{"_id":"@audit-core/mcp-server","name":"@audit-core/mcp-server","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@audit-core/mcp-server","version":"1.0.0","description":"MCP server for AuditCore — run security scans, fetch findings, and generate AI-powered fixes from your IDE (Claude Desktop, Claude Code, Cursor, Continue.dev, Cline).","type":"module","main":"dist/index.js","bin":{"auditcore-mcp":"dist/index.js"},"scripts":{"build":"tsc","dev":"tsx src/index.ts","prepublishOnly":"npm run build && chmod +x dist/index.js"},"keywords":["mcp","model-context-protocol","claude","cursor","security","vulnerability-scanner","pentest","ai-agent","auditcore"],"author":{"name":"AuditCore","email":"contact@audit-core.tech"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/auditcore-tech/scanner.git","directory":"mcp-server"},"homepage":"https://audit-core.tech","bugs":{"url":"https://audit-core.tech/contact"},"engines":{"node":">=18.0.0"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","zod":"^3.23.0","zod-to-json-schema":"^3.23.0"},"devDependencies":{"@types/node":"^22.0.0","tsx":"^4.19.0","typescript":"^5.5.0"},"_id":"@audit-core/mcp-server@1.0.0","_nodeVersion":"23.11.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-o7VXhnlCxsgOVxZmWOZg3Xv5nB/kOi4neKdNNBpsBtxY/qwi0vXhSI8Mx/A4Kfz9Py+YdSIhzeDrJPnsAsBRfA==","shasum":"e7af6e8dcb6253af68924ad02c033af2cbef0377","tarball":"https://registry.npmjs.org/@audit-core/mcp-server/-/mcp-server-1.0.0.tgz","fileCount":10,"unpackedSize":27439,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAFSP2vd+YtAeL8QYfGeWxoy8Guown++pu0/GcwyXei+AiBHyFPV5tvZ225RjGK3Bo4GczrRoB20OeMtcc86527nrw=="}]},"_npmUser":{"name":"k-szozda","email":"kr.szozda@gmail.com"},"directories":{},"maintainers":[{"name":"k-szozda","email":"kr.szozda@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server_1.0.0_1778788308230_0.052796831356553664"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-14T19:51:48.110Z","1.0.0":"2026-05-14T19:51:48.373Z","modified":"2026-05-14T19:51:48.609Z"},"maintainers":[{"name":"k-szozda","email":"kr.szozda@gmail.com"}],"description":"MCP server for AuditCore — run security scans, fetch findings, and generate AI-powered fixes from your IDE (Claude Desktop, Claude Code, Cursor, Continue.dev, Cline).","homepage":"https://audit-core.tech","keywords":["mcp","model-context-protocol","claude","cursor","security","vulnerability-scanner","pentest","ai-agent","auditcore"],"repository":{"type":"git","url":"git+https://github.com/auditcore-tech/scanner.git","directory":"mcp-server"},"author":{"name":"AuditCore","email":"contact@audit-core.tech"},"bugs":{"url":"https://audit-core.tech/contact"},"license":"MIT","readme":"# @audit-core/mcp-server\n\n[![npm version](https://img.shields.io/npm/v/@audit-core/mcp-server.svg)](https://www.npmjs.com/package/@audit-core/mcp-server)\n[![npm downloads](https://img.shields.io/npm/dm/@audit-core/mcp-server.svg)](https://www.npmjs.com/package/@audit-core/mcp-server)\n[![license](https://img.shields.io/npm/l/@audit-core/mcp-server.svg)](https://github.com/auditcore-tech/scanner/blob/main/mcp-server/LICENSE)\n\nModel Context Protocol server for **[AuditCore](https://audit-core.tech)** — run automated security scans, fetch vulnerability findings, and generate AI-powered fix code from inside Claude Desktop, Claude Code, Cursor, Continue.dev, Cline, or any MCP-compatible client.\n\n> AuditCore is an automated security + SEO + AI-readiness audit platform — 50+ open-source pentest tools (OWASP ZAP, Nuclei, sqlmap, BOLA/BFLA, gitleaks, Semgrep, MobSF) plus an AI-agent prompt-injection scanner and a 60+ check SEO auditor. One-time payment per site, unlimited rescans.\n\n## Quick start\n\n### 1. Get an API key (optional but recommended)\n\nFree-tier scans run anonymously. For paid tiers (Basic / Pro / Enterprise), AI fix generation, and access to your own scan history, get an API key:\n\n→ https://audit-core.tech/dashboard/settings → **API Keys** → Create\n\nKeys are prefixed `ac_live_`.\n\n### 2. Add to your MCP client\n\n**Claude Desktop** — edit `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\\Claude\\claude_desktop_config.json` (Windows):\n\n```json\n{\n  \"mcpServers\": {\n    \"auditcore\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@audit-core/mcp-server\"],\n      \"env\": {\n        \"AUDITCORE_API_KEY\": \"ac_live_YOUR_KEY_HERE\"\n      }\n    }\n  }\n}\n```\n\n**Claude Code** — `~/.config/claude/mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"auditcore\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@audit-core/mcp-server\"],\n      \"env\": {\n        \"AUDITCORE_API_KEY\": \"ac_live_YOUR_KEY_HERE\"\n      }\n    }\n  }\n}\n```\n\n**Cursor** — `.cursor/mcp.json` in