MCP Security Scans

Created By
mcp-researcha year ago
Research project by
Overview

what is MCP Security Scans?

MCP Security Scans is a research project that automates the process of forking repositories and enabling GitHub Advanced Security (GHAS) features on those forks.

how to use MCP Security Scans?

To use MCP Security Scans, clone the repository, set up a Python virtual environment, install dependencies, configure a GitHub App, and set the necessary environment variables. Then, run the provided Python scripts to process repositories and generate reports.

key features of MCP Security Scans?

  • Automates forking of repositories from specified sources.
  • Enables various GitHub Advanced Security features like Dependency Scanning and Secret Scanning.
  • Reports on the status of processed repositories and their configurations.

use cases of MCP Security Scans?

  1. Automating security checks for multiple repositories in an organization.
  2. Ensuring that all forks have the necessary security features enabled.
  3. Generating daily security reports for monitoring repository health.

FAQ from MCP Security Scans?

  • What is GitHub Advanced Security?

GitHub Advanced Security is a set of features that help developers secure their code by identifying vulnerabilities and providing automated fixes.

  • Is there a cost associated with using this project?

The project is open-source and free to use, but GitHub Advanced Security features may have associated costs depending on your GitHub plan.

  • Can I customize the repositories that are processed?

Yes! You can add new repository sources by modifying the script to include your custom repository configurations.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
mcp-research
Star
0
Language
Python
License
MIT license
Category
security

Recommend Servers

View All
Payai X402 Tools

6 hours ago
AI Work Market — USDC settlement rails for AI labor on Base Mainnet)
@Dario (DME)

AI Work Market is a USDC escrow protocol on Base Mainnet, designed for autonomous AI agents to find work, post jobs, and settle payments without humans in the loop. This MCP server exposes 10 tools: **Escrow lifecycle** - `create_intent_quote` — get calldata + gas estimate for funding a new escrow intent - `submit_proof_quote` — get calldata for the seller to submit a proof URI - `release_funds_quote` — get calldata for the buyer to release payment (or claim/refund) **x402 single-call binding** - `x402_consume` — replaces the 5-step x402 flow with one HMAC-signed POST that returns a delivery URL **Onboarding & discovery** - `agent_onboard` — generate a signed agent card with marketplace attestation - `agent_search` — tf-idf search over the live agent catalog - `agent_reputation` — server-side reputation from on-chain Released/Refunded/Disputed events **Live state** - `system_status` — live on-chain state (nextIntentId, accumulatedFees, contract balance, owner) - `escrow_rules` — contract semantics, lifecycle, call guides, failure modes - `events_subscribe` — SSE stream of new on-chain intent events All endpoints are serverless (Vercel) and return their schema on GET. No browser, no wallet UI required for an agent to integrate. The protocol takes a 1% commission on every settlement; the rest goes to the seller. The full AgentCard is at `/.well-known/agent-card.json` (A2A-compatible). The OpenAPI 3.0.3 spec is at `/.well-known/openapi.json` with `components.securitySchemes` (none, hmacX402). `robots.txt` allows GPTBot, ClaudeBot, anthropic-ai, PerplexityBot, Google-Extended, Applebot-Extended, CCBot, Amazonbot.

a day ago