{"_id":"@authtrack/secura","_rev":"3-d264b067b597db087d82ca70483299aa","name":"@authtrack/secura","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@authtrack/secura","version":"0.1.0","keywords":["sast","static-analysis","security","semgrep","codeql","gitleaks","osv-scanner","bearer","cli","vulnerability","authtrack"],"license":"MIT","_id":"@authtrack/secura@0.1.0","maintainers":[{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"}],"homepage":"https://github.com/ashleyalmeida07/Authtrack-Major-Project#readme","bugs":{"url":"https://github.com/ashleyalmeida07/Authtrack-Major-Project/issues"},"bin":{"secura":"bin/secura.mjs"},"dist":{"shasum":"0a2b5f419ab609574144056163db6526e1fd553c","tarball":"https://registry.npmjs.org/@authtrack/secura/-/secura-0.1.0.tgz","fileCount":13,"integrity":"sha512-SDoQMuF09h2zh2sOsuVRzrD9JeQYLznRK+fefZ2xAPhjAt0ki8SLxVl9a6QEFqCEGN4cKF9YqwyKuZSUsoYmDg==","signatures":[{"sig":"MEUCIQCv/SLK5oE/fX5FiznojRof4P+FvxfioBOLyiLdUPQTuQIgOH0plV5JZV9y1cgU025wmrDv63nHBwX5O/7hgFmJzoQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":50319},"type":"module","engines":{"node":">=18"},"gitHead":"83105c5f18c234a2354ffe2da723398080372469","scripts":{"secura":"node bin/secura.mjs"},"_npmUser":{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"},"repository":{"url":"git+https://github.com/ashleyalmeida07/Authtrack-Major-Project.git","type":"git","directory":"cli"},"_npmVersion":"11.12.1","description":"AuthTrack static analysis (SAST) from the command line — streams a five-scanner scan (Semgrep, Bearer, OSV-Scanner, Gitleaks, CodeQL) from the AuthTrack backend and renders it live in your terminal.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/secura_0.1.0_1788956880972_0.40912690377294036","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@authtrack/secura","version":"0.1.1","keywords":["sast","static-analysis","security","semgrep","codeql","gitleaks","osv-scanner","bearer","cli","vulnerability","mcp","model-context-protocol","securai","securaai"],"license":"MIT","_id":"@authtrack/secura@0.1.1","maintainers":[{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"}],"homepage":"https://github.com/ashleyalmeida07/Authtrack-Major-Project#readme","bugs":{"url":"https://github.com/ashleyalmeida07/Authtrack-Major-Project/issues"},"bin":{"secura":"bin/secura.mjs","secura-mcp":"bin/secura-mcp.mjs"},"dist":{"shasum":"4c4021e9f9b04975fa7a18d95b311661f0814639","tarball":"https://registry.npmjs.org/@authtrack/secura/-/secura-0.1.1.tgz","fileCount":14,"integrity":"sha512-n0izF+DPpVMuCDVRa+P7jUQorHeBJx+yHShJbf4DbciE3n9KeR8gZFmpXNITapZ2Eje7FIswoR05D4K51kKtog==","signatures":[{"sig":"MEYCIQCdM1+jTALV8YgLXFXYC+jwN1KkKOYjRTju43XSPTPl3QIhALROParag984Ivlf4ecCaqaeM3GC/9Hp0SG99T3Oxpkk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCICfnyY/D3S++Z6Ah05/2Sq9kqkWV2NG3eNj29J1N9aD0AiAhTRkKZEGgJozCnOxUpYummflc51K2pyOmjYrcXGuYTA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66737},"type":"module","engines":{"node":">=18"},"gitHead":"6c798b08dd0d931d4b944ac7e468c3abcc11e962","scripts":{"secura":"node bin/secura.mjs","secura-mcp":"node bin/secura-mcp.mjs"},"_npmUser":{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"},"repository":{"url":"git+https://github.com/ashleyalmeida07/Authtrack-Major-Project.git","type":"git","directory":"cli"},"_npmVersion":"11.12.1","description":"SecuraAI security scanner CLI and MCP server — static analysis, recon, header audit and injection testing via AI agents.