Graneth
Pre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"mcp-server": {
"command": "npx",
"args": [
"@graneth/mcp-server"
]
}
}
}Paquetes ejecutables
0.7.1stdioPuntos de conexión remotos
https://graneth.com/api/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (4)
⚪scan_repository(owner, repo, pull_number, token)
Trigger a Level 1 + Level 2 security scan on a GitHub pull request. Returns SAST findings, taint flows, entropy-detected secrets, and (for PRO users) LLM-triaged results. Requires Graneth authentication.
Esquema de entrada
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository owner"
},
"repo": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository name"
},
"pull_number": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 1000000,
"description": "Pull request number to scan"
},
"token": {
"type": "string",
"maxLength": 200,
"description": "GitHub access token with repo read permissions"
}
},
"required": [
"owner",
"repo",
"pull_number",
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴pre_flight_check(files, context)
Security pre-flight check for local file changes BEFORE committing. Run this whenever you are about to suggest `git commit`, `git push`, or open a pull request — especially when changes touch auth, secrets, SQL queries, package.json / requirements.txt, or environment variables. Returns CLEAR or BLOCKED with specific findings and remediation steps.
Esquema de entrada
{
"type": "object",
"properties": {
"files": {
"maxItems": 50,
"type": "array",
"items": {
"type": "object",
"properties": {
"path": {
"type": "string",
"maxLength": 500,
"description": "Relative file path"
},
"content": {
"type": "string",
"maxLength": 200000,
"description": "Full file content to check"
}
},
"required": [
"path",
"content"
]
},
"description": "Files staged for commit (path + content)"
},
"context": {
"description": "What these changes do (helps with triage)",
"type": "string",
"maxLength": 500
}
},
"required": [
"files"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_findings(owner, repo, file, severity)
Retrieve the security findings recorded by your most recent scan of this repository, optionally filtered by exact file path or severity. Returns an error if you have never scanned it — that is not the same answer as no findings. Checks that could not run are reported as a count, never listed among the findings.
Esquema de entrada
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository owner"
},
"repo": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository name"
},
"file": {
"description": "Filter findings to a specific file path",
"type": "string",
"maxLength": 500
},
"severity": {
"description": "Filter by severity level",
"type": "string",
"enum": [
"critical",
"warning",
"info"
]
}
},
"required": [
"owner",
"repo"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪auto_remediate(owner, repo, token, file, line, ...)
Generate an automated security fix for a specific finding. Creates a GitHub PR with the patched code. Verifies the fix with Level 1 SAST before opening the PR. Requires authentication, 3 credits, and ANTHROPIC_API_KEY.
Esquema de entrada
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository owner"
},
"repo": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository name"
},
"token": {
"type": "string",
"maxLength": 200,
"description": "GitHub token with repo write access"
},
"file": {
"type": "string",
"maxLength": 500,
"description": "File path containing the vulnerability (relative, no traversal)"
},
"line": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 100000,
"description": "Line number of the finding"
},
"finding_type": {
"type": "string",
"maxLength": 100,
"description": "Finding type e.g. 'command_injection', 'sql_injection'"
},
"title": {
"type": "string",
"maxLength": 300,
"description": "Finding title from scan results"
},
"severity": {
"type": "string",
"enum": [
"critical",
"warning",
"info"
],
"description": "Finding severity"
},
"description": {
"type": "string",
"maxLength": 2000,
"description": "Finding description"
},
"recommendation": {
"type": "string",
"maxLength": 2000,
"description": "Recommended fix from scan results"
},
"ref": {
"default": "main",
"description": "Git ref (branch/SHA)",
"type": "string",
"maxLength": 200,
"pattern": "^[a-zA-Z0-9/_.-]{1,200}$"
}
},
"required": [
"owner",
"repo",
"token",
"file",
"line",
"finding_type",
"title",
"severity",
"description",
"recommendation"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}Comunidad
Evidencia