{"_id":"@bergabruh/system-scanner","_rev":"2-6310913851d29db02ae854499621e174","name":"@bergabruh/system-scanner","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@bergabruh/system-scanner","version":"0.1.0","keywords":["opencode","opencode-plugin","security","linux"],"license":"Apache-2.0","_id":"@bergabruh/system-scanner@0.1.0","maintainers":[{"name":"bergabruh","email":"grigoriy884@gmail.com"}],"homepage":"https://github.com/BergaBruh/mnogovid","bugs":{"url":"https://github.com/BergaBruh/mnogovid/issues"},"dist":{"shasum":"4bf2248ef77d9bebf1ae69dea8ccab39e80273bb","tarball":"https://registry.npmjs.org/@bergabruh/system-scanner/-/system-scanner-0.1.0.tgz","fileCount":7,"integrity":"sha512-GaLWqz6WN1VK5Zba7578nyrCO1BC8sOfJODMmkoTXpDRiqOaZxli3MhxyHTKVtjq6ZVmNjeeXKQUksfvbKSfaw==","signatures":[{"sig":"MEYCIQDT2oQ4je4ARxikVgvmzksPhijMQtxmh9VhDOb4U1IZLgIhAKJUstNE9cxUn4wOmRyt+GFAPewjGosyJ/iPAw1K7+r+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":83562},"main":"./opencode.js","type":"module","module":"./opencode.js","exports":"./opencode.js","gitHead":"ce54a14e4c6480348ead2d949f9f048717299cc0","scripts":{"check":"node --check opencode.js"},"_npmUser":{"name":"bergabruh","email":"grigoriy884@gmail.com"},"repository":{"url":"git+https://github.com/BergaBruh/mnogovid.git","type":"git"},"_npmVersion":"12.0.2","description":"OpenCode plugin for consent-gated Linux host security assessment.","directories":{},"_nodeVersion":"26.4.0","_hasShrinkwrap":false,"devDependencies":{"@opencode-ai/plugin":"^1.18.11"},"_npmOperationalInternal":{"tmp":"tmp/system-scanner_0.1.0_1788172963734_0.6358513620089392","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@bergabruh/system-scanner","version":"0.1.1","description":"MCP server package for consent-gated Linux host security assessment.","license":"Apache-2.0","bin":{"mnogovid-system-scanner":"bin/mnogovid-system-scanner.mjs"},"keywords":["opencode","opencode-plugin","security","linux"],"scripts":{"check":"node --check bin/mnogovid-system-scanner.mjs"},"homepage":"https://github.com/BergaBruh/mnogovid","repository":{"type":"git","url":"git+https://github.com/BergaBruh/mnogovid.git"},"gitHead":"ce54a14e4c6480348ead2d949f9f048717299cc0","_id":"@bergabruh/system-scanner@0.1.1","bugs":{"url":"https://github.com/BergaBruh/mnogovid/issues"},"_nodeVersion":"26.4.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-r/sUg80SlLhhfc+ENLLdCBBVMvrpTVwXd8RcWOrDtUgZTXSIEgGjxu5P57OQwxoJacey+zN9kxzKYGL63cErQQ==","shasum":"69b1c07c859a7d61f8fbfd7edb2fcde267d27e27","tarball":"https://registry.npmjs.org/@bergabruh/system-scanner/-/system-scanner-0.1.1.tgz","fileCount":7,"unpackedSize":79861,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDmJg0iWFXSh35EBcjULyXSGzTXuz7DfnzptIQ5OVN2xAIhAJjCAoh1aCMKvQM2PuROirbwbu6XLMKlN0SBcGwwBPCu"}]},"_npmUser":{"name":"bergabruh","email":"grigoriy884@gmail.com"},"directories":{},"maintainers":[{"name":"bergabruh","email":"grigoriy884@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/system-scanner_0.1.1_1788174886287_0.4142721845278632"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-31T10:42:43.472Z","modified":"2026-08-31T11:14:46.570Z","0.1.0":"2026-08-31T10:42:43.887Z","0.1.1":"2026-08-31T11:14:46.425Z"},"bugs":{"url":"https://github.com/BergaBruh/mnogovid/issues"},"license":"Apache-2.0","homepage":"https://github.com/BergaBruh/mnogovid","keywords":["opencode","opencode-plugin","security","linux"],"repository":{"type":"git","url":"git+https://github.com/BergaBruh/mnogovid.git"},"description":"MCP server package for consent-gated Linux host security assessment.","maintainers":[{"name":"bergabruh","email":"grigoriy884@gmail.com"}],"readme":"# Mnogovid System Scanner\n\nMnogovid System Scanner is a consent-gated Linux host assessment plugin. It\norchestrates installed local tools and records redacted evidence; it never\ninstalls software, applies a fix, deletes/quarantines a file, saves PCAPs, or\nruns shell text.