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/secura_0.1.1_1790688988142_0.17364611505479788","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"_id":"@authtrack/secura@0.1.2","bin":{"secura":"bin/secura.mjs","secura-mcp":"bin/secura-mcp.mjs"},"bugs":{"url":"https://github.com/ashleyalmeida07/Authtrack-Major-Project/issues"},"dist":{"shasum":"9cd148d38abbc2e93785873a5a9b04ca39d47f7e","tarball":"https://registry.npmjs.org/@authtrack/secura/-/secura-0.1.2.tgz","fileCount":14,"integrity":"sha512-zoT1djsrDNBQbKNGAmfZh/1josCqFdZkHZrcYhmbg0h89EQVzjuKRWEutGlrQJEbLDy9d+2gtLt91u9IRjUX0g==","signatures":[{"sig":"MEQCIEbrpaAGDiqFQL0Zl83OngfUYv+8zwTzCSQa3VNudcTTAiA08V7Wk4A3jg188uMhMG1KCsk1U0H3EIbvU/TTfh56gA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEWeKVJwPMVbsEQeLn7tk6V8zMkYZoJ6+HCt06hSoUs8AiEAo8FhJhkTSAntWfscqDsRksqINg1rAOFST8IdO4tkpd0="}],"unpackedSize":67617},"name":"@authtrack/secura","type":"module","engines":{"node":">=18"},"gitHead":"8f9d271ab54fdf6332b4303ca6874063fab4c524","license":"MIT","scripts":{"secura":"node bin/secura.mjs","secura-mcp":"node bin/secura-mcp.mjs"},"version":"0.1.2","_npmUser":{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"},"homepage":"https://github.com/ashleyalmeida07/Authtrack-Major-Project#readme","keywords":["sast","static-analysis","security","semgrep","codeql","gitleaks","osv-scanner","bearer","cli","vulnerability","mcp","model-context-protocol","securai","securaai"],"repository":{"url":"git+https://github.com/ashleyalmeida07/Authtrack-Major-Project.git","type":"git","directory":"cli"},"_npmVersion":"11.12.1","description":"SecuraAI security scanner CLI and MCP server — static analysis, recon, header audit and injection testing via AI agents.","directories":{},"maintainers":[{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"}],"_nodeVersion":"22.14.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/secura_0.1.2_1790689895075_0.5839987550688746"}}},"time":{"created":"2026-09-09T12:27:59.091Z","modified":"2026-09-29T13:51:35.472Z","0.1.0":"2026-09-09T12:28:01.101Z","0.1.1":"2026-09-29T13:36:28.262Z","0.1.2":"2026-09-29T13:51:35.181Z"},"bugs":{"url":"https://github.com/ashleyalmeida07/Authtrack-Major-Project/issues"},"license":"MIT","homepage":"https://github.com/ashleyalmeida07/Authtrack-Major-Project#readme","keywords":["sast","static-analysis","security","semgrep","codeql","gitleaks","osv-scanner","bearer","cli","vulnerability","mcp","model-context-protocol","securai","securaai"],"repository":{"url":"git+https://github.com/ashleyalmeida07/Authtrack-Major-Project.git","type":"git","directory":"cli"},"description":"SecuraAI security scanner CLI and MCP server — static analysis, recon, header audit and injection testing via AI agents.","maintainers":[{"name":"ashleyalmeida","email":"ashleyalmeida182006@gmail.com"}],"readme":"# @authtrack/secura\r\n\r\n**AuthTrack static analysis (SAST) from the command line.**\r\n\r\n`secura` points five independent engines — [Semgrep], [Bearer], [OSV-Scanner],\r\n[Gitleaks] and [CodeQL] — at a repository, merges and deduplicates their\r\nfindings, retrieves similar known-vulnerable patterns, then has an LLM confirm\r\nor rule out each finding and write a patch for the confirmed ones. It streams\r\nthe whole run live in your terminal and prints a report at the end.\r\n\r\nThe scanning runs on the **AuthTrack backend**; this CLI is a thin, zero-dependency\r\nclient that talks to it. You don't need Python, and you don't need the scanners\r\ninstalled locally.\r\n\r\n[Semgrep]: https://semgrep.dev\r\n[Bearer]: https://www.bearer.com\r\n[OSV-Scanner]: https://google.github.io/osv-scanner/\r\n[Gitleaks]: https://github.com/gitleaks/gitleaks\r\n[CodeQL]: https://codeql.github.com\r\n\r\n---\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install -g @authtrack/secura\r\n```\r\n\r\nOr run it once, without installing:\r\n\r\n```bash\r\nnpx @authtrack/secura scan .