
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@digidenone/synapseaudit-mcp
Advanced tools
SynapseAudit MCP Server - AI-Powered Security Scanner for LLM Integration
AI-Powered Security Scanner for LLMs.
Integrate professional security analysis into Claude, GitHub Copilot, Cursor, and other AI agents. This MCP server allows your LLM to scan code, detect vulnerabilities, and use the SynapseCortex engine to fix them.
# Clone repository
git clone https://github.com/digidenone/SynapseAudit.git
cd SynapseAudit/mcp-server
# Install and Build
npm install
npm run build
Add the following to your claude_desktop_config.json:
{
"mcpServers": {
"synapseaudit": {
"command": "node",
"args": ["/absolute/path/to/SynapseAudit/mcp-server/dist/index.js"]
}
}
}
The server exposes the following tools to the LLM:
| Tool | Description | Arguments |
|---|---|---|
scan_project | Scan a directory for vulnerabilities. | path (string), deep (boolean) |
scan_sca | Check dependencies for known vulnerabilities. | path (string) |
scan_secrets | Find exposed API keys and credentials. | path (string) |
scan_iac | Audit Infrastructure-as-Code files. | path (string) |
scan_sbom | Generate CycloneDX SBOM. | path (string) |
analyze_code | Analyze a specific code snippet. | code (string), language (string) |
explain_vuln | Get a detailed explanation of a vulnerability type. | vuln_id (string) |
get_fix | Generate a secure fix for a finding. | vuln_id (string), context (string) |
check_compliance | Check code against specific standards (OWASP, GDPR). | standard (string) |
The server provides read-only resources:
synapse://rules/active: List of currently active security rules.synapse://cwe/definitions: Common Weakness Enumeration definitions.synapse://stats/current: Current session statistics.MIT
FAQs
SynapseAudit MCP Server - AI-Powered Security Scanner for LLM Integration
We found that @digidenone/synapseaudit-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.