Vaspera Hardening MCP server
Enterprise certification for codebases with multi-agent security, reliability, and quality audits
Usage numbers are collected on the next scan
Reviews
Write oneNobody has reviewed Vaspera Hardening yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Vaspera Hardening tools (28, 2 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
agent_completeSignal that an agent has completed its validation run. Must include summary with findings count and confidence score.
agent_cross_verifyCross-verify a finding from another agent. Increases or decreases confidence based on verification.
agent_submit_findingwrite actionSubmit a finding from a validation agent during certification. Each finding must have a unique ID, severity, and evidence.
autofix_applyApply an automatic fix for a certification finding. Use autofix_preview first to see what will change.
autofix_list_patternsList all available auto-fix patterns that can be applied to findings.
autofix_previewPreview an automatic fix for a certification finding without applying it. Returns the before/after diff.
certification_consensusCalculate consensus score and certification level from all agent findings. Requires all requested agents to have completed. Set auto_cross_verify: true (default) to automatically cross-verify critical findings if blocked.
certification_cross_verifyBatch cross-verify critical findings. In "auto" mode (default), automatically verifies all critical findings based on agent domain overlap. In "manual" mode, verifies only specified finding IDs. Run this after all agents complete to unblock consensus calculation.
certification_dashboardPortfolio-wide view of enterprise certifications across all projects. Shows certification status, levels, and expiry.
certification_export_sarifExport certification findings to SARIF format for GitHub Security, SonarQube, or other tools.
certification_filterFilter certification findings by severity, agent, category, file, or confidence level.
certification_finalizeFinalize certification and generate CERTIFICATION.md and CERTIFICATION.json artifacts.
certification_startInitialize an enterprise certification process for a project. Creates certification directory and metadata. Returns certification ID for tracking.
certification_statusCheck the current status of a certification process including which agents have completed.
certification_summaryGet a progressive disclosure summary of certification findings grouped by severity, agent, file, and category.
hardening_dashboardCompare production readiness across all Vaspera projects. Shows which projects have been audited, their readiness scores, issue counts, and what phases have been completed. Use to prioritize which project to harden next.
hardening_get_commandRetrieve the full prompt text for a specific hardening command. Use this to execute a hardening phase against a project. Available commands: audit, fix-critical, fix-high, fix-medium, fix-rls, add-tests, verify, harden.
hardening_installInstall the production hardening slash commands into a project's .claude/commands/ directory. After installation, Claude Code can use /audit, /fix-critical, /fix-high, /fix-medium, /fix-rls, /add-tests, /verify, and /harden in that project.
hardening_install_allInstall hardening slash commands into every discovered project in the workspace. Scans the base directory, finds all projects, and installs commands to each one. Defaults to dry-run mode for safety - set dry_run: false to apply changes.
hardening_list_commandsList all available production hardening commands with their descriptions. Use to understand what commands are available and what order to run them.
hardening_list_projectsDiscover all projects in the Vaspera workspace directory. Returns project names, paths, and whether hardening commands are already installed. Set VASPERA_PROJECTS_DIR env var to override the default directory (~/Documents/GitHub).
hardening_read_auditRead the AUDIT.md file from a project. Returns the full audit content including severity counts and readiness score. Use after running /audit in a project.
hardening_read_reportRead the HARDENING-REPORT.md from a project. Contains the before/after comparison and deployment checklist. Available after running /verify.
redteam_challengeRed team challenges an area marked clean by another agent. Used to dispute false negatives.
rules_check_filewrite actionRun custom rules against a specific file and return matches.
rules_generate_configGenerate a sample .vaspera/hardening-rules.yaml configuration file.
rules_loadLoad custom validation rules from .vaspera/hardening-rules.yaml or .json
rules_templatesList built-in rule templates that can be used in custom rule configuration.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan132 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/certification/rules.js: …severity: "critical", message: "eval() is dangerous and should never be used.…
Install Vaspera Hardening in Claude Code, Cursor or VS Code
Runs npx -y vaspera-hardening-mcp-server on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add vaspera-hardening -- npx -y vaspera-hardening-mcp-server
Vaspera Hardening: common questions
- Is Vaspera Hardening MCP server safe?
- With care: it is graded C, so read the findings first (57/100). Read the Vaspera Hardening safety report
- How do I install Vaspera Hardening?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Vaspera Hardening need an API key?
- No secret keys are declared. It reads 1 setting from the environment.
- Is Vaspera Hardening maintained?
- The latest release is v1.0.2.
- What can I use instead of Vaspera Hardening?
- Servers from other publishers that do the same job: Claude Prompts MCP server, Image MCP server and Shellward MCP server. Compare all Vaspera Hardening alternatives.
Alternatives to Vaspera Hardening
Same job from other publishers: the closest match first, then the best rated.
- Claude PromptsReusable prompt templates, multi-step workflow chains, and quality gates for any MCP client.not reviewedEstablishedA
- ImageAI image generation and editing with prompt optimization and quality presetsnot reviewedEstablishedB
- ShellwardAI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.not reviewedEstablishedA
- Roast My Design SystemAudit your Design System and serve your Agent the rules that keep AI-written UI on-system.not reviewedEstablishedA
- three.ws ProvenanceAppend-only, signed, on-chain-verifiable agent action log — record and audit what agents did.not reviewedEstablishedB