MCP scanner for AI-written code

Catch the key your agent pasted — and the package it invented — before it hits git.

Your AI assistant writes fast and trusts everything. SafeWeave runs inside Cursor, Claude Code, VS Code, and Windsurf as an MCP server — scanning what it writes for hardcoded secrets, risky dependencies, and vulnerabilities, and handing your assistant the fix in the same turn.

No signup — paste in your terminal

$ npx -y safeweave-mcp
10 free scans, no signupSAST, secrets & dependencies free1 free repo — managed cloud scanningScanners run locally (Free & Pro)Fix in the same chat turn

Free forever: SAST, secrets & dependencies + 1 repo with managed cloud scanning · No credit card · No sales call

Try it on a real repo

Scan any public repo — right now, no signup

Paste a GitHub or GitLab URL. SAST, secrets, and dependency scanners run in our cloud and hand you a shareable security score.

Public repos only · 1 free scan per day · We keep the score, never the code.

8

scanner engines

~12s

Typical scan

OWASP

Top 10 coverage

MIT

licensed open core

MCP-native

Cursor · Claude Code · VS Code · Windsurf

Why SafeWeave

AppSec that keeps up with your AI

Traditional scanners were built for a slower, cloud-first world. SafeWeave is AI-native — local, editor-first, and shaped around the way you actually ship today.

Local scanning

On Free and Self-Hosted Pro, scanners run locally against your code — the source stays on your machine. Only scanner-binary downloads and a license check use the network (Cloud is opt-in and sends file contents to scan).

AI-assisted remediation

Fixes are suggested right where you code. Ask your AI to patch a finding and apply the diff without leaving the file.

Editor-native workflow

MCP plugs SafeWeave straight into Cursor, Claude Code, VS Code and Windsurf. Scan from a prompt — zero context switching.

Built for AI-generated code

Tuned for the patterns AI coding tools actually produce — so the findings match the code your assistant is writing today.

One-command install

No org setup, no CI wiring to get started. Run a single npx command and you are scanning in seconds.

8 scanners, one result

SAST, secrets, dependencies, IaC, container, DAST, license and posture run in parallel — unified into a single report.

DimensionSafeWeaveTraditional AppSec
Where it runsLocal on Free & Pro; Cloud is opt-inCloud upload required
Install timeOne command, scanning in secondsAccount, org config & CI wiring
WorkflowInside your editor via MCPSeparate dashboard, context switch
RemediationAI-suggested fixes in your editorTicket, triage, hand-off
AI-code fitTuned for AI-generated patternsBuilt for human-written code

Architectural comparison — how the tools work, not a benchmark.

Getting Started

Running in under 2 minutes

Run one command — no signup needed

Get 10 free scans instantly with zero registration. Run npx safeweave-mcp and start scanning. 3 scanners (SAST, Secrets, Dependencies) run locally on your machine. Sign up for a free account for unlimited scans, or upgrade to Pro for all 8 scanners.

shell
# Just run it — no signup, no license key, no config
$ npx safeweave-mcp

# 10 free scans, 3 scanners, runs locally:
#   ✓ SAST (Semgrep/Opengrep)
#   ✓ Secrets (Gitleaks)
#   ✓ Dependencies (npm audit, pip-audit, etc.)
#
# Register free for unlimited scans:
#   safeweave.dev/signup
#
# Want all 8 scanners? Add a Pro license key:
# SAFEWEAVE_LICENSE_KEY=sw_shpro_xxx

Connect your editor

Add SafeWeave as an MCP server in your AI editor of choice. No license key needed for the free tier — add one later to unlock all 8 scanners on Pro.

json
# Claude Code (free — no key needed)
$ claude mcp add safeweave -- npx -y safeweave-mcp

# Cursor — .cursor/mcp.json
{
  "mcpServers": {
    "safeweave": {
      "command": "npx",
      "args": ["-y", "safeweave-mcp"]
    }
  }
}

# VS Code — .vscode/mcp.json
{
  "servers": {
    "safeweave": {
      "command": "npx",
      "args": ["-y", "safeweave-mcp"]
    }
  }
}

# Later, for Self-Hosted Pro (all 8 scanners), add the key:
#   "env": { "SAFEWEAVE_LICENSE_KEY": "sw_shpro_..." }

Ask your AI to scan

Just type a natural-language prompt. SafeWeave handles the rest — SAST, secrets, and dependency scanning run locally on your machine using downloaded binaries. On Free and Self-Hosted Pro plans, your code stays on your device.

shell
> "Scan this project for security vulnerabilities"
> "Check for hardcoded secrets and leaked API keys"
> "Run a dependency audit on this repo"
> "How secure is this codebase? Give me a score."

