Feldspar free repository security scan

Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
65%
命名质量
90%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~296token 数(工具定义)
~389 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.23%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "scan": {
      "url": "https://project-feldspar.com/mcp"
    }
  }
}

远程端点

https://project-feldspar.com/mcpstreamable-http

它能做什么

工具清单

工具(2)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢scan_repository(url)

Clone a public git repository and run feldspar-scan: OSV.dev advisories for pinned dependencies in lockfiles (npm, pnpm, yarn, pip/uv/poetry, Cargo, Go, Gemfile.lock, composer), secret patterns with redacted evidence, and configuration lint. Returns a JSON report with summary counts and per-finding severity, file, line, advisory id and fixed versions. Deterministic, no LLM involved. Takes 2-90 s depending on repository size.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "https://github.com/owner/repo (also gitlab.com, codeberg.org, bitbucket.org)"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
🟢audit_pricing

Describe Project Feldspar's paid code audit (security, correctness, maintainability; three independent review passes plus consolidation and manual verification of every reported file:line), its price, turnaround, and the Stripe checkout URL. No arguments.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

社区

评价此服务器

证据

最近观测

已验证未记录版本2 个工具
已验证未记录版本2 个工具