What it does
A local security MCP server and CLI that scans JavaScript and TypeScript code, including code written with AI tools. It combines Opengrep, Gitleaks and Trivy, and checks for exposed secrets, Supabase row level security and prompt injection. It runs on your machine and sends no code over the network during scans.
Use cases
- 01Check a repository for exposed secrets
- 02Review Supabase row level security settings
- 03Run a scan, fix the findings and scan again