only |
boolean | false |
Only check AI tokens |
scan_env |
boolean | false |
Include .env files |
ai_inventory
AI stack awareness (no secret detection). Parameters:
| Parameter | Type | Default | Description |
|---|---|---|---|
directory |
string | required | Path to scan |
Detection Coverage
- AI Tokens (20+) — OpenAI, Anthropic, Google, AWS, HuggingFace, Groq, Replicate, and more
- Generic Secrets (59) — Stripe, Twilio, GitHub, Slack, Discord, database URIs, private keys, JWTs
- LLM SDKs (23) — OpenAI, Anthropic, Google Gemini, LiteLLM, AWS Bedrock, and more
- AI Frameworks (24) — LangChain, LlamaIndex, CrewAI, AutoGen, DSPy, Vercel AI SDK, and more
- 145 total detection patterns
License
Instalação
Adicione AI Scanner ao seu cliente. Escolha o que você usa.
claude mcp add ai-scanner-mcp -- npx -y ai-scanner-mcpcodex mcp add ai-scanner-mcp -- npx -y ai-scanner-mcpamp mcp add ai-scanner-mcp -- npx -y ai-scanner-mcp{
"mcpServers": {
"ai-scanner-mcp": {
"command": "npx",
"args": [
"-y",
"ai-scanner-mcp"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"ai-scanner-mcp": {
"command": "npx",
"args": [
"-y",
"ai-scanner-mcp"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"ai-scanner-mcp","command":"npx","args":["-y","ai-scanner-mcp"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"ai-scanner-mcp": {
"command": "npx",
"args": [
"-y",
"ai-scanner-mcp"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"ai-scanner-mcp": {
"command": "npx",
"args": [
"-y",
"ai-scanner-mcp"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"ai-scanner-mcp": {
"command": "npx",
"args": [
"-y",
"ai-scanner-mcp"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"ai-scanner-mcp": {
"type": "local",
"command": "npx",
"args": [
"-y",
"ai-scanner-mcp"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"ai-scanner-mcp": {
"command": {
"path": "npx",
"args": [
"-y",
"ai-scanner-mcp"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y ai-scanner-mcpRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
3 ferramentas
AI Scanner expõe 3 ferramentas a um agente conectado.
- scan_directory
- Full scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levels
- check_secrets
- Security check — pass/fail scan for exposed credentials only. Perfect for pre-commit checks
- ai_inventory
- AI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection)
Pontuação
70 / 100
Boa
- Documentação22/25
- Manutenção19/25
- Confiança13/20
- Capacidade4/15
- Instalação12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 163 days ago
- Has a release history
- Repository is not archived
- Licensed MIT
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 3 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Histórico de versões
| Versões | Publicada |
|---|---|
| 1.0.6Mais recente | 21 de mar. de 2026 |
| 1.0.5 | 21 de mar. de 2026 |
| 1.0.4 | 21 de mar. de 2026 |
| 1.0.3 | 21 de mar. de 2026 |
| 1.0.2 | 21 de mar. de 2026 |