\n\nIt is intentionally layered. No tool can prove a Linux host is clean: a\nrootkit can hide from user-space checks, package CVE state can differ because\nof distribution backports, and encrypted or unobserved traffic cannot be fully\ninspected.\n\n## Coverage\n\n| Area | Allowlisted adapters |\n| --- | --- |\n| Hardening | Lynis |\n| Malware / rootkits | ClamAV, rkhunter, chkrootkit |\n| File/package integrity | AIDE, `rpm -Va` |\n| Installed-package CVEs | debsecan |\n| Runtime inventory | osquery |\n| Listener and firewall exposure | `ss`, nftables |\n| Persistence | enabled systemd units and timers |\n| Audit, kernel, and logs | audit rules, loaded kernel modules, warning journal entries |\n| Containers | Docker and Podman inventory when their CLI is available |\n| Docker hardening and image CVEs | Docker security options/container posture, Trivy, Grype, Dockle |\n| Service posture | Nginx syntax; bounded local MySQL, PostgreSQL, Redis, MongoDB, and ClickHouse probes |\n| Active ports (explicit target only) | Nmap, top 100 ports with light version detection |\n| Live traffic metadata (bounded) | TShark, 5–300 seconds, no packet file |\n\nMissing executables are recorded as coverage gaps. The plugin does not attempt\nto install them or elevate privilege. Some checks need root access and will\nreport failure rather than invoke `sudo`.\n\n## Run\n\nInstall it from the Mnogovid marketplace, then use one of the native Codex\ncommands:\n\n```text\n@mnogovid-system-scanner\n/mnogovid-system-scanner:system-scan\n```\n\nThe `@` mention invokes the plugin onboarding prompt. The unified command first\nasks whether to assess the local host or a configured remote MCP host, checks\nthe profile and toolchain, and creates a missing profile only after consent.\nOn later runs it validates the existing profile and available adapters before\nasking which mode to use: adapters only, adapters plus AI triage, or adapters\nplus AI triage and independent review. It collects all scanner permissions\nseparately.\n\n### Remote server over SSH-stdio MCP\n\nInstall the same plugin on the remote host, preferably at\n`/opt/mnogovid-system-scanner`, and define an SSH alias for a dedicated audit\naccount. Generate a static local Codex configuration stanza:\n\n```bash\npython3 /path/to/mnogovid-system-scanner/scripts/remote_mcp_config.py prod-audit\n```\n\nCopy its output into local `~/.codex/config.toml`, restart Codex, then use:\n\n```text\n/mnogovid-system-scanner:system-scan\n```\n\nThe MCP protocol stays inside SSH stdio: no remote TCP listener or secret is\nrequired in the generated configuration. It explicitly disables SSH agent and\nother forwarding, enables batch mode, and requires a known host key. The utility\nonly renders TOML; it does not edit the local configuration or contact the\nhost. See [`remote-mcp.toml.example`](remote-mcp.toml.example).\n\nThe unified command asks in chat which configured remote MCP connection to use\nwhen there is more than one, then asks a separate first consent before it\nconnects or starts discovery. It defaults reports to the remote MCP process's\ncurrent working directory and shows its resolved path before scanner planning.\n\n### Claude Code\n\nInstall the plugin from the configured marketplace, start Claude in the\nselected report directory, then invoke:\n\n```text\n/system-scan\n```\n\n### OpenCode\n\nAdd the MCP server to the project or global `opencode.json` and restart\nOpenCode:\n\n```json\n{\n  \"$schema\": \"https://opencode.ai/config.json\",\n  \"mcp\": {\n    \"mnogovid-system-scanner\": {\n      \"type\": \"local\",\n      \"command\": [\"npx\", \"--yes\", \"@bergabruh/system-scanner\"],\n      \"enabled\": true\n    }\n  }\n}\n```\n\n`npx` installs and starts the bundled Python MCP server; no absolute path or\ncopied `.opencode` assets are needed. OpenCode exposes its tools with the\n`mnogovid-system-scanner_` prefix and still requests every recorded consent.