Feldspar free repository security scan
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"scan": {
"url": "https://project-feldspar.com/mcp"
}
}
}Remote-Endpunkte
https://project-feldspar.com/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (2)
🟢scan_repository(url)
Clone a public git repository and run feldspar-scan: OSV.dev advisories for pinned dependencies in lockfiles (npm, pnpm, yarn, pip/uv/poetry, Cargo, Go, Gemfile.lock, composer), secret patterns with redacted evidence, and configuration lint. Returns a JSON report with summary counts and per-finding severity, file, line, advisory id and fixed versions. Deterministic, no LLM involved. Takes 2-90 s depending on repository size.
Eingabe-Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "https://github.com/owner/repo (also gitlab.com, codeberg.org, bitbucket.org)"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟢audit_pricing
Describe Project Feldspar's paid code audit (security, correctness, maintainability; three independent review passes plus consolidation and manual verification of every reported file:line), its price, turnaround, and the Stripe checkout URL. No arguments.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Community
Nachweis