# Cycode Security Scanner

> Use this tool when you need to automate security scanning for secrets, vulnerabilities, and compliance issues in your codebase. It integrates with Cycode's security platform to perform SAST, SCA, IaC, and secrets scanning on local files, Git repositories, and commit ranges, supporting multiple programming languages. The tool provides detailed security reports with remediation guidance, making it ideal for developers who want to enhance their AI-assisted development workflows with automated security checks.

Canonical page: https://skillsregistry.net/skills/cycode-security-scanner  
JSON: https://api.skillsregistry.net/v1/skills/cycode-security-scanner

## Description

Cycode CLI MCP server that provides security scanning capabilities for detecting secrets, vulnerabilities, and compliance issues across codebases through Cycode's security platform. Built by Cycode Ltd., the implementation integrates with their cloud-based security service to perform SAST, SCA, IaC, and secrets scanning on local files, Git repositories, and commit ranges, supporting multiple programming languages and package managers including npm, Maven, Go, Ruby, and .NET. The server handles authentication via OAuth device flow, manages scan configurations, and provides detailed security reports with remediation guidance, making it valuable for developers who want to integrate automated security scanning into their AI-assisted development workflows without manually running CLI commands or navigating web dashboards.

## Trust

- **Trust score (0–1):** 0.59
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** version-control
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/cycode-security-scanner)
- **Repository:** <https://github.com/cycodehq/cycode-cli>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "cycode-security-scanner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/cycode-security-scanner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/cycode-security-scanner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
