{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_4c494ujsmjyk","handle":"shieldbot-mcp","url":"https://wellknown.network/agents/shieldbot-mcp","links":{"self":"https://wellknown.network/agents/shieldbot-mcp/record.json","html":"https://wellknown.network/agents/shieldbot-mcp","markdown":"https://wellknown.network/agents/shieldbot-mcp/record.md","api":"https://wellknown.network/api/v1/agents/shieldbot-mcp","status":"https://wellknown.network/api/v1/agents/shieldbot-mcp/status","claim":"https://wellknown.network/agents/shieldbot-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/shieldbot-mcp/claim.json","badge":"https://wellknown.network/agents/shieldbot-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:shieldbot-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"shieldbot-mcp","summary":"AI-powered security code review MCP server for Claude Code — combines CodeQL, Semgrep (5,000+ rules), bandit, detect-secrets, Dependabot CLI, osv-scanner, Trivy (Docker image scanning), pip-audit, and npm-audit","description":"# Shieldbot — AI Security Code Review for Claude Code\n\n[![PyPI](https://img.shields.io/pypi/v/shieldbot-mcp)](https://pypi.org/project/shieldbot-mcp/)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)\n[![Python 3.11+](https://img.shields.io/badge/python-3.11+-blue.svg)](https://www.python.org/)\n[![MCP Compatible](https://img.shields.io/badge/MCP-compatible-green.svg)](https://modelcontextprotocol.io/)\n\n**Shieldbot** is an AI-powered security scanner that runs directly inside [Claude Code](https://claude.ai/code). It combines deep dataflow analysis, 5,000+ static analysis rules, and advisory-database lookups with Claude's reasoning to detect vulnerabilities, hardcoded secrets, and CVE-affected dependencies — then synthesizes findings into a prioritized, actionable report.\n\n> One command. Full security audit. Zero context switching.\n\n---\n\n## What It Scans\n\n| Scanner | What It Catches | Auto-installed |\n|---------|----------------|:--------------:|\n| **CodeQL** | Deep dataflow / taint-analysis SAST — SQL injection, XSS, path traversal, RCE, authentication flaws across 8+ languages | ✓ |\n| **Semgrep** (5,000+ rules) | OWASP Top 10, CWE Top 25, SQL injection, XSS, SSRF, command injection | |\n| **Bandit** | Python-specific security flaws (hardcoded passwords, weak crypto, shell injection) | |\n| **Ruff** | Python code quality and security anti-patterns | |\n| **detect-secrets** | API keys, tokens, passwords, private keys in source code | |\n| **Dependabot CLI** | Ecosystem-specific security updates via GitHub's Dependabot engine (security-updates-only mode, requires Docker at runtime) | ✓ |\n| **osv-scanner** | Dependency CVEs from the OSV / GitHub Advisory Database — works offline, no token required | ✓ |\n| **Trivy** | Docker image CVEs (OS packages + libraries), Dockerfile misconfigurations, and secrets baked into image layers — runs automatically when a Dockerfile is found | ✓ |\n| **pip-audit** | Python dependency CVEs (PyPI Advisory Database…","publisher":null,"homepage":"https://github.com/BalaSriharsha/shieldbot","repository":"https://github.com/BalaSriharsha/shieldbot/issues","version":"1.0.5","license":"MIT","protocols":["mcp"],"tags":["anthropic","claude","code-review","mcp","sast","security","semgrep","vulnerability"],"pricing":null,"endpoints":[{"url":"pypi:shieldbot-mcp","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi"}},"derived":{"capabilities":[{"slug":"code.review","name":"Code Review","confidence":1,"provenance":"derived"},{"slug":"code.security-review","name":"Security Review","confidence":1,"provenance":"declared"},{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":1,"provenance":"derived"},{"slug":"security.scanning","name":"Security Scanning","confidence":1,"provenance":"declared"},{"slug":"data.database","name":"Databases","confidence":0.768,"provenance":"derived"}],"categories":["code","data","dev","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"shieldbot-mcp","registry":"pypi","observedAt":"2026-09-10T12:23:25.484Z","publishedAt":"2026-04-09T17:51:08.093420Z","latestVersion":"1.0.5"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"shieldbot-mcp","url":"https://pypi.org/project/shieldbot-mcp/","firstSeenAt":"2026-09-10T12:21:54.811Z","fetchedAt":"2026-09-10T12:21:54.811Z","normalizedAt":"2026-09-10T12:21:54.811Z"}]},"firstSeenAt":"2026-09-10T12:21:54.811Z","updatedAt":"2026-09-10T12:23:25.484Z"}