scan_your_ai_toolkit
🛡️ Scan Your AI Toolkit
Herramientas de gobernanza de IA de código abierto. Cada una funciona de forma independiente como servidor MCP o CLI; juntas forman una malla de gobernanza.
Creado por Maiife — Plano de control de IA empresarial.
Herramientas
Paquete | Descripción | Publicado |
| Tipos y formateadores compartidos utilizados por todos los paquetes del kit de herramientas | ✅ |
| Escáner de entorno de IA — descubre extensiones de IDE, servidores MCP, marcos de trabajo de agentes, claves API, modelos locales | ✅ |
| Escáner de seguridad de servidores MCP — puntúa configuraciones según permisos, sensibilidad de datos, radio de explosión | ✅ |
| "¿Cuál es tu stack de IA?" — tarjeta de perfil compartible de tu kit de herramientas de IA | ✅ |
| Comprobación de salud y auto-reparación de MCP — el "brew doctor" para tu configuración de MCP | ✅ |
| Diario personal de uso de IA — rastrea cómo usas la IA, obtén reflexiones | ✅ |
| Sincronización de memoria de IA entre herramientas — un context.json, sincronizado con Cursor, Claude, MCP | ✅ |
| Analizador de calidad de prompts — puntúa, mejora y revisa tus prompts de IA | ✅ |
| Motor de evaluación LLM-as-judge — puntúa las salidas de los agentes con rúbricas estructuradas | ✅ |
| Rastreador de flujo de trabajo de agentes — rastrea, visualiza y analiza los tramos de ejecución | ✅ |
| Calculadora y optimizador de gastos en IA — informe de costes unificado entre proveedores | ✅ |
| Entrenador de prompts gamificado — niveles, rachas, insignias para mejorar tus prompts | ✅ |
| Auditor de suscripciones personales de IA — encuentra desperdicios en tu gasto de IA | ✅ |
| Recomendador personal de modelos — encuentra el mejor modelo para TUS tareas | ✅ |
| Resumen semanal de IA — el "Spotify Wrapped" de tu uso de IA, semanalmente | ✅ |
Related MCP server: Mund
Inicio rápido
# Scan your AI environment
npx @maiife-ai-pub/probe scan
# Audit your MCP server security
npx @maiife-ai-pub/mcp-audit scan
# Generate your AI Stack profile card
npx @maiife-ai-pub/ai-stack --format svg --output my-stack.svg
# Health check your MCP servers
npx @maiife-ai-pub/mcp-doctor check
# Log an AI interaction
npx @maiife-ai-pub/ai-journal log --tool claude --task coding --duration 30
# Sync AI context across tools
npx @maiife-ai-pub/context-sync push
# Score your AI prompts
npx @maiife-ai-pub/prompt-score analyze --input prompt.txt
# Evaluate agent outputs with rubrics
npx @maiife-ai-pub/eval score --rubric code-review --input review.txt
# Trace agent workflows
npx @maiife-ai-pub/trace list --days 7
# Track AI spend across vendors
npx @maiife-ai-pub/cost report --period last-30d
# Gamified prompt coaching
npx @maiife-ai-pub/prompt-craft score --input prompt.txt
# Audit AI subscriptions for waste
npx @maiife-ai-pub/sub-audit
# Find the best model for your tasks
npx @maiife-ai-pub/model-match recommend --task coding
# Generate your AI week in review
npx @maiife-ai-pub/weekly-ai-report generateUso como servidor MCP
Cada herramienta con un servidor MCP puede añadirse a Claude Desktop, Cursor o cualquier cliente compatible con MCP. Cada una expone herramientas a través del transporte stdio.
