Feldspar free repository security scan

Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
65%
Naming quality
90%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~296Tokens (tool definitions)
~389 BTypical response size
Minimal attention impact (0.23% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "scan": {
      "url": "https://project-feldspar.com/mcp"
    }
  }
}

Remote endpoints

https://project-feldspar.com/mcpstreamable-http

What it can do

Tool inventory

Tools (2)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢scan_repository(url)

Clone a public git repository and run feldspar-scan: OSV.dev advisories for pinned dependencies in lockfiles (npm, pnpm, yarn, pip/uv/poetry, Cargo, Go, Gemfile.lock, composer), secret patterns with redacted evidence, and configuration lint. Returns a JSON report with summary counts and per-finding severity, file, line, advisory id and fixed versions. Deterministic, no LLM involved. Takes 2-90 s depending on repository size.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "https://github.com/owner/repo (also gitlab.com, codeberg.org, bitbucket.org)"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟢audit_pricing

Describe Project Feldspar's paid code audit (security, correctness, maintainability; three independent review passes plus consolidation and manual verification of every reported file:line), its price, turnaround, and the Stripe checkout URL. No arguments.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded2 tools
verifiedversion not recorded2 tools