Security Vulnerability Scanner

Security Vulnerability Scanner MCP Connector for Claude

A+

Scans code for security vulnerabilities like SQL injection and command injection using AST pattern matching.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

This MCP server provides deterministic security analysis by parsing source code into an Abstract Syntax Tree (AST). It identifies critical risks such as SQL injection, command injection, path traversal, insecure deserialization, and hardcoded credentials. Use scan_source_code to perform a full audit of a directory or file, or get_vulnerability_summary to review security health across multiple scans.

securityastvulnerabilitycode-auditdevops

3 tools expose this connector's capabilities to your AI agent.

get_vulnerability_summary

Provides a high-level statistical overview of security health across multiple scan results

check_pattern_definition

g., SQL_INJECTION) is supported. Validates if a specific vulnerability pattern is currently supported by the engine's logic

scan_source_code

Performs a full security audit on a specific file or directory of code

See how to talk to your AI agent using Security Vulnerability Scanner.

Scan the current directory for any security vulnerabilities.

The scan of the current directory found 2 vulnerabilities: one SQL injection in `db.py` at line 42 and one hardcoded credential in `config.py` at line 12.

Is the pattern 'SQL_INJECTION' supported by the scanner?

Yes, SQL injection is a supported pattern that detects unsafe string concatenation in database queries.

Give me a summary of the security health for scan IDs 'scan_001' and 'scan_002'.

Across the provided scans, there are 3 total vulnerabilities. The risk level is High Risk due to a critical command injection vulnerability.

The scanner uses AST pattern matching to identify dangerous structural patterns in the code, such as string concatenation in SQL queries or unsafe use of system execution functions.

Related Connectors