MCP Security Guardian — SAST, Secrets, SCA, IaC scanning for AI-powered development
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"codemind-mcp","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# CodeMind — AI Security Guardian <p align="center"> <pre align="center"> ___ _ __ __ _ _ / __\___ __| | ___| \/ (_)_ __ __| | / / / _ \ / _` |/ _ \ |\/| | | '_ \ / _` | / /__| (_) | (_| | __/ | | | | | | | (_| | \____/\___/ \__,_|\___|_| |_|_|_| |_|\__,_| </pre> </p> <p align="center"> <strong>🛡️ Enterprise-Grade Security for AI-Generated Code</strong><br> <em>Think before ship.</em> </p> <p align="center"> <a href="https://pypi.org/project/codemind-mcp/">📦 PyPI</a> • <a href="https://codemind-ai.github.io/codemind">📖 Documentation</a> • <a href="#installation">🚀 Quick Start</a> • <a href="#available-tools">🔧 Tools</a> </p> <p align="center"> <a href="https://pypi.org/project/codemind-mcp/"> <img src="https://img.shields.io/pypi/v/codemind-mcp.svg" alt="PyPI Version"> </a> <img src="https://img.shields.io/badge/python-3.10+-green.svg" alt="Python"> <img src="https://img.shields.io/badge/MCP-Native-purple.svg" alt="MCP"> <img src="https://img.shields.io/badge/license-MIT-blue.svg" alt="License"> <img src="https://img.shields.io/badge/privacy-100%25%20local-brightgreen.svg" alt="Privacy"> </p> --- ## Technical Overview CodeMind transforms your AI coding assistant (Cursor, Windsurf, Claude Desktop) into a full security platform. It provides real-time oversight of AI-generated code across five security dimensions. ### Core Capabilities | Module | Description | |:---|:---| | **SAST Engine** | Detection of SQL injection, XSS, SSRF, and command injection patterns. | | **Secrets Detection** | Identification of hardcoded API keys and tokens with entropy analysis. | | **SCA (Dependencies)** | Scanning project lockfiles (12 formats) for CVEs via OSV.dev. | | **IaC Scanning** | Security auditing for Dockerfiles, GitHub Actions, and docker-compose. | | **SARIF Reporting** | Industry-standard output for CI/CD integration and GitHub Code Scanning. |…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.