~/Library/Application Support/Claude/claude_desktop_config.json (macOS) o %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"maiife-probe": {
"command": "npx",
"args": ["@maiife-ai-pub/probe", "mcp"]
},
"maiife-mcp-audit": {
"command": "npx",
"args": ["@maiife-ai-pub/mcp-audit", "mcp"]
},
"maiife-mcp-doctor": {
"command": "npx",
"args": ["@maiife-ai-pub/mcp-doctor", "mcp"]
},
"maiife-eval": {
"command": "npx",
"args": ["@maiife-ai-pub/eval", "mcp"]
},
"maiife-prompt-score": {
"command": "npx",
"args": ["@maiife-ai-pub/prompt-score", "mcp"]
},
"maiife-prompt-craft": {
"command": "npx",
"args": ["@maiife-ai-pub/prompt-craft", "mcp"]
},
"maiife-cost": {
"command": "npx",
"args": ["@maiife-ai-pub/cost", "mcp"]
},
"maiife-model-match": {
"command": "npx",
"args": ["@maiife-ai-pub/model-match", "mcp"]
},
"maiife-ai-stack": {
"command": "npx",
"args": ["@maiife-ai-pub/ai-stack", "mcp"]
},
"maiife-context-sync": {
"command": "npx",
"args": ["@maiife-ai-pub/context-sync", "mcp"]
},
"maiife-sub-audit": {
"command": "npx",
"args": ["@maiife-ai-pub/sub-audit", "mcp"]
},
"maiife-trace": {
"command": "npx",
"args": ["@maiife-ai-pub/trace", "mcp"]
}
}
}Elige las herramientas que necesites; no tienes que añadirlas todas. Una vez configurado, Claude puede llamar a herramientas como probe_scan, mcp_audit_scan, eval_score, prompt_score_analyze, cost_report y más directamente desde el chat.
Ejecutar con Docker
Cada servidor MCP se publica como una imagen de Docker en GHCR. Útil para entornos aislados o integración con Glama.
# Pull and run any server
docker run -i ghcr.io/sakthivelchan89/maiife-probe
docker run -i ghcr.io/sakthivelchan89/maiife-mcp-audit
docker run -i ghcr.io/sakthivelchan89/maiife-eval
# ... same pattern for all 12 packages
# Or build from source
docker build -f packages/probe/Dockerfile -t maiife-probe .
docker run -i maiife-probeLas imágenes de Docker utilizan transporte stdio (sin puertos expuestos). Pasa -i para una comunicación interactiva stdin/stdout con clientes MCP.
Calidad y cumplimiento
Este kit de herramientas tiene como objetivo cumplir con los estándares de calidad MCP Tier 1 (según MCP SEP-1730). Esto es lo que significa:
Dimensión | Estado |
Licencia | Apache 2.0 — SPDX canónico, aprobado por OSI |
Transporte | solo stdio (sin exposición a red) |
CI/CD | GitHub Actions: lint + comprobación de tipos + pruebas en Node 18, 20, 22 |
Cobertura de pruebas | vitest + |
Conformidad MCP | Suite de cumplimiento de protocolo para los 12 servidores MCP |
Escaneo de seguridad | CodeQL (semanal + en PR), Dependabot (semanal) |
Respuesta a vulnerabilidades | 48h CRÍTICO / 7d ALTO (ver DEPENDENCY_POLICY.md) |
SLA de triaje de incidencias | 2 días hábiles (ver CONTRIBUTING.md) |
Versionado | SemVer, sincronizado entre paquetes, CHANGELOG.md |
Cadena de suministro |
|
Seguridad de contenedores | Usuario no root, sin puertos expuestos, firmado por GHCR |
Suite de pruebas de conformidad
Cada servidor MCP en este repositorio se valida contra el contrato del protocolo MCP:
✅ Invariante de transporte stdio (sin salida no JSON en stdout)
✅ El handshake
initializeresponde conserverInfo+ capacidades válidas✅
tools/listdevuelve el conjunto de herramientas documentado✅ Todos los campos
inputSchemade las herramientas son objetos JSON Schema válidos✅ Las llamadas a herramientas desconocidas devuelven errores estructurados (no bloqueos)
Ejecuta la suite:
pnpm test:conformance # all packages
cd packages/probe && pnpm test:conformance # single packageDocumentación
SECURITY.md — política de reporte de vulnerabilidades
CONTRIBUTING.md — directrices de incidencias/PR y SLAs
CHANGELOG.md — historial de versiones (formato Keep a Changelog)
DEPENDENCY_POLICY.md — criterios de selección de dependencias y SLAs de parches
Contribución
¡Las contribuciones son bienvenidas! Lee CONTRIBUTING.md para la guía completa. Versión rápida:
Haz un fork del repositorio en GitHub
Crea una rama:
git checkout -b feat/my-improvementRealiza tus cambios — cada paquete reside en
packages/<nombre>/Ejecuta las pruebas:
pnpm test && pnpm test:conformanceAbre un PR contra
main— describe qué cambiaste y por qué
Por favor, sigue el estilo de código existente (TypeScript, ESM, Vitest para pruebas). Cada paquete debería funcionar tanto como CLI como servidor MCP cuando sea aplicable.
