Graneth
Pre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account.
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"mcp-server": {
"command": "npx",
"args": [
"@graneth/mcp-server"
]
}
}
}実行可能なパッケージ
0.7.1stdioリモートエンドポイント
https://graneth.com/api/mcpstreamable-httpできること
ツール一覧
ツール(4)
⚪scan_repository(owner, repo, pull_number, token)
Trigger a Level 1 + Level 2 security scan on a GitHub pull request. Returns SAST findings, taint flows, entropy-detected secrets, and (for PRO users) LLM-triaged results. Requires Graneth authentication.
入力スキーマ
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository owner"
},
"repo": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository name"
},
"pull_number": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 1000000,
"description": "Pull request number to scan"
},
"token": {
"type": "string",
"maxLength": 200,
"description": "GitHub access token with repo read permissions"
}
},
"required": [
"owner",
"repo",
"pull_number",
"token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴pre_flight_check(files, context)
Security pre-flight check for local file changes BEFORE committing. Run this whenever you are about to suggest `git commit`, `git push`, or open a pull request — especially when changes touch auth, secrets, SQL queries, package.json / requirements.txt, or environment variables. Returns CLEAR or BLOCKED with specific findings and remediation steps.
入力スキーマ
{
"type": "object",
"properties": {
"files": {
"maxItems": 50,
"type": "array",
"items": {
"type": "object",
"properties": {
"path": {
"type": "string",
"maxLength": 500,
"description": "Relative file path"
},
"content": {
"type": "string",
"maxLength": 200000,
"description": "Full file content to check"
}
},
"required": [
"path",
"content"
]
},
"description": "Files staged for commit (path + content)"
},
"context": {
"description": "What these changes do (helps with triage)",
"type": "string",
"maxLength": 500
}
},
"required": [
"files"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_findings(owner, repo, file, severity)
Retrieve the security findings recorded by your most recent scan of this repository, optionally filtered by exact file path or severity. Returns an error if you have never scanned it — that is not the same answer as no findings. Checks that could not run are reported as a count, never listed among the findings.
入力スキーマ
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository owner"
},
"repo": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository name"
},
"file": {
"description": "Filter findings to a specific file path",
"type": "string",
"maxLength": 500
},
"severity": {
"description": "Filter by severity level",
"type": "string",
"enum": [
"critical",
"warning",
"info"
]
}
},
"required": [
"owner",
"repo"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪auto_remediate(owner, repo, token, file, line, ...)
Generate an automated security fix for a specific finding. Creates a GitHub PR with the patched code. Verifies the fix with Level 1 SAST before opening the PR. Requires authentication, 3 credits, and ANTHROPIC_API_KEY.
入力スキーマ
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository owner"
},
"repo": {
"type": "string",
"maxLength": 100,
"pattern": "^[a-zA-Z0-9._-]{1,100}$",
"description": "GitHub repository name"
},
"token": {
"type": "string",
"maxLength": 200,
"description": "GitHub token with repo write access"
},
"file": {
"type": "string",
"maxLength": 500,
"description": "File path containing the vulnerability (relative, no traversal)"
},
"line": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 100000,
"description": "Line number of the finding"
},
"finding_type": {
"type": "string",
"maxLength": 100,
"description": "Finding type e.g. 'command_injection', 'sql_injection'"
},
"title": {
"type": "string",
"maxLength": 300,
"description": "Finding title from scan results"
},
"severity": {
"type": "string",
"enum": [
"critical",
"warning",
"info"
],
"description": "Finding severity"
},
"description": {
"type": "string",
"maxLength": 2000,
"description": "Finding description"
},
"recommendation": {
"type": "string",
"maxLength": 2000,
"description": "Recommended fix from scan results"
},
"ref": {
"default": "main",
"description": "Git ref (branch/SHA)",
"type": "string",
"maxLength": 200,
"pattern": "^[a-zA-Z0-9/_.-]{1,200}$"
}
},
"required": [
"owner",
"repo",
"token",
"file",
"line",
"finding_type",
"title",
"severity",
"description",
"recommendation"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}コミュニティ
エビデンス