Code Pathfinder

general MCP Server

Static Code Analysis for security teams with Inter file taint analysis. Built for finding vulnerabilities, advanced structural search, derive insights and supports MCP

Verified
generalgeneral
3 views137 stars16 forksApache-2.0

Why This Matters

Discovered via github-seeds and last synced 3mo ago.

Verified
Source
github-seeds
Stars
137
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
21
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (21)

github-token

GitHub token (required when `pr-comment` or `pr-inline` is enabled)

project

Path to source code

37

Root user, exposed secrets, image pinning, multi-stage builds, layer optimization

output-file

Output file path

python-version

Python version to use

10

Privileged mode, socket exposure, capability escalation, network isolation

Input

Description

rules

Path to local Python rule files or directory

debug

Enable debug diagnostics with timestamps

ruleset

Remote ruleset(s), comma-separated (e.g., `python/all`, `docker/security`)

skip-tests

Skip test files

output

Output format: `sarif`, `json`, or `csv`

disable-metrics

Disable anonymous usage metrics

Language

Analysis

refresh-rules

Force refresh cached rulesets

no-diff

Disable diff-aware scanning (scan all files)

fail-on

Fail on severities (e.g., `critical,high`)

pr-inline

Post inline review comments for critical/high findings

verbose

Enable verbose output

158

SQL injection, RCE, SSRF, path traversal, XSS, deserialization, crypto misuse, JWT vulnerabilities

pr-comment

Post summary comment on pull request