# CodeInspectus

> CodeInspectus — synvoya-codeinspectus. Use this tool when you need to identify security vulnerabilities in AI-generated JavaScript and TypeScript code, such as client-side secret exposure and XSS sinks. CodeInspectus solves problems related to secure coding practices, including detecting potential security threats and data breaches. It takes in local code repositories and outputs comprehensive security scan reports, making it an ideal solution for developers working with AI-generated code who require a private and telemetry-free security scanning experience.

Canonical page: https://skillsregistry.net/skills/synvoya-codeinspectus  
JSON: https://api.skillsregistry.net/v1/skills/synvoya-codeinspectus

## Description

Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.

## Trust

- **Trust score (0–1):** 0.66
- **Verification tier:** scanned
- **Last scanned:** 2026-08-30

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-08-30

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/dwnvqbiugq)
- **Repository:** <https://github.com/Synvoya/codeinspectus>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "synvoya-codeinspectus"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/synvoya-codeinspectus` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/synvoya-codeinspectus/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