  [scanning] 3 scanners running in parallel...

  ✓ SAST          2 findings  (1 high, 1 medium)
  ✓ Secrets       1 finding   (1 critical — API key in config.ts)
  ✓ Dependencies  3 findings  (1 high, 2 medium)

  Score: 78/100  ► 6 findings (1 critical, 2 high, 3 medium)

Upgrade for more power

Self-Hosted Pro ($15/mo) unlocks all 8 scanners, compliance profiles, and a local dashboard — everything runs on your machine. Need team features? Cloud plans add hosted dashboards, trend tracking, and AI-suggested fixes.

shell
# Self-Hosted Pro: all 8 scanners + dashboard
# Same license key, just upgrade at safeweave.dev

  ✓ SAST          ✓ IaC          ✓ License
  ✓ Secrets       ✓ Container    ✓ Posture
  ✓ Dependencies  ✓ DAST

# Compliance profiles included:
  Standard · Hardened · OWASP
  SOC 2 · PCI-DSS · HIPAA

WHAT GETS SCANNED

8 scanners. Coverage across eight scan types.

Every attack surface covered — from source code to running containers — through a single integration point.

All 8 scanners run through a single MCP call — your AI asks once and gets findings from every engine. Built on Semgrep-compatible rules (Opengrep), Trivy, Gitleaks, and Nuclei — battle-tested open-source engines used by millions of developers.

How it's built

One protocol in. Eight scanners out.

A prompt in your editor reaches every scanner through a single MCP connection — no plugins to juggle, no dashboards to tab into.

AI editor

CursorClaude CodeVS CodeWindsurf
SafeWeave GatewayMCP server
Parallel Scanning Enginefan-out
SAST
Secrets
Dependencies
IaC
Container
DAST
License
Posture
Unified resultone report · one score

Fast by design. Scanners run in parallel rather than in sequence, and execution stays local — so there is no upload latency between writing code and seeing results.

Deploy your way

Scanners run on your machine

On Free and Self-Hosted Pro the scanners run locally via npx against your code. The only network calls are downloading the scanner binaries and a license check.

  • Source code stays local
  • One-command npx start
  • Free: SAST, secrets, deps

FINDINGS

What a finding looks like

Every finding includes severity, location, and an AI-generated fix suggestion.

HIGHSQL Injection via unsanitized input
CWE-89 · SAST
src/api/users.ts:47:12
45  const query = "SELECT * FROM users";
46  const filter = req.query.filter;
47  const result = db.query(`${query} WHERE name = '${filter}'`);
48  return res.json(result.rows);
FIX

Use parameterized queries instead of string interpolation to prevent SQL injection:

const result = db.query(
  'SELECT * FROM users WHERE name = $1',
  [filter]
);
Auto-detected in 0.8sAI fix suggestion includedMapped to OWASP A03:2021

What You Get

See your security posture at a glance

Track findings, monitor trends, and get AI-suggested fixes — all from your dashboard.

safeweave.dev/dashboard

Security Score

61/100

Total Findings

8

+2 since last scan

Scans This Week

23

all engines

Compliance

SOC 2

profile active

Recent Findings8 total
CRIHardcoded API key in config.ts
HIGHSQL injection via unsanitized input
HIGHPrototype pollution in lodash < 4.17.21
MEDMissing rate limiting on /api/auth
MEDContainer running as root

HOW WE COMPARE

An honest comparison

The good tools all have MCP now. Here's where SafeWeave fits — a flat-price scanner you can run before you ever create an account.

Feature comparison between SafeWeave, Snyk, Semgrep, and GitHub Code / Secret Protection
FeatureSafeWeaveSnykSemgrepGitHub Code / Secret Protection
Official MCP in Cursor or Claude CodeYesYes (Snyk Studio)Yes (Guardian)No official GHAS MCP
EditorsCursor, Claude Code, VS Code, WindsurfCursor, Claude, Windsurf, Copilot, VS Code, JetBrainsCursor, Claude Code, Copilot, VS Code, WindsurfGitHub Copilot
First scan without a paid planYes (npx, 10 scans, no signup)Yes (Free, account required)Yes (Free, ≤ 10 contributors)Yes on public repos
Starting paid price$15/mo flat$25/mo per contributing dev$30/mo per contributor (Code)$19/mo Secret or $30 Code per committer
What you scan3 scanners free, 8 on ProSCA, SAST, IaC, container, secretsSAST, SCA, secrets (modules)CodeQL, Dependabot, secret scanning
Open-source enginesYesPartialYesCodeQL source-available
Self-hosted / localYes, scanners run locally on Free/ProEnterprise / on-premLocal CLI + hosted GuardianGitHub Enterprise Server
CI/CDCLI + GitHub Action (Free/Pro); checks on CloudBroadBroadGitHub-native

Competitor details as of Aug 2026; check each vendor for current pricing and plans. Free tier includes SAST, secrets, and dependency scanning; all 8 scanners require Self-Hosted Pro or higher.

