Orcorus Repository Scanner
Scans GitHub repositories for security vulnerabilities, hardcoded secrets, and generates a SECURITY.md report with a security score and tier classification.
Uses an OpenAI-compatible LLM to perform an agentic, multi-turn code review that explores the codebase and produces an OWASP Top 10-aligned security report.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Orcorus Repository ScannerScan https://github.com/myorg/myrepo for security issues"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Orcorus Repository Scanner
A repository security scanner for GitHub repositories, available as both an MCP server and a CLI tool. Orcorus clones a repo, runs static analysis, detects hardcoded secrets, verifies the build, and performs an AI-powered OWASP-aligned security code review — producing a scored SECURITY.md report.
Features
Static analysis — Runs Bandit on Python code to detect common vulnerabilities
Secrets detection — Pattern-based scanning for API keys, tokens, private keys, and credentials
Build verification — Attempts to build/install the project (supports Python, Node, Go, Rust)
Test detection — Identifies test frameworks (pytest, jest, mocha, vitest, unittest)
AI security review — Agentic, multi-turn code review that explores the codebase with tools (read files, search code, list directories) and produces an OWASP Top 10-aligned report. Two backends: any OpenAI-compatible LLM, or the Claude Code CLI driven in print mode
Scoring & tiering — Assigns a 0–100 security score and classifies repos as Gold / Silver / Bronze / Reject
MCP server — Exposes
scan_repo,get_report, andlist_reportstools via FastMCP
Related MCP server: shieldbot
Project Structure
src/ # Core library
__init__.py # Public API: Scanner, ScanConfig, ScanResult
models.py # Data models (ScanConfig, ScanResult)
scanner.py # Main scanning pipeline
analyzers.py # Bandit, secrets, build, test, and quality checks
ai_review.py # Agentic AI security review loop
report.py # SECURITY.md report generation
server.py # MCP server (FastMCP)
scan_repo.py # CLI clientQuick Start
CLI
# With AI review (GitHub repo)
python scan_repo.py https://github.com/owner/repo --api-key sk-...
# Without AI review
python scan_repo.py https://github.com/owner/repo --skip-ai
# Scan a local directory in-place (absolute --subdir path)
python scan_repo.py --name SSH-Command \
--subdir /srv/docker/orcorus-integrations/ssh-command \
--api-key sk-... --model gpt-5.4 --base-url https://api.cometapi.com/v1
# Scan current directory
python scan_repo.py .
# Custom model / provider
python scan_repo.py https://github.com/owner/repo \
--model gpt-5.2 \
--base-url https://api.openai.com/v1 \
--api-key sk-...Claude Code CLI backend
If the claude CLI is installed and logged in, the scanner can hand the review to it instead of calling an API directly. Claude explores the checkout with its own read-only tools (Read, Grep, Glob, LS); no API key is needed.
python scan_repo.py https://github.com/owner/repo --ai-backend claude-cli # model: sonnet
python scan_repo.py https://github.com/owner/repo --ai-backend claude-cli --model opus
python scan_repo.py https://github.com/owner/repo --ai-backend claude-cli \
--ai-timeout 900 --max-budget-usd 2 --json-out result.jsonHow the CLI is invoked, and why:
claude -p --output-format jsonwith the prompt on stdin; the JSON result carries the report plus cost and turn counts, which land inScanResult.ai_cost_usd/ai_turns.Tools are restricted to
Read,Grep,Glob,LSvia--tools/--allowedTools, andBash,Edit,Write, web and agent tools are disallowed, so the reviewer can only look.--setting-sources userand--strict-mcp-configstop a scanned repository's own.claude/settings.json, hooks or MCP config from being honoured. The system prompt also tells the model to treatCLAUDE.md,AGENTS.mdand READMEs in the repo as untrusted evidence.--ai-timeoutbounds the whole review for this backend (default 900s).--max-turnsand--max-budget-usdare passed through when the installed CLI supports them.Nested-session environment variables (
CLAUDECODE,CLAUDE_CODE_*) are stripped so a scan can be launched from inside a Claude Code session.
Set ORCORUS_AI_BACKEND=claude-cli (and optionally ORCORUS_CLAUDE_BIN, ORCORUS_MODEL, ORCORUS_MAX_BUDGET_USD) to use the same backend from the MCP server. The Docker image does not ship the Claude CLI; this backend is meant for host runs.
