0
/ 100
24 days ago
glama

CodeInspectus

Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
15 live-looking API keys in source: 4 Stripe secret (live), 3 SendGrid API key, 2 Stripe publishable (live)
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCG_LOG_LEVEL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/synvoya-codeinspectus-larcgo)](https://m8ven.ai/mcp/synvoya-codeinspectus-larcgo)
commit: 5c6dec2ad7f44a088bb3668b6cff86a3b6caa714
code hash: b613051cc0aa210a44737b594e0d2d6f1483e69e6afff63e1d73de8e4d5ba0f3
verified: 7/7/2026, 9:58:26 AM
view raw JSON →