BUILT FOR YOU

Who is SafeWeave for?

⌨️

Scan from your IDE. Ship with confidence.

SafeWeave runs as an MCP server inside Cursor, Claude Code, and VS Code. Just ask your AI to scan — no context switching, no dashboards, no config files. Free forever on the self-hosted tier.

Start Scanning Free

CI/CD

A security gate on every push

Two ways to gate CI, both first-class: run it yourself on Free / Self-Hosted Pro, or let the Cloud plan run it for you.

Free / Self-Hosted Pro

Run it yourself — CLI + GitHub Action

The same scanners as your editor, in any pipeline. Exits non-zero on findings and emits SARIF for GitHub code scanning.

# Any CI
npx -y safeweave-mcp scan . --format sarif --fail-on high

# …or the GitHub Action
uses: nickfluxk/safeweave-action@v1
Cloud plan

Managed — GitHub Check Runs

  1. 1Connect your repo. On the Cloud plan, connect a GitHub repository from your dashboard — no YAML, no runner to configure.
  2. 2Push or open a PR. Every push and pull request triggers a managed cloud scan against your entitled scanners.
  3. 3Read the check on the commit. Results post back as a GitHub Check Run with inline annotations on the exact file and line.
Claude Code Skill

Auto-scan before every push

Install the secure-before-push skill and SafeWeave automatically scans your code before every git commit, push, and PR. No manual steps.

✍️

You write code

Build features as usual with your AI editor

🛡️

Auto-scan triggers

SafeWeave scans before every commit and push

⚠️

Issues blocked

Critical and high severity findings block the push

✅

Ship secure code

Only clean code reaches your repository

Run in your terminal

mkdir -p ~/.claude/skills/secure-before-push
curl -sL https://raw.githubusercontent.com/nickfluxk/safeweave/main/skills/secure-before-push/SKILL.md \
  -o ~/.claude/skills/secure-before-push/SKILL.md

What happens: Before every git commit, git push, or PR creation, Claude automatically runs a SafeWeave scan. Critical and high findings block the operation. Medium findings warn you. Low/info findings pass through.

Critical / High

Blocks push

Medium

Warns you

Low / Info

Passes through

Free Resource

Get our free OWASP AI security checklist

10 things to check before shipping AI-generated code to production. Delivered to your inbox.

No spam. Unsubscribe anytime.

Ready to find what your AI missed?

Start Scanning FreeFirst scan free, no signup — or paste npx -y safeweave-mcp in your terminal.

THE SAFEWEAVE PROMISE

Zero disruption or your money back

CI SPEED

If SafeWeave adds more than 30 seconds to your CI pipeline, we refund your first month.

ZERO LOCK-IN

Cancel anytime. Export all findings data. No contracts, no penalties, no exit fees.

NO ALERT FATIGUE

Smart deduplication and severity scoring. Deduplicated and severity-ranked findings.

14-day money-back guarantee on all paid plans · Cancel anytime

Pricing

Transparent pricing. No surprises.

Free forever with 3 scanners and 1 connected repo — run npx -y safeweave-mcp. First 10 scans need no signup; unlimited scans with a free account.

MonthlyYearlyYearly — save 2 months free 🎉

Free

$0

First 10 scans need no signup. Unlimited scans with a free account.

  • ✓Instant trial (10 scans, no signup)
  • ✓SAST (top 20 curated rules)
  • —SAST (the full upstream rule registry)
  • ✓Secrets (Gitleaks default ruleset, no custom rules)
  • ✓Dependency scanning
  • —All 8 scanners
  • —Compliance profiles (7 frameworks)
  • ✓Runs locally via npx
  • —Dashboard & reporting
  • —Hosted scanning
  • 1Connected repositories
  • —No-code integrations
  • —Team management
  • —SSO
  • —Custom profiles

Self-Hosted Pro

Most Popular
$15/mo

Runs on your infrastructure. License + updates included.

