security-preflight
io.github.jdhart81/security-preflight·v1.3.1Static MCP, source-code and injection-indicator checks with redacted signed receipts.
Usage numbers are collected on the next scan
Reviews
Write oneNobody has reviewed security-preflight yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Tools (5, 1 write)
write = sends, deletes, buys or postsdescribe_agentFreeDescribe scope, evidence boundary, inputs, and outputs.
get_security_receiptFreeRead a previously issued public, input-redacted receipt.
scan_sourceFree$1 bounded inline VulnCanon source scan; indicators, not proven exploits. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.
screen_injectionFree$1 batch of 1–20 text samples screened for deterministic injection markers. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.
security_preflightwrite actionFreeRun a $1 static Security Preflight and return a signed receipt. New x402 payer wallets may receive the fleet-wide $0.01 introductory call. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.
Public scan report
scanner v0.1.2 · 2026-09-18 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 1816ms20/20
- Tool poisoning5 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (1)
- highWrite-action tools reachable without authentication
auth.open-write
Install directly
claude mcp add --transport http security-preflight https://mcp.viridis-security.com/security-preflight/mcp
Alternatives to security-preflight
Same job, ranked by rating then adoption.
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewed—A- TroothLook up a witnessed Trust Profile, read a domain's security surface, or verify a Trust Ledger Token.not reviewed—A
- b/citedAEO tools: scan any URL for AI-citation readiness, read the public leaderboard and citation panel.not reviewed—B
- FlowSentrySecurity scanner for n8n workflows + live MCP Trust-Check. 18 rules, OWASP mapped. Paid x402 API.not reviewed—C