Skip to main content
Glama

Cheen - mcp-audit

项目描述

基于MCP Server协议的前端安全依赖审计工具

工具支持本地工程和远程仓库,包含CVSS、CWE、依赖链等关键审计信息。

审计结果为标准化 markdown 文件

现在是MVP版本

🚀 后续可能支持

  • monorepo工程如何处理

  • 适配不同的仓库

  • 适配不同的本地环境

  • 图形展示依赖关系 ……

Related MCP server: mcp-web-audit

审查结果示例:

@cheen/project审计结果

您所审计的工程总共有 2 个风险漏洞。

其中:

  • 严重漏洞:共计 0

  • 高危漏洞:共计 0

  • 中危漏洞:共计 2

  • 低危漏洞:共计 0

说明:

  • 严重漏洞被认为是极其严重的,应该立即修复。

  • 高危漏洞被认为是严重的,应该尽快修复。

  • 中危漏洞被认为是中等严重的,可以选择在时间允许时修复。

  • 低危漏洞被认为是轻微的,可以根据自行需要进行修复。

下面是漏洞的详细信息

中危漏洞

共计 2

esbuild

漏洞描述

依赖关系

  • @cheen/project / vitest / vite-node / vite / esbuild

  • @cheen/project / vitest / vite / esbuild

漏洞包所在目录

  • node_modules/esbuild

vue-template-compiler

漏洞描述

依赖关系

  • @cheen/project / vue-tsc / @vue/language-core / vue-template-compiler

漏洞包所在目录

  • node_modules/vue-template-compiler

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    A Node.js-based frontend security audit tool that performs comprehensive dependency security audits for both local projects and remote repositories. Generates detailed Markdown reports with vulnerability detection, risk assessment, and fix recommendations.
    1
    5 npm
    7
    ISC
  • A
    license
    A
    quality
    D
    maintenance
    An AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time MITRE CWE data and npm audit. It enables users to perform comprehensive scans for authentication issues, exposed secrets, and dependency risks with structured remediation steps.
    2
    6 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time data from MITRE CWE and npm audit. It enables deep analysis of authentication, API security, and dependencies to provide structured findings and remediation steps.
    2
    6 npm
    1
    MIT