\r\n```\r\n\r\nRequires **Node ≥ 18**. No build step, no native modules.\r\n\r\n## Quick start\r\n\r\n```bash\r\n# Scan the current directory\r\nsecura scan .\r\n\r\n# Scan a public GitHub repo (the backend clones it)\r\nsecura scan owner/repo\r\nsecura scan https://github.com/owner/repo\r\n\r\n# Fast pass — skip CodeQL (its database build dominates the run)\r\nsecura scan . --fast\r\n\r\n# CI gate: exit non-zero if anything HIGH or worse is confirmed\r\nsecura scan . --fail-on high\r\n\r\n# Save the full machine-readable report\r\nsecura scan . --json report.json\r\n```\r\n\r\n## Targets\r\n\r\n| Target | What happens |\r\n| --- | --- |\r\n| `.` or `./path/to/repo` | A local folder. Sent to the backend to scan (see [Backend](#backend)). |\r\n| `owner/repo` | Public GitHub shorthand. The backend shallow-clones it, scans, then deletes it. |\r\n| `https://github.com/owner/repo`, `git@…`, `ssh://…` | Any public Git URL. Cloned by the backend. |\r\n\r\nFor a local path, how the code reaches the backend depends on where the backend runs:\r\n\r\n- **Local backend** (the default, `http://localhost:8000`): the absolute path is\r\n  sent as-is and scanned in place — nothing is copied.\r\n- **Remote backend** (a `--api` that isn't localhost), or **`--upload`**: the\r\n  directory is packaged into a `tar.gz` (excluding `node_modules`, `.git`, build\r\n  output, lockfiles, minified assets, …) and uploaded. Requires `tar` on your\r\n  PATH (bundled with Windows 10 1803+, macOS and Linux). If `tar` is missing,\r\n  scan a Git URL instead.\r\n\r\n## Options\r\n\r\n```\r\n-f, --fast                 Skip CodeQL (its DB build dominates the run).\r\n-l, --language <lang>      CodeQL language (javascript, python, java, go, ruby,\r\n                           csharp, cpp). Auto-detected when omitted.\r\n-t, --max-triage <n>       Cap findings sent to LLM triage (default 25).\r\n    --fail-on <sev>        Exit 1 if a confirmed finding is >= this severity\r\n                           (critical|high|medium|low). For CI gates.\r\n-o, --json <path>          Write the full report as JSON to <path>.\r\n    --max-findings <n>     How many confirmed findings to print (default 20).\r\n    --show-fixes           Print the generated fix diffs in full.\r\n-q, --quiet                Suppress the live view; print only the report.\r\n    --api <url>            Backend base URL (default $SECURA_API or\r\n                           http://localhost:8000/api/v1).\r\n    --token <token>        Bearer token, if the backend requires one\r\n                           (default $SECURA_TOKEN).\r\n    --upload               Package and upload the local dir even for a local\r\n                           backend (automatic for a remote --api).\r\n```\r\n\r\n### Exit codes\r\n\r\n| Code | Meaning |\r\n| --- | --- |\r\n| `0` | Completed; no `--fail-on` breach. |\r\n| `1` | `--fail-on` gate breached (a confirmed finding at or above the threshold). |\r\n| `2` | Bad target, or the scan failed. |\r\n| `130` | Interrupted (Ctrl-C). |\r\n\r\n## Backend\r\n\r\n`secura` needs a reachable AuthTrack backend. Point it at one with `--api` or the\r\n`SECURA_API` environment variable (matching the web app's `NEXT_PUBLIC_API_URL`):\r\n\r\n```bash\r\nexport SECURA_API=\"https://scans.example.com/api/v1\"\r\nsecura scan owner/repo\r\n```\r\n\r\nThe default is `http://localhost:8000/api/v1`. The scan endpoints are unauthenticated;\r\n`--token` / `SECURA_TOKEN` is sent as a bearer header only if provided, so it keeps\r\nworking if auth is added later.