TTokenySpace
返回 MCP 列表

AI Scanner

开发工具

A powerful tool that scans your codebase to detect LLM SDK usage, AI framework integrations, and exposed API tokens/keys for any LLM provider.

1JavaScriptv1.0.6更新于 2026/3/21
GitHub
0

介绍

Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.

README

<p align="center"> <img src="https://raw.githubusercontent.com/Aakashbhardwaj27/ai-scanner/main/logo.svg" width="80" alt="ai-scanner logo"> </p> <h1 align="center">ai-scanner-mcp</h1> <p align="center"> MCP server for ai-scanner - let AI agents scan codebases for LLM usage, AI frameworks, and exposed secrets. </p> <p align="center"> <a href="https://opensource.org/licenses/MIT"><img src="https://img.shields.io/badge/License-MIT-yellow.svg" alt="License: MIT"></a> <a href="https://nodejs.org/"><img src="https://img.shields.io/badge/node-≥18-brightgreen.svg" alt="Node.js"></a> <a href="https://modelcontextprotocol.io"><img src="https://img.shields.io/badge/MCP-compatible-blue.svg" alt="MCP"></a> </p>

An MCP server that exposes ai-scanner as tools for AI agents. Works with Claude Code, Claude Desktop, Cursor, Windsurf, and any MCP-compatible client.

Tools

ToolDescription
scan_directoryFull scan — LLM SDKs, AI frameworks, exposed tokens, and hardcoded secrets with severity levels
check_secretsSecurity check — pass/fail scan for exposed credentials only. Perfect for pre-commit checks
ai_inventoryAI stack overview — which SDKs, frameworks, models, and API endpoints are used (no secret detection)

Setup

Claude Code

claude mcp add ai-scanner npx ai-scanner-mcp

Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "ai-scanner": {
      "command": "npx",
      "args": ["ai-scanner-mcp"]
    }
  }
}

Config file location:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json

Cursor

Add to .cursor/mcp.json in your project:

{
  "mcpServers": {
    "ai-scanner": {
      "command": "npx",
      "args": ["ai-scanner-mcp"]
    }
  }
}

Windsurf

Add to ~/.windsurf/mcp.json:

{
  "mcpServers": {
    "ai-scanner": {
      "command": "npx",
      "args": ["ai-scanner-mcp"]
    }
  }
}

Example Usage

Once connected, you can ask your AI agent:

  • "Scan this project for any exposed API keys"
  • "Check if there are any hardcoded secrets before I commit"
  • "What AI SDKs and frameworks does this codebase use?"
  • "Run a security scan on ./src and tell me if it's safe to push"
  • "Give me an AI inventory of this project"

Tool Details

scan_directory

Full scan with all detection categories. Parameters:

ParameterTypeDefaultDescription
directorystringrequiredPath to scan
ai_onlybooleanfalseSkip generic secrets (Stripe, GitHub, etc.)
scan_envbooleanfalseInclude .env files
include_endpointsbooleantrueDetect LLM API endpoint URLs
include_modelsbooleantrueDetect model name references

check_secrets

Security-focused pass/fail check. Parameters:

ParameterTypeDefaultDescription
directorystringrequiredPath to scan
ai_onlybooleanfalseOnly check AI tokens
scan_envbooleanfalseInclude .env files

ai_inventory

AI stack awareness (no secret detection). Parameters:

ParameterTypeDefaultDescription
directorystringrequiredPath to scan

Detection Coverage

  • AI Tokens (20+) — OpenAI, Anthropic, Google, AWS, HuggingFace, Groq, Replicate, and more
  • Generic Secrets (59) — Stripe, Twilio, GitHub, Slack, Discord, database URIs, private keys, JWTs
  • LLM SDKs (23) — OpenAI, Anthropic, Google Gemini, LiteLLM, AWS Bedrock, and more
  • AI Frameworks (24) — LangChain, LlamaIndex, CrewAI, AutoGen, DSPy, Vercel AI SDK, and more
  • 145 total detection patterns

License

MIT

评论

加载中…

同类推荐