SecureCode MCP
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@SecureCode MCPScan my codebase for security vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
SecureCode MCP
Standalone MCP (Model Context Protocol) server for SecureCode AI. Provides security scanning tools to AI coding assistants — Cursor, Claude Code, Codex, Windsurf, and other compatible MCP clients — without requiring the VS Code extension.
Install
npm install -g @securecode-ai/mcpOr use directly with npx (no install needed):
npx @securecode-ai/mcp scan src/app.tsRelated MCP server: Secure Code Review MCP Server
Quick Start
securecode-mcp login # Authenticate (email + OTP)
securecode-mcp doctor # Verify your setup works
securecode-mcp scan src/app.ts # Scan a file from the CLI
securecode-mcp serve # Start the MCP server (for AI clients)CLI Commands
securecode-mcp serve [--workspace <path>] Start the MCP stdio server
securecode-mcp login [--api-url <url>] Authenticate via email + OTP
securecode-mcp status Show current auth status
securecode-mcp logout Remove stored credentials
securecode-mcp scan <filePath> [--json] Scan a single file
[--depth <fast|deep|agent>] [--workspace <path>]
securecode-mcp doctor Verify setup (credentials, API, scan)
securecode-mcp --help Show helpScan from CLI
# Agent scan (deep, AI-powered)
securecode-mcp scan src/app/api/users/route.ts
# Fast scan (no AI, free, <5s)
securecode-mcp scan src/lib/auth.ts --depth fast
# JSON output for CI
securecode-mcp scan src/app.ts --json
# Exit codes: 0 = no findings, 1 = findings found, 2 = errorCI/CD Example
# GitHub Action
- name: SecureCode scan
run: |
npm install -g @securecode-ai/mcp
securecode-mcp login # or set SECURECODE_API_TOKEN
securecode-mcp scan src/ --json > scan-results.json
# Exit 1 if findings foundMCP client configuration
Cursor / Windsurf
{
"mcpServers": {
"securecode": {
"command": "npx",
"args": ["-y", "@securecode-ai/mcp@latest", "serve", "--workspace", "/path/to/your/project"],
"env": {
"SECURECODE_API_TOKEN": "your-api-token-here"
}
}
}
}Or if installed globally:
{
"mcpServers": {
"securecode": {
"command": "securecode-mcp",
"args": ["serve", "--workspace", "/path/to/your/project"]
}
}
}Claude Code
claude mcp add securecode -s user -- securecode-mcp serve --workspace /path/to/your/projectTools (17)
Scanning
Tool | Description | Approval |
| Scan code for vulnerabilities (AI pipeline) | No |
| Agent-mode deep scan with 20+ tools, structured proof, and sandbox verification | No |
| Sequential batch scan: map + architecture scout + scan top N files one at a time | No |
| Scan multiple files in one call | No |
| Scan for hardcoded secrets and PII (local, no AI) | No |
| Scan lockfiles for known vulnerabilities (OSV/NVD) | No |
Project Analysis
Tool | Description | Approval |
| Run the AI architecture scout: ranked important files, trust boundaries, security controls, recommended scan order (uses AI credits, cached per depth) | No |
Fixes & Testing
Tool | Description | Approval |
| Generate a patch for a specific finding | Yes |
| Endpoint red-team testing (beta) with deterministic corroboration — findings arrive confirmed/refuted with rule citations, not just "suspected" | Yes |
| Run tests in sandbox for verification | Yes |
Agent Memory (FP Learning)
Tool | Description | Approval |
| Dismiss a finding as FP — agent learns not to report it | No |
| View learned false positives and known facts | No |
| Clear all agent memory (or one FP by ID) | No |
| Add a project fact for faster investigations | No |
Finding Review
Tool | Description | Approval |
| Review the finding queue for a workspace | No |
| Accept or reject a finding in the review queue | No |
| Clear all finding reviews for a workspace | No |
How Agent Memory Works
When the agent reports a false positive, dismiss it with record-false-positive. The agent stores the pattern in .securecode/agent-memory.json and will not report similar patterns in future scans of that workspace.
Scan 1: Agent reports csp_bypass → You dismiss as "intentional design"
Scan 2: Agent sees the FP memory → skips similar patterns → fewer false positivesMemory is per-workspace, user-owned, and deletable. No cross-tenant leakage.