your repo root:\n\n```json\n{\n  \"mcpServers\": {\n    \"auditcore\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@audit-core/mcp-server\"],\n      \"env\": {\n        \"AUDITCORE_API_KEY\": \"ac_live_YOUR_KEY_HERE\"\n      }\n    }\n  }\n}\n```\n\n**Continue.dev** — `.continue/config.json`:\n\n```json\n{\n  \"experimental\": {\n    \"modelContextProtocolServers\": [{\n      \"transport\": {\n        \"type\": \"stdio\",\n        \"command\": \"npx\",\n        \"args\": [\"-y\", \"@audit-core/mcp-server\"],\n        \"env\": {\n          \"AUDITCORE_API_KEY\": \"ac_live_YOUR_KEY_HERE\"\n        }\n      }\n    }]\n  }\n}\n```\n\n**Cline (VS Code)** — settings → MCP Servers → Add:\n\n```json\n{\n  \"auditcore\": {\n    \"command\": \"npx\",\n    \"args\": [\"-y\", \"@audit-core/mcp-server\"],\n    \"env\": { \"AUDITCORE_API_KEY\": \"ac_live_YOUR_KEY_HERE\" }\n  }\n}\n```\n\nRestart your MCP client. You should see \"auditcore\" with 5 tools in the MCP server list.\n\n## Available tools\n\n| Tool | Auth | What it does |\n|---|---|---|\n| `auditcore_start_scan` | optional | Start a scan on a URL. Free tier runs without auth (1-page SEO + AI-readiness + security headers). |\n| `auditcore_scan_status` | none | Poll progress + current phase/tool + partial findings summary. |\n| `auditcore_scan_results` | none | Fetch findings (severity, CVSS, CWE, affected URL, description, fix hint). |\n| `auditcore_generate_fix` | **required** | AI-generated fix code for a specific vulnerability. Language auto-detected from scan target's tech stack. |\n| `auditcore_list_my_scans` | **required** | List your account's scans. Filter by status. |\n\n## Example prompts\n\nAfter installation, try these in your IDE:\n\n- *\"Scan https://example.com with AuditCore\"* → starts a free scan\n- *\"What's the status of scan abc-123-def?\"* → polls progress\n- *\"Show me the critical findings\"* → fetches results\n- *\"Generate a fix for the SQL injection finding\"* → AI fix code\n- *\"List my recent scans\"* → your account history\n\n## How it works\n\n```\n┌─────────────────┐    stdio       ┌──────────────────┐    HTTPS    ┌─────────────────┐\n│ Claude / Cursor │ ─── MCP ──▶   │ @audit-core/mcp- │ ─── REST ──▶│  audit-core.tech│\n│  (LLM client)   │ ◀──────────── │     server       │ ◀────────── │   FastAPI       │\n└─────────────────┘   JSON-RPC    └──────────────────┘    JSON     └─────────────────┘\n                                  Reads AUDITCORE_API_KEY\n                                  from env, adds as Bearer\n                                  to authenticated calls.\n```\n\n## Configuration\n\n| Env var | Required | Default | Description |\n|---|---|---|---|\n| `AUDITCORE_API_KEY` | for paid tools | — | Your `ac_live_*` API key. Required for `auditcore_generate_fix` and `auditcore_list_my_scans`. Optional for public tools. |\n| `AUDITCORE_API_URL` | no | `https://audit-core.tech` | Override for self-hosted AuditCore deployments or staging. |\n\n## Tiers + quotas\n\n| Tier | Price | Page limit | Scanners | AI fixes/day |\n|---|---|---|---|---|\n| Free | $0 | 1 | SEO + AI-readiness + security headers | 0 |\n| Basic | $99 | 25 | + SSL/TLS, CORS, nmap, DMARC, headers, cookies | 10 |\n| Pro | $299 | 100 | + ZAP, Nuclei, Nikto, JWT, subdomain enum | 50 |\n| Enterprise | $499 | 500 | Full pentest suite + BOLA/BFLA + sqlmap + SSRF + mobile binary + AI prompt-injection | 200 |\n\nPer-domain license — pay once, rescan unlimited.\n\n## Building from source\n\n```bash\ngit clone https://github.com/auditcore-tech/scanner.git\ncd scanner/mcp-server\nnpm install\nnpm run build\nnode dist/index.js  # smoke test — should log \"5 tools registered\"\n```\n\n## Use with ChatGPT (Custom GPT Actions)\n\nChatGPT doesn't speak MCP natively, but you can wire AuditCore in as a **Custom GPT** via OpenAPI Actions:\n\n1. **chatgpt.com → \"Create a GPT\"** (requires ChatGPT Plus)\n2. **Configure → Actions → Import from URL**:\n   `https://audit-core.tech/api/v1/openapi.json`\n3. **Authentication → API Key**:\n   - Type: API Key\n   - Auth Type: Bearer\n   - Value: your `ac_live_*` key\n4. **Test** with a prompt like *\"Scan https://example.com for vulnerabilities\"*\n\nEach user creates their own private GPT with their own key — no shared credentials. The OpenAPI spec at `/api/v1/openapi.json` exposes all 51 endpoints; you can scope the GPT to a subset by editing the imported schema.\n\n## Issues + feedback\n\n- Bug reports: https://audit-core.tech/contact\n- Source: https://github.com/auditcore-tech/scanner (mcp-server/)\n- Status: https://audit-core.tech (live status banner)\n\n## License\n\nMIT — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md","_rev":"1-09fe3ff2acedf721b8c31145035d750e"}