Your AI's Senior Security Engineer. Instantly audits local code for OWASP risks and leaked secrets.
About
**What it does:** Security Auditor Pro upgrades your local AI agent (Claude Desktop, Cursor, Antigravity) into a Senior DevSecOps Engineer. It gives your AI the native ability to deeply scan your local codebase and hunt for severe security risks—like hardcoded API keys, dangerous arbitrary code execution (e.g., eval()), and critical OWASP Top 10 vulnerabilities (like SQL injections and XSS).
**How it works:** Built natively on the Model Context Protocol (MCP), it securely exposes the `audit_codebase` tool to your AI. When asked to review a file or an entire directory, the server rapidly scans the raw code for dangerous anti-patterns and leaked secrets, compiling a structured threat report directly into the AI's context window. The AI then explains the vulnerabilities to you and writes the exact patches needed to secure them.
**Who it's for:** This tool is built for developers, agency owners, and security researchers who want to ensure their code is perfectly secure before shipping to production. Instead of paying for an expensive manual security audit, simply ask your AI to *"audit the /src directory"* and instantly secure your application.
Security Report
This security auditor MCP server has a clear purpose and appropriate permissions for local file scanning, but contains several security concerns that limit its reliability. The main issues are: inadequate input validation allowing directory traversal attacks, overly simplistic pattern-matching for security scanning that produces false positives/negatives, potential sensitive data exposure in error messages, and lack of proper output escaping. While not malicious, these flaws undermine the server's credibility as a security tool and create exploitable attack surfaces. Package verification found 1 issue.
2 files analyzed · 9 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Install instructions and configuration are available after purchase.
Getting Started
Once installed, try these example prompts and explore these capabilities:
- 1"Audit my entire /backend directory for security risks"
- 2"Check this auth.js file for any leaked secrets or dangerous code"
- 3"Scan the current workspace for OWASP Top 10 vulnerabilities"
- 4Tool: audit_codebase: Scans a target path for hardcoded secrets and dangerous patterns
Reviews
No written reviews yet. Be the first!
More Security MCP Servers
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
Google Workspace MCP
Freeby Taylorwilsdon · Productivity
Control Gmail, Calendar, Docs, Sheets, Drive, and more from your AI