Feldspar free repository security scan
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"scan": {
"url": "https://project-feldspar.com/mcp"
}
}
}远程端点
https://project-feldspar.com/mcpstreamable-http它能做什么
工具清单
工具(2)
🟢scan_repository(url)
Clone a public git repository and run feldspar-scan: OSV.dev advisories for pinned dependencies in lockfiles (npm, pnpm, yarn, pip/uv/poetry, Cargo, Go, Gemfile.lock, composer), secret patterns with redacted evidence, and configuration lint. Returns a JSON report with summary counts and per-finding severity, file, line, advisory id and fixed versions. Deterministic, no LLM involved. Takes 2-90 s depending on repository size.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "https://github.com/owner/repo (also gitlab.com, codeberg.org, bitbucket.org)"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟢audit_pricing
Describe Project Feldspar's paid code audit (security, correctness, maintainability; three independent review passes plus consolidation and manual verification of every reported file:line), its price, turnaround, and the Stripe checkout URL. No arguments.
输入模式
{
"type": "object",
"properties": {},
"additionalProperties": false
}社区
证据