Agent Scan Architecture
The agent scan (securecode.agent-scan) is an AI security investigator that:
Maps the project architecture (architecture scout with trust boundaries, security controls, risks)
Reads the target file and related files across the codebase
Traces data flows (taint tracking, cross-file flow with structured source→sink→hop chains)
Checks guards, endpoint policies, and configuration
Verifies threat model applicability and capability reachability
Self-critiques before reporting (selfCritique field)
Gets reviewed by an independent critique LLM
Proves findings in a sandbox (PROVEN/UNPROVEN)
Runtime-verifies HTTP findings the sandbox can't reach — with your approval, executes baseline + attack requests against your local dev server to confirm real-world impact
Generates fixes for proven findings
Agent tools (20+): read_file, search_code, trace_flow, trace_flow_cross_file, check_guard, check_policy, get_endpoints, list_imports, list_files, call_graph, git_blame, git_history, git_diff, check_dependencies, read_config, find_definition, find_references, find_tests, run_tests, finish.
The deterministic control plane enforces proof quality:
Every finding requires source, reachability, control, threat-model, and impact evidence
Unproven concerns become investigation notes, not findings
Architecture risks expand across related files (callers, implementations, sinks)
The finish gate rejects finish while proof requirements remain unsatisfied
Languages: JavaScript, TypeScript, Python (partial).
Runtime Verification
Some findings can't be proven in a sandbox — auth bypasses, runtime-dependent behavior, effects that only manifest in a live server. When an agent scan produces an HTTP-shaped finding that the sandbox couldn't prove, SecureCode can verify it against your local dev server:
The agent generates a minimal probe plan (a baseline request + attack requests) grounded in its attack library
You approve the probe once per scan (60-second approval window — silently skipped if you don't respond)
SecureCode executes the plan against
127.0.0.1:<port>and maps the outcome to a deterministic verdict
Confirmed probes upgrade the finding to impact-confirmed with live response evidence.
Safety rails:
Localhost only — no external traffic, ever
Unauthenticated endpoints only; auth headers (
Authorization, cookies, API keys) are stripped from generated plansRelative paths only, whitelisted methods, read-only payloads
Max 8 requests per finding, max 3 probed findings per scan (severity-ordered)
Plan credits are refunded if no probe can run
Dev server discovery (first match wins):
SECURECODE_DEV_SERVER_PORTenvironment variable.securecode/runtime-probe.jsonin the workspace root:{ "port": 3000 }Auto-detect across common dev ports (3000, 3001, 4000, 5173, 5174, 8000, 8080)
Disable entirely with SECURECODE_DISABLE_RUNTIME_PROBE=1.
Note: probes currently fire for findings on endpoints the project map can detect (Express/Fastify-style routes). Support for other frameworks is on the roadmap.
Environment Variables
Variable | Default | Description |
| — | API token (alternative to login) |
|
| API base URL |
| — | Set to |
| auto | Local dev server port for runtime verification |
| — | Set to |
Security
Credentials stored in OS keychain (Windows Credential Manager, macOS Keychain, Linux Secret Service) with file fallback (
~/.securecode/credentials.json, mode 0600).File reads are confined to the
--workspaceroot.Fixes are returned for review and never auto-applied.
Agent memory is per-workspace (
.securecode/agent-memory.json), never sent to the API.No telemetry.
Development
npm install
npm run build
npm testLicense
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
- ArcjetOAuthcom.arcjet
An MCP server for Arcjet - the runtime security platform that ships with your AI code.
Related MCP Servers
AlicenseNot gradedqualityAmaintenanceAn MCP server that enables easy integration with coding assistants, providing security context to AI agents. This runs locally using the Snyk CLI.55Apache 2.0- FlicenseNot gradedqualityDmaintenanceLocal MCP server that scans code for security issues (secrets, dependencies, configurations, risky patterns) and integrates with GitHub Copilot in VS Code for automated pre-commit reviews.-
- AlicenseNot gradedqualityBmaintenanceA production-ready MCP server that enables AI assistants to intelligently understand, analyze, edit, navigate, and review software projects with multi-workspace support, Git integration, and semantic search.1MIT
- AlicenseAqualityBmaintenanceA local MCP server that scans repository dependencies for known vulnerabilities (CVEs) using OSV.dev, enriches findings with NVD and CISA KEV data, and supports triage, remediation, and accepted risk management directly from an AI coding assistant.622 npm1MIT