smithery Safe content atomic mcp-remote

Compuute MCP Security Scanner

Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly. POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review. Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.

Cognium trust score
30%
Tier
Unverified

Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-08-28.

Scan details: Circle-IR · 2026-08-28 · Appeal

View full trust & usage report →

Metadata

Version
1.0.0
Skill type
atomic
Execution layer
mcp-remote
Category
database
Source
Smithery
Author type
human
Last scanned
2026-08-28
Updated
2026-08-28
View source Find related skills

Use via MCP

MCP

Resolve Compuute MCP Security Scanner from your agent

Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.

One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.

claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Swap --scope user for --scope project to commit it to .mcp.json.

Search SkillsRegistry