MCP Server
python server.py
# or
fastmcp run server.pyThe server exposes three tools:
Tool | Description |
| Scan a GitHub repo (runs as a background task) |
| Retrieve a completed SECURITY.md report by name |
| List all available scan reports with scores |
MCP Client Setup
VS Code / Claude Code (settings.json)
Add the following to your MCP settings.json to run Orcorus as a Docker container:
{
"mcpServers": {
"scanner": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "OPENAI_API_KEY=sk-your-api-key-here",
"-e", "ORCORUS_MODEL=gpt-5.2",
"-e", "OPENAI_BASE_URL=https://api.openai.com/v1",
"-e", "ORCORUS_REPORTS_DIR=/app/reports",
"-e", "ORCORUS_WORK_DIR=/app/repos",
"-e", "ORCORUS_AI_TIMEOUT=300",
"-e", "ORCORUS_MAX_TURNS=40",
"orcorus/security_scanner:latest"
]
}
}
}To persist reports between runs, mount a volume:
{
"mcpServers": {
"scanner": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "OPENAI_API_KEY=sk-your-api-key-here",
"-e", "ORCORUS_MODEL=gpt-5.2",
"-e", "OPENAI_BASE_URL=https://api.openai.com/v1",
"-v", "/path/to/local/reports:/app/reports",
"orcorus/security_scanner:latest"
]
}
}
}To skip AI review (static analysis only), add -e, "ORCORUS_SKIP_AI=true" to the args.
Configuration
CLI Arguments
Argument | Default | Description |
|
| GitHub repository URL or local path (ignored when |
| auto-detected | Display name for the report |
| HEAD | Specific commit to checkout |
| (none) | Subdirectory scope, or an absolute path to scan a directory in-place without cloning |
|
|
|
|
| Claude CLI executable name for |
|
| Spend cap per review for |
|
| API key for the LLM provider ( |
|
| Model to use for AI review (default depends on backend) |
|
| OpenAI-compatible API base URL |
|
| Directory to save reports |
|
| Where repositories are cloned |
| (none) | Also write the ScanResult as JSON to this path |
|
| Timeout per AI call ( |
|
| Max agentic review turns |
|
| Skip the AI review step |
|
| Keep the cloned repo after scanning |
Environment Variables (MCP Server)
Variable | Default | Description |
|
|
|
|
| Claude CLI executable for |
|
| Spend cap per review for |
| (none) | API key for AI review ( |
|
| LLM model name |
|
| API base URL |
|
| Reports output directory |
|
| Temporary clone directory |
|
| Timeout per AI call (seconds) |
|
| Max agentic review turns |
|
| Set to |
|
| Set to |
Scoring
Score | Tier |
90–100 | Gold |
75–89 | Silver |
60–74 | Bronze |
0–59 | Reject |
Deductions are applied for high/medium/low Bandit findings, hardcoded secrets, build failures, missing tests, missing README, missing dependency files, and critical/high severity issues found during AI review.
Dependencies
Python 3.10+
openai — LLM client (only for the
openaibackend; imported lazily)Claude Code CLI — only for the
claude-clibackendfastmcp — MCP server framework
bandit — Python static analysis (optional, for security scanning)
git — for cloning repositories
This server cannot be deployed
Maintenance
Related MCP Connectors
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
- VulX WatchOAuthai.vulx
Independent security review for AI-built apps. Watch a GitHub repo. Never a patch.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceDetect live website vulnerabilities and security flaws in GitHub repositories using automated DAST and SAST scanning. Safeguard applications by identifying exposed secrets, insecure dependencies, and common code patterns prone to exploitation. Receive structured fix plans with precise code remediation steps to resolve identified risks and improve security posture.2MIT
- AlicenseAqualityCmaintenanceAI-powered security code review for Claude Code that runs multiple scanners (CodeQL, Semgrep, etc.) to detect vulnerabilities, secrets, and dependency CVEs, producing prioritized reports.23MIT
- AlicenseNot gradedqualityDmaintenanceAI-powered security scanner for Python projects and GitHub repositories. Detects vulnerabilities, secrets, and provides AI risk assessment.11MIT
- FlicenseNot gradedqualityBmaintenanceAutomated security audit assistant for GitHub repositories that detects static vulnerabilities (leaked credentials, vulnerable dependencies, bad Docker practices, excessive GitHub Actions permissions), calculates a security score, and provides risk explanations and mitigation recommendations via Cohere.-