PerfOSec functions as a Meta-MCP-Server, addressing the fragmentation, token inefficiency, and lack of orchestration prevalent in existing security and performance scanners. It unifies diverse tools like Semgrep, gitleaks, k6, and Lighthouse under a single interface, intelligently compressing their outputs to overcome LLM context window limitations. The tool features a diff-mode for focused analysis on code changes, baseline suppression for managing known findings, and automatically generates tailored instructions for AI coding assistants such as Claude Code, Cursor, and Gemini. This empowers AI agents to seamlessly verify and stabilize code, streamlining the development workflow by delivering comprehensive security and performance audits with a single, efficient tool call.
주요 기능
010 GitHub stars
02Diff-mode reporting with baseline suppression to focus on new findings
03Automatic generation of AI agent instructions for various coding assistants
04Parallel orchestration of multiple security and performance scanners for aggregated reports
05Automated setup and installation of integrated scanners with OS detection
06Context-aware output compression (SARIF to Markdown, k6 to percentiles) for LLM efficiency