Skip to main content
Glama

security_review

Scan code for injection, XSS, secrets, CORS issues, and insecure comparisons. Get severity-graded findings without LLM. Suppress false positives via .ai-patterns.json.

Instructions

Scan for security patterns: injection (eval/exec/spawn/SQL/template), XSS, secrets, CORS*, insecure compare. Severity-graded, zero LLM. Suppress via malong-ignore or .ai-patterns.json. Out of scope: SSRF/XXE/deserialization/auth.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
fileNoFile path relative to workspace_dir to scan (reads from disk)
scopeNoDirectory relative to workspace_dir to scan recursively (default: none, single file only). scope wins over file/source if both passed
sourceNoSource code text to scan (mutually exclusive with file)
max_findingsNoMax findings per file to return (default: 50)
workspace_dirYesREQUIRED: absolute path of the project root to scan

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/wulun811/LiuHe'

If you have feedback or need assistance with the MCP directory API, please join our Discord server