01Detects Command Injection (OWASP A03) and Credential Exposure (OWASP A07)
02Can run as an MCP server itself, enabling direct auditing via AI agents
03Integrates with CI/CD pipelines via GitHub Actions and programmatic API
04Identifies Excessive Permissions (OWASP A05) and Auth Bypass vulnerabilities
05Supports scanning Claude Desktop, Cursor, and custom JSON MCP configs
061 GitHub stars
07Comprehensive scanning for Prompt Injection (OWASP A01)