Skip to main content
Glama
thfothijn

opzyai

by thfothijn

Opzyai MCP — local security check for AI coding agents

CI npm license

Source for @opzyai/mcp — an MCP server that scans the project in your workspace for the mistakes that ship secrets and vulnerabilities to production, entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.

Built by Opzyai — security for apps built with AI tools like Cursor, Lovable, v0 and Bolt.

Install

# Claude Code
claude mcp add opzyai -- npx -y @opzyai/mcp
// Cursor / generic MCP client
{
  "mcpServers": {
    "opzyai": { "command": "npx", "args": ["-y", "@opzyai/mcp"] }
  }
}

Related MCP server: CodeInspectus

What it checks

One tool — security_check({ path?, offline? }) — runs four detectors:

Detector

Catches

Working-tree secrets

API keys/tokens hardcoded in source (OpenAI, Anthropic, Stripe, Supabase service-role, AWS, GitHub, …)

.env exposure

env files committed or not gitignored

Git-history secrets

credentials committed once and "removed" — still recoverable from history

Dependency CVEs

known-vulnerable packages via OSV (package-lock.json, pnpm-lock.yaml, yarn.lock)

Detection is precision-first: an explicit allowlist keeps intentionally-public values (Stripe pk_*, Supabase anon keys) from ever being flagged.

Privacy

Everything runs locally over stdio. The only network call is the OSV dependency check — package names + versions only, never your code — and offline: true disables even that.

Repository layout

This is the public source mirror of the local scanner; it is developed inside the private Opzyai monorepo and synced here on each release, byte-identical.

packages/
  mcp-local/   @opzyai/mcp — the MCP server published to npm
  detectors/   @appsec/detectors — shared secret-detection patterns + allowlist
  core/        @appsec/core — trimmed shim (shared types only; the full package is server-side)

Develop

pnpm install
pnpm typecheck && pnpm test   # vitest, all packages
pnpm build                    # tsup → packages/mcp-local/dist/cli.js

Requires Node >= 20 and git on PATH (for the git-history detector's tests).

  • Free URL scan (no account): paste your deployed URL at opzyai.com/scan — passive check for leaked client-bundle keys, exposed .env/.git/source maps, missing headers.

  • Hosted Pro MCP: deep scans of repos you own (dependency CVEs, SAST, git-history secrets) plus propose_fix — the exact change for your agent to apply: opzyai.com/mcp.

License

MIT © Opzyai

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    B
    maintenance
    Predeploy security scanner for AI-generated code. 80+ vulnerability patterns across secrets, auth, injection, config, Supabase, and logging. Runs locally, code never leaves your machine. Optional x402 witnessed attestation.
    79
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
    6
    305
    39
    MIT
  • F
    license
    -
    quality
    C
    maintenance
    Enables local security scanning and compliance gap analysis for code and text, detecting secrets, PII, and OWASP vulnerabilities, and assessing readiness across major frameworks like NCA, ISO 27001, NIST CSF, and SOC 2.

View all related MCP servers

Related MCP Connectors

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/thfothijn/opzyai-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server