Scans GitHub repositories for security vulnerabilities by cloning, performing static analysis, secret detection, build verification, and AI-powered OWASP-aligned code review, producing a scored SECURITY.md report.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.OPENAI_API_KEY— "-e", "=sk-your-api-key-here",ORCORUS_REPORTS_DIR— "-e", "=/app/reports",ORCORUS_WORK_DIR— "-e", "=/app/repos",ORCORUS_MODEL— "-e", "=gpt-5.2",OPENAI_BASE_URL— "-e", "=https://api.openai.com/v1",ORCORUS_AI_TIMEOUT— "-e", "=300",ORCORUS_MAX_TURNS— "-e", "=40",ORCORUS_SKIP_AI— To skip AI review (static analysis only), add -e, "=true" to the args.ORCORUS_ALLOW_DANGEROUS_BUILDORCORUS_INCLUDE_BUILD_LOGSORCORUS_ALLOW_LOCAL_PATHS— false Set to 1 or true to allow scanning local filesystem paths via MCP[](https://m8ven.ai/mcp/ceilingduster-mcp-security-scanner-hs2ung)