SecureAI-Scan: Free Open-Source Offline Scanner for MCP Servers and Claude Skills
Key point
SecureAI-Scan is a free, MIT-licensed CLI tool that audits MCP server configurations and skills for vulnerabilities and secrets offline, supporting clients like Claude Code, Cursor, and VS Code.
Details
SecureAI-Scan is a free, open-source (MIT) command-line tool built with Claude Code to audit security configurations for AI coding assistants and MCP servers. The tool operates entirely offline, ensuring no data is uploaded during analysis.
Core Functionality
The secureai-scan installed command reads MCP server configs for Claude Code (including per-project servers), Claude Desktop, Cursor, VS Code, Windsurf, Gemini CLI, Cline, Roo Code, and Amazon Q. It also scans ~/.claude/skills and ~/.claude/plugins. The scanner reports issues such as unpinned packages, known-malicious or vulnerable releases, inline secrets, plaintext transports, and poisoned skill text, pointing to the specific file and line.
Deep Scan and Safety
The --deep flag extends the audit to scan the actual code of each server. For npm-launched servers, it uses npm pack to fetch code without installing or executing it. The tool reads only server entries from configs, never accessing session state or tokens.
Development and Reliability
Developed over approximately 90 commits (with about 40 co-authored by Claude), the project emphasizes a zero-false-positive policy. Every detection rule must pass a corpus of known-safe code and scans of real public repositories before being accepted. The package includes an MCP server and a Claude Skill, allowing Claude itself to scan skills or servers before recommending installation.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.