\n`python3` and individual scanner executables remain system prerequisites and\nare never installed by the package.\n\nFirst inspect the host/tool availability without starting a scanner:\n\n```bash\npython3 /path/to/mnogovid-system-scanner/scripts/init.py /safe/report-directory --json\n```\n\nThis manual initializer is optional; the unified workflow uses `system_bootstrap`\nfirst. A profile records discovery only and never grants scanner permission:\n\n```bash\npython3 /path/to/mnogovid-system-scanner/scripts/init.py /safe/report-directory --json --write\n```\n\nFor every adapter the agent previews its exact argv and asks for approval. Two\nadditional controls are deliberately separate:\n\n- Image scanners with external vulnerability databases require `network`\n  consent, an image reference, and per-scanner approval.\n- `nmap-local` needs recorded lifecycle active-network consent,\n  `authorizedTarget=true`, and one explicitly authorized literal IP.\n- Database clients require `serviceProbe` consent and use only fixed local,\n  read-only status commands. Their raw output is withheld after normalization.\n- `tshark-summary` needs recorded lifecycle traffic-capture consent, a named\n  interface, and a 5–300 second capture interval. It emits metadata to the\n  scanner result only, not a PCAP file; packet metadata can still be sensitive.\n\nThe database adapters use fixed local read-only status/version commands. They\ncan be unavailable when a service is not local, its socket is inaccessible, or\nit requires credentials; such a result is a coverage gap, not a clean bill of\nhealth.\n\nReports are written only after `system_finalize_run`:\n\n```text\n<report-directory>/.mnogovid/system-scanner/<timestamp>/result.md\n```\n\nThe report is reader-first: verdict, actionable findings, coverage gaps with\nrecovery guidance, scanner coverage, security-relevant observations, recorded\nconsent, and distinct AI/independent-review sections. A failed, missing, or\ndeclined adapter is a coverage gap—not a clean result.\n\n## AI and independent review\n\nThe AI and independent-review modes create bounded, secret-redacted payloads\nonly after their own separate approvals. Both assessments are advisory and\nremain distinct from the scanner evidence.\n\nUse `system_ingest` to normalize a pre-existing private local JSON or SARIF\nreport inside the selected report directory without starting a process.\n`system_advisory_lookup` queries OSV for one\npackage version only after a separate `allowNetwork=true` approval; it is\nadvisory evidence and does not account for distribution backports by itself.\n\n## Development\n\nValidate the manifest and exercise the JSON-RPC server without starting a\nscanner:\n\n```bash\npython3 /path/to/plugin-creator/scripts/validate_plugin.py /path/to/mnogovid-system-scanner\npython3 -m unittest discover -s /path/to/mnogovid-system-scanner/tests -v\n```\n\nLicensed under the Apache License 2.0.\n\n## Troubleshooting\n\n- **Profile missing:** rerun the unified workflow and approve profile creation.\n- **Profile invalid:** stop and repair it explicitly; the workflow will not\n  scan through an invalid profile.\n- **Adapter missing or permission denied:** install or grant the required\n  read-only access through normal system administration, then rerun bootstrap.\n- **Remote MCP unavailable:** verify the SSH alias, known host key, remote\n  Python path, and remote plugin path; the generator does not contact the\n  server or modify `~/.codex/config.toml`.\n- **No findings:** a completed set of checks cannot prove the absence of\n  compromise, unseen traffic, or kernel-level stealth. Review coverage gaps.\n","readmeFilename":"README.md"}