Licencia
Apache 2.0 — libre de usar, modificar y distribuir.
Parte de la plataforma Maiife — Plano de control de IA empresarial.
Available Tools
1 toolprobe_scanA
Scan the current environment for AI tools, MCP servers, agent frameworks, API keys, and local models
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | Root path to scan (defaults to current directory) | |
| scope | No | Scan scope: full=everything, quick=IDE+MCP only, category=specific | full |
| categories | No | Comma-separated categories: ide,mcp,agents,keys,models,deps | |
| includeProjectDeps | No | Scan package.json/requirements.txt for AI dependencies |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must disclose behavioral traits. The word 'Scan' suggests a read operation, but there is no mention of side effects, permissions, safety, or potential impact on the environment. For a tool that scans files and possibly accesses sensitive data (API keys), this is a significant omission.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that front-loads the action and key details. Every word contributes to understanding the tool's purpose, with no filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema and 4 optional parameters, the description fails to cover what the tool returns (e.g., a list of found items, JSON output). The agent lacks information on how to interpret results, which is critical for a scanning tool. Additionally, it does not explain the behavior of different scopes or categories beyond what the schema provides.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description does not add any additional meaning beyond the schema; it simply restates the categories listed in the 'categories' parameter description. No deeper semantics are provided.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Scan') and the specific resources ('AI tools, MCP servers, agent frameworks, API keys, local models'), making it easy for an AI agent to understand the tool's purpose. No sibling tools exist, so differentiation is not required.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
While there are no sibling tools to compare against, the description implies the tool is for enumeration and discovery, which is sufficient. However, it lacks explicit guidance on when to use it (e.g., initial reconnaissance vs. targeted search), leaving some ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Added
probe_scan
1 tool update
- Removed
probe_scan
1 tool update
v0.1.3- First observed
probe_scan
TDQS
Scored across 1 tool
Only one tool exists, so there is no possibility of ambiguity.
With a single tool, naming consistency is not applicable; the name 'probe_scan' is clear and descriptive.
One tool is too few for a toolkit; it feels thin and does not provide a meaningful set of capabilities.
The single scan tool likely misses complementary operations like listing previous scans, filtering, or exporting results, leaving the surface incomplete.
Maintenance
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Find, compare, and audit software for AI agents. Scored registry of tools and MCP servers.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Related MCP Servers
- AlicenseAqualityAmaintenanceagent-bom v0.104.0 is an open security scanner and self-hosted control plane for AI, MCP, and cloud infrastructure. The default scan profile in MCP server mode exposes 8 MCP tools. Additional profiles provide inventory, findings, compliance, graph, and runtime workflows.831Apache 2.0
- AlicenseNot gradedqualityAmaintenanceMCP security scanner for AI agents - detects prompt injection, secrets, PII, and vets MCP servers before installationApache 2.0
- AlicenseAqualityCmaintenanceReputation scoring for AI agent wallets on Base. 9 tools for trust scores, fraud checks, blacklist lookups, leaderboard, badge generation, and agent registration with x402 payment verification.933 npm1MIT
- AlicenseNot gradedqualityNot gradedmaintenanceOpen-source AI governance toolkit — MCP servers & CLIs for scanning, auditing, and managing your AI environment1-