vibecode-checker
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_rulesC | Search baseline and realtime security guidance rules. Set |
| get_ruleC | Return a rule by ID. |
| scan_codeA | 코드 조각을 공공기관 보안 기준으로 점검(보안·검토·체크·검사)합니다. 사용자가 메모리에 있는 코드(붙여넣은 스니펫, 방금 생성한 코드)가 "안전한지", 개인정보·시크릿·SQL 삽입·위험한 코드 실행·LLM 위험이 있는지 묻거나, "보안 점검/검토/체크"를 요청하면 이 도구를 사용하세요. 파일·폴더 경로라면 대신 scan_path 를 씁니다. 코드를 외부 API로 보내지 않습니다. 시크릿·개인정보는 마스킹된 짧은 증거만 반환하며, 각 발견 사항에 why_it_matters(왜 위험한가)와 safe_fix(안전한 수정 방향)가 함께 담깁니다. |
| detect_secrets_and_piiC | Detect secrets, Korean personal information, and internal network values. |
| check_packageA | Check a package against OSV.dev before installing an AI-suggested dependency. |
| scan_dependenciesA | Parse a dependency manifest and check packages with OSV.dev. Only package names and versions are sent to OSV.dev. Source code is not sent. 락파일(poetry.lock·yarn.lock 등)은 파싱하지 못하므로 verdict="unparsed"로
정직하게 거절합니다 — 원본 매니페스트(requirements.txt·package.json)를 주세요.
결과를 scan_path 결과 JSON의 |
| suggest_fixC | Return a public-officer-friendly safe-fix recommendation for a finding. |
| scan_pathA | 파일 또는 폴더를 공공기관 보안 기준으로 점검(보안·검토·체크·검사)합니다. 사용자가 "이 폴더/프로젝트 보안 점검해줘", "이 파일 검토/체크해줘", "안전한지 검사해줘"처럼 로컬 경로를 가리키면 이 도구를 사용하세요. 메모리의 코드 조각이면 대신 scan_code 를 씁니다. "기존 코드베이스 감사" 흐름의 진입점입니다. 경로를 로컬에서 순회하며 빌드·vendor 디렉터리를 건너뛰고 바이너리는 무시하며, 소스 코드를 외부 API로 전혀 보내지 않습니다. 각 발견 사항에는 why_it_matters 와 safe_fix 가 포함됩니다. 검사 후 render_report 로 한국어 보고서를 만드세요. |
| render_reportA | ScanReport(scan_code / scan_path 결과)를 한국어 보고서로 렌더링합니다. 사람이 읽고 결재·보고에 쓸 문서가 필요할 때 사용하세요.
출력은 자체 완결적이라 비전공 이해관계자 공유나 내부 승인 기록 첨부에 적합합니다. |
| list_loaded_rulesA | List loaded guidance rules for debugging and audit. |
| server_statusA | Return runtime diagnostics: package version, rules dir, rule counts, env. Use this from any MCP client (Claude, Cursor, Codex, ...) to verify the server is healthy and to see which rules are loaded. No network calls. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| 보안점검 | 폴더·파일·코드를 한국 공공기관 보안 기준으로 점검하고 한국어 보고서까지 만드는 표준 절차 |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 11 tools
The two scan tools are clearly separated by input type (snippet vs path), and rule/status/report tools are distinct. However, detect_secrets_and_pii overlaps with the broader scan tools' secret/PII detection, and suggest_fix duplicates the safe_fix already included in findings, creating potential misselection.
Tool names consistently use snake_case with an imperative verb_noun structure (search_rules, scan_code, render_report). server_status breaks the verb pattern as a noun phrase, but this is a minor deviation.
At 11 tools, the count is within the healthy 3-15 range and covers scanning, dependencies, rules, diagnostics, and reporting. A couple of tools (suggest_fix, list_loaded_rules) are arguably redundant with existing outputs, making it slightly over-scoped.
The toolset covers the full audit workflow: scanning snippets/paths, dependency checks, fix suggestions, and report rendering in multiple formats. Minor gaps exist, such as no direct finding-listing or batch rule-update operations, but the core domain is well covered.