devops-infra MCP Server
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Discovered via github-topic:mcp and last synced 2mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
gitleaks v8
Required fields and format validation
family
Built-in pipeline
CRITICAL
Webhook/requestbin exfiltration endpoints
Guide
skillsafety
yes (skills mode)
[docs/integrations/codex-cli.md](docs/integrations/codex-cli.md)
JSON-RPC stdio
supplychain
Cosign signatures and checksum files present (strict+)
osv.dev
Declared `requires.*` vs actual code: network/filesystem/bins/env reads (family+)
Scanner
supplychain
Cisco MCP Scanner
Skill
secrets, cve, supplychain, meta, capability, skillsafety
Unexpected script blocks in primary-language skills (family+)
Python
no
Skill
Tool definitions changed since the approved baseline (family+)
## Integrations
no
Skill
family + attestation + allowlist
[docs/EXAMPLES.md](docs/EXAMPLES.md)
Scanners
None
family + attestation