  • —Instant trial (10 scans, no signup)
  • —SAST (top 20 curated rules)
  • ✓SAST (the full upstream rule registry)
  • ✓Secrets (Gitleaks default ruleset, no custom rules)
  • ✓Dependency scanning
  • ✓All 8 scanners
  • ✓Compliance profiles (7 frameworks)
  • ✓Runs locally via npx
  • ✓Dashboard & reporting
  • —Hosted scanning
  • 1Connected repositories
  • —No-code integrations
  • —Team management
  • —SSO
  • —Custom profiles
Self-Host in 5 Minutes
✓ 14-day money-back guarantee · Cancel anytime

Cloud

$20/mo
  • —Instant trial (10 scans, no signup)
  • —SAST (top 20 curated rules)
  • ✓SAST (the full upstream rule registry)
  • ✓Secrets (Gitleaks default ruleset, no custom rules)
  • ✓Dependency scanning
  • ✓All 8 scanners
  • ✓Compliance profiles (7 frameworks)
  • —Runs locally via npx
  • ✓Dashboard & reporting
  • ✓Hosted scanning
  • 10Connected repositories
  • —No-code integrations
  • —Team management
  • —SSO
  • —Custom profiles
Start 14-Day Trial
✓ 14-day money-back guarantee · Cancel anytime

Cloud Plus

$29/mo
  • —Instant trial (10 scans, no signup)
  • —SAST (top 20 curated rules)
  • ✓SAST (the full upstream rule registry)
  • ✓Secrets (Gitleaks default ruleset, no custom rules)
  • ✓Dependency scanning
  • ✓All 8 scanners
  • ✓Compliance profiles (7 frameworks)
  • ✓Runs locally via npx
  • ✓Dashboard & reporting
  • ✓Hosted scanning
  • 25Connected repositories
  • ✓No-code integrations
  • —Team management
  • —SSO
  • —Custom profiles
Start 14-Day Trial
✓ 14-day money-back guarantee · Cancel anytime

Team

$99/mo

Up to 25 seats · Unlimited repos

  • —Instant trial (10 scans, no signup)
  • —SAST (top 20 curated rules)
  • ✓SAST (the full upstream rule registry)
  • ✓Secrets (Gitleaks default ruleset, no custom rules)
  • ✓Dependency scanning
  • ✓All 8 scanners
  • ✓Compliance profiles (7 frameworks)
  • ✓Runs locally via npx
  • ✓Dashboard & reporting
  • ✓Hosted scanning
  • UnlimitedConnected repositories
  • ✓No-code integrations
  • ✓Team management
  • ✓SSO
  • ✓Custom profiles
Try Team Free
✓ 14-day money-back guarantee · Cancel anytime

Invite your team — get 1 month free

FAQ

Frequently asked questions

Do I need to sign up before my first scan?

No. Run npx -y safeweave-mcp, point your AI editor at it, and you get 10 free scans with no account. After that, register for free (still no card) for unlimited scans on the free scanners — SAST, secrets, and dependencies.

Does SafeWeave transmit my source code?

On Free and Self-Hosted Pro, the scanners run locally on your machine, so your source code stays local — the only network calls are downloading the scanner binaries and a license check. The Cloud plan is different and opt-in: when you connect a repo, file contents are sent over HTTPS to api.safeweave.dev to be scanned (secret-bearing files like .env are withheld). Self-Hosted Pro’s dashboard syncs only findings metadata, never source.

How is this different from Snyk, Semgrep, or GitHub?

All of them are good, and Snyk (Snyk Studio) and Semgrep (Guardian) both have official Cursor/Claude Code MCP now, so “MCP-native” isn’t unique. SafeWeave’s angle is simpler adoption for a small team: a flat $15/mo for all 8 scanners (no per-seat math), scanners that run locally on Free and Pro, and a first scan over npx before you ever create an account.

Is there a CI gate?

Two ways. Free / Self-Hosted Pro: run `npx -y safeweave-mcp scan . --format sarif --fail-on high` in any CI (or use the SafeWeave GitHub Action) — it exits non-zero on findings, so the check fails, and it can upload SARIF to GitHub code scanning. Cloud plan: connect a GitHub repo and every push and pull request gets a managed scan that posts a GitHub Check Run with inline annotations on the exact file and line.

Does it need internet access?

On Free and Self-Hosted Pro, scanning is local — internet is needed only to download scanner binaries on first run and to verify your license. On Cloud, file contents are sent to api.safeweave.dev to be scanned.

What do I get free vs paid?

Free: SAST, secrets, and dependency scanning, running locally. Self-Hosted Pro ($15/mo) unlocks all 8 scanners (adds IaC, container, DAST, license, posture) and compliance profiles while keeping scanning local. Cloud ($20) and Cloud Plus ($29) add hosted scans, a dashboard, history, and GitHub checks; Team ($99/mo, 25 seats) adds org management.