\r\n\r\n## CI example\r\n\r\n```yaml\r\n# GitHub Actions — fail the build on a confirmed high+ finding\r\n- name: SAST\r\n  run: npx @authtrack/secura scan . --fast --fail-on high --json sast.json\r\n  env:\r\n    SECURA_API: ${{ secrets.SECURA_API }}\r\n```\r\n\r\n---\r\n\r\n## MCP Server (`secura-mcp`)\r\n\r\nAfter `npm install -g @authtrack/secura`, a second command `secura-mcp` is also installed.\r\n**You never run it yourself** — your AI editor runs it automatically as a background subprocess\r\nand exposes its tools to the AI assistant.\r\n\r\n### Tools exposed\r\n\r\n| Tool | What it does |\r\n|------|-------------|\r\n| `run_static_scan` | SAST — Semgrep, Bearer, OSV-Scanner, Gitleaks, CodeQL + AI triage |\r\n| `run_recon` | Surface mapping — crawl & classify endpoints |\r\n| `run_header_audit` | OWASP security-header & cookie audit |\r\n\r\n### Claude Code setup\r\n\r\nCreate or edit `~/.claude/claude_desktop_config.json` (or the path shown in Claude's settings):\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"secura\": {\r\n      \"command\": \"secura-mcp\",\r\n      \"env\": {\r\n        \"SECURA_API\": \"http://localhost:8000/api/v1\",\r\n        \"SECURA_TOKEN\": \"<your-jwt-if-needed>\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n### Cursor setup\r\n\r\nOpen **Cursor → Settings → Features → MCP** and add:\r\n\r\n```json\r\n{\r\n  \"secura\": {\r\n    \"command\": \"secura-mcp\",\r\n    \"env\": {\r\n      \"SECURA_API\": \"http://localhost:8000/api/v1\",\r\n      \"SECURA_TOKEN\": \"<your-jwt-if-needed>\"\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n### Usage (after setup)\r\n\r\nJust talk to your AI assistant as normal — it will automatically call the tools when relevant:\r\n\r\n```\r\n\"Check this repo for vulnerabilities\"\r\n→ AI calls run_static_scan({ target_path: \".\" })\r\n\r\n\"Map the attack surface of https://example.com\"\r\n→ AI calls run_recon({ url: \"https://example.com\" })\r\n\r\n\"Audit the security headers on my staging server\"\r\n→ AI calls run_header_audit({ url: \"https://staging.example.com\" })\r\n```\r\n\r\n### Environment variables\r\n\r\n| Variable | Default | Description |\r\n|----------|---------|-------------|\r\n| `SECURA_API` | `https://securaai-major-project.onrender.com/api/v1` | Backend base URL |\r\n| `SECURA_TOKEN` | _(empty)_ | Bearer token for authenticated backends |\r\n\r\n---\r\n\r\n\r\n\r\nThis package publishes from the `cli/` directory of the AuthTrack repo. It is\r\nplain ESM with no build step, so publishing is just:\r\n\r\n```bash\r\ncd cli\r\nnpm login                     # once per machine\r\nnpm version patch             # 0.1.0 -> 0.1.1 (bumps package.json + git tag)\r\nnpm publish --access public   # scoped packages need --access public on first publish\r\n```\r\n\r\nNotes:\r\n\r\n- **Scope.** The name `@authtrack/secura` requires the `@SecuraAI` org to exist\r\n  on npm and your account to be a member. Create it at\r\n  <https://www.npmjs.com/org/create>, or rename the package to an unscoped name\r\n  you own (e.g. `securai-secura`) in `package.json` — the `bin` stays `secura`\r\n  either way, so `secura scan …` is unchanged for users.\r\n- **What ships.** Only `bin/`, `src/` and `README.md` (the `files` allowlist).\r\n  Verify with `npm pack --dry-run` before publishing.\r\n- **Smoke test the tarball.** `npm pack` then\r\n  `npm i -g ./securai-secura-<version>.tgz` and run `secura --help`.\r\n\r\n## License\r\n\r\nMIT\r\n","readmeFilename":"README.md"}