vibescan-mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| vibescan_scanA | Scan a project directory for leaked secrets and security issues. Detects:
Returns issues with severity, file location, description, and fix suggestion. All scanning runs locally — your code never leaves your machine. Args: path: Project directory to scan (default: current directory) min_severity: Minimum severity to report — critical, high, medium, low, info (default: info) |
| vibescan_rulesA | List all available VibeScan detection rules. Returns the full list of 17 detection rules with their IDs, names, and descriptions. Useful for understanding what VibeScan checks for. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one lists detection rules, the other performs scans. There is no overlap or ambiguity.
Both tool names follow a consistent 'vibescan_' prefix with a verb_noun pattern ('rules' for list, 'scan' for execute), making it predictable.
With only 2 tools, the set is slightly below the typical 3-15 range, but it is still reasonable for a focused security scanner. Each tool serves a distinct and necessary function.
The set covers the core workflow of learning about rules and running scans. A minor gap is the absence of a tool to view a single rule in detail, but the overall surface is adequate for the domain.