{"_id":"@aegiskit/mcp","name":"@aegiskit/mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@aegiskit/mcp","version":"0.1.0","description":"Aegis as a Model Context Protocol server — scan and explain Supabase RLS/authz gaps from inside Claude Code, Cursor, and other MCP agents.","license":"MIT","type":"module","bin":{"aegis-mcp":"dist/main.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","zod":"^4.4.3","@aegiskit/cli":"0.3.0","@aegiskit/policy-diff":"0.1.0","@aegiskit/scanner":"0.3.0"},"devDependencies":{"@types/node":"^26.0.1","tsup":"^8.5.1","typescript":"^6.0.3","vitest":"^4.1.9"},"engines":{"node":">=24.0.0"},"keywords":["security","mcp","model-context-protocol","claude-code","cursor","supabase","rls","nextjs","appsec"],"author":{"name":"tomodahinata"},"homepage":"https://github.com/tomodahinata/aegis/tree/main/packages/mcp#readme","repository":{"type":"git","url":"git+https://github.com/tomodahinata/aegis.git","directory":"packages/mcp"},"bugs":{"url":"https://github.com/tomodahinata/aegis/issues"},"publishConfig":{"access":"public"},"scripts":{"build":"tsup","typecheck":"tsc --noEmit"},"_id":"@aegiskit/mcp@0.1.0","_integrity":"sha512-IP2L9RJENjZnr3EjGOs4h1eMEkExqWcQXipP4NpNdK8sUQaq2Z7+sLK2TTklUkh2Xwy5QLEWir1YXEEefH3oTw==","_resolved":"/tmp/a5f5b46812d33df2d40f0fcb5902b978/aegiskit-mcp-0.1.0.tgz","_from":"file:aegiskit-mcp-0.1.0.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-IP2L9RJENjZnr3EjGOs4h1eMEkExqWcQXipP4NpNdK8sUQaq2Z7+sLK2TTklUkh2Xwy5QLEWir1YXEEefH3oTw==","shasum":"aab234a565cceda3bd12cf63481c89bf5b391418","tarball":"https://registry.npmjs.org/@aegiskit/mcp/-/mcp-0.1.0.tgz","fileCount":8,"unpackedSize":17304,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aegiskit%2fmcp@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEEfW30YyS1f9B1lwqFvbHdht6/zx+pHswgcRQsk3TzNAiBM72v/1T3m31UdWoRtCKBtlJoRci9Imc+iRQY0yJuwOw=="}]},"_npmUser":{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"},"directories":{},"maintainers":[{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.1.0_1783680187737_0.4702415992052613"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-10T10:43:07.592Z","0.1.0":"2026-07-10T10:43:07.927Z","modified":"2026-07-10T10:43:08.302Z"},"maintainers":[{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"}],"description":"Aegis as a Model Context Protocol server — scan and explain Supabase RLS/authz gaps from inside Claude Code, Cursor, and other MCP agents.","homepage":"https://github.com/tomodahinata/aegis/tree/main/packages/mcp#readme","keywords":["security","mcp","model-context-protocol","claude-code","cursor","supabase","rls","nextjs","appsec"],"repository":{"type":"git","url":"git+https://github.com/tomodahinata/aegis.git","directory":"packages/mcp"},"author":{"name":"tomodahinata"},"bugs":{"url":"https://github.com/tomodahinata/aegis/issues"},"license":"MIT","readme":"# @aegiskit/mcp\n\nAegis as a [Model Context Protocol](https://modelcontextprotocol.io) server. Add it to Claude Code, Cursor, or any MCP-capable agent and it gains two tools:\n\n- **`scan_project`** — run the Aegis static scanner over a Next.js/Supabase project and return a prioritized summary of findings (RLS/authz correctness, secrets, CSP, injection…), each with a stable fingerprint.\n- **`explain_finding`** — given a fingerprint, return the full explanation of *why* it is a gap and, for Supabase RLS owner-scoping gaps, a concrete corrected `CREATE POLICY` you can adapt and apply.\n\nThis lets a coding agent find and fix the exact class of bug that dominates real vibe-coded incidents — \"RLS exists but doesn't scope rows to the owner\" — without leaving the editor. Evidence for secret-bearing findings is redacted before it reaches the model.\n\n> **Honest scope.** Aegis reports and explains; it does not \"protect\" your app, and a suggested policy is advisory — your agent or you apply it, so Aegis never silently rewrites your SQL. It complements secure design, code review, and testing; it does not replace them.\n\n## Use with Claude Code\n\nAdd to your project's `.mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"aegis\": { \"command\": \"npx\", \"args\": [\"-y\", \"@aegiskit/mcp\"] }\n  }\n}\n```\n\n## Use with Cursor\n\nAdd to `~/.cursor/mcp.json` (or the project `.cursor/mcp.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"aegis\": { \"command\": \"npx\", \"args\": [\"-y\", \"@aegiskit/mcp\"] }\n  }\n}\n```\n\nThe server scans the working directory by default; pass `path` to a tool to scan elsewhere.\n\n## Related\n\n- [`@aegiskit/cli`](../cli) — the same scanner on the command line and in CI (SARIF, baselines, compliance evidence).\n- [`@aegiskit/scanner`](../scanner) — the analysis engine.\n","readmeFilename":"README.md","_rev":"1-a841aaddc165105612ac5a19c4184213"}