$ npx -y safeweave-mcp — first scan free, no signup
Catch the key your agent pasted —
and the package it invented — before it hits git.
Your AI assistant writes fast and trusts everything. SafeWeave runs inside Cursor, Claude Code, VS Code, and Windsurf as an MCP server — scanning what it writes for hardcoded secrets, risky dependencies, and vulnerabilities, and handing your assistant the fix in the same turn.
No signup — paste in your terminal
$ npx -y safeweave-mcpFree forever: SAST, secrets & dependencies + 1 repo with managed cloud scanning · No credit card · No sales call
Security score 94/100
Hardcoded API key
config/db.ts:12
SQL injection in query builder
api/users.ts:47
Outdated dependency: axios 0.21.1
package.json
Missing input validation
routes/auth.ts:88
Scan any public repo — right now, no signup
Paste a GitHub or GitLab URL. SAST, secrets, and dependency scanners run in our cloud and hand you a shareable security score.
Public repos only · 1 free scan per day · We keep the score, never the code.
8
scanner engines
~12s
Typical scan
OWASP
Top 10 coverage
MIT
licensed open core
MCP-native
Cursor · Claude Code · VS Code · Windsurf
Why SafeWeave
AppSec that keeps up with your AI
Traditional scanners were built for a slower, cloud-first world. SafeWeave is AI-native — local, editor-first, and shaped around the way you actually ship today.
Local scanning
On Free and Self-Hosted Pro, scanners run locally against your code — the source stays on your machine. Only scanner-binary downloads and a license check use the network (Cloud is opt-in and sends file contents to scan).
AI-assisted remediation
Fixes are suggested right where you code. Ask your AI to patch a finding and apply the diff without leaving the file.
Editor-native workflow
MCP plugs SafeWeave straight into Cursor, Claude Code, VS Code and Windsurf. Scan from a prompt — zero context switching.
Built for AI-generated code
Tuned for the patterns AI coding tools actually produce — so the findings match the code your assistant is writing today.
One-command install
No org setup, no CI wiring to get started. Run a single npx command and you are scanning in seconds.
8 scanners, one result
SAST, secrets, dependencies, IaC, container, DAST, license and posture run in parallel — unified into a single report.
Architectural comparison — how the tools work, not a benchmark.
Getting Started
Running in under 2 minutes
Run one command — no signup needed
Get 10 free scans instantly with zero registration. Run npx safeweave-mcp and start scanning. 3 scanners (SAST, Secrets, Dependencies) run locally on your machine. Sign up for a free account for unlimited scans, or upgrade to Pro for all 8 scanners.
# Just run it — no signup, no license key, no config
$ npx safeweave-mcp
# 10 free scans, 3 scanners, runs locally:
# ✓ SAST (Semgrep/Opengrep)
# ✓ Secrets (Gitleaks)
# ✓ Dependencies (npm audit, pip-audit, etc.)
#
# Register free for unlimited scans:
# safeweave.dev/signup
#
# Want all 8 scanners? Add a Pro license key:
# SAFEWEAVE_LICENSE_KEY=sw_shpro_xxxConnect your editor
Add SafeWeave as an MCP server in your AI editor of choice. No license key needed for the free tier — add one later to unlock all 8 scanners on Pro.
# Claude Code (free — no key needed)
$ claude mcp add safeweave -- npx -y safeweave-mcp
# Cursor — .cursor/mcp.json
{
"mcpServers": {
"safeweave": {
"command": "npx",
"args": ["-y", "safeweave-mcp"]
}
}
}
# VS Code — .vscode/mcp.json
{
"servers": {
"safeweave": {
"command": "npx",
"args": ["-y", "safeweave-mcp"]
}
}
}
# Later, for Self-Hosted Pro (all 8 scanners), add the key:
# "env": { "SAFEWEAVE_LICENSE_KEY": "sw_shpro_..." }Ask your AI to scan
Just type a natural-language prompt. SafeWeave handles the rest — SAST, secrets, and dependency scanning run locally on your machine using downloaded binaries. On Free and Self-Hosted Pro plans, your code stays on your device.
> "Scan this project for security vulnerabilities"
> "Check for hardcoded secrets and leaked API keys"
> "Run a dependency audit on this repo"
> "How secure is this codebase? Give me a score."
[scanning] 3 scanners running in parallel...
✓ SAST 2 findings (1 high, 1 medium)
✓ Secrets 1 finding (1 critical — API key in config.ts)
✓ Dependencies 3 findings (1 high, 2 medium)
Score: 78/100 ► 6 findings (1 critical, 2 high, 3 medium)Upgrade for more power
Self-Hosted Pro ($15/mo) unlocks all 8 scanners, compliance profiles, and a local dashboard — everything runs on your machine. Need team features? Cloud plans add hosted dashboards, trend tracking, and AI-suggested fixes.
# Self-Hosted Pro: all 8 scanners + dashboard
# Same license key, just upgrade at safeweave.dev
✓ SAST ✓ IaC ✓ License
✓ Secrets ✓ Container ✓ Posture
✓ Dependencies ✓ DAST
# Compliance profiles included:
Standard · Hardened · OWASP
SOC 2 · PCI-DSS · HIPAAReady to secure your code?
WHAT GETS SCANNED
8 scanners. Coverage across eight scan types.
Every attack surface covered — from source code to running containers — through a single integration point.
All 8 scanners run through a single MCP call — your AI asks once and gets findings from every engine. Built on Semgrep-compatible rules (Opengrep), Trivy, Gitleaks, and Nuclei — battle-tested open-source engines used by millions of developers.
How it's built
One protocol in. Eight scanners out.
A prompt in your editor reaches every scanner through a single MCP connection — no plugins to juggle, no dashboards to tab into.
AI editor
Fast by design. Scanners run in parallel rather than in sequence, and execution stays local — so there is no upload latency between writing code and seeing results.
Deploy your way
Scanners run on your machine
On Free and Self-Hosted Pro the scanners run locally via npx against your code. The only network calls are downloading the scanner binaries and a license check.
- Source code stays local
- One-command npx start
- Free: SAST, secrets, deps
FINDINGS
What a finding looks like
Every finding includes severity, location, and an AI-generated fix suggestion.
45 const query = "SELECT * FROM users"; 46 const filter = req.query.filter; 47 const result = db.query(`${query} WHERE name = '${filter}'`); 48 return res.json(result.rows);
Use parameterized queries instead of string interpolation to prevent SQL injection:
const result = db.query( 'SELECT * FROM users WHERE name = $1', [filter] );
What You Get
See your security posture at a glance
Track findings, monitor trends, and get AI-suggested fixes — all from your dashboard.
Security Score
Total Findings
8
+2 since last scan
Scans This Week
23
all engines
Compliance
SOC 2
profile active
HOW WE COMPARE
An honest comparison
The good tools all have MCP now. Here's where SafeWeave fits — a flat-price scanner you can run before you ever create an account.
| Feature | SafeWeave | Snyk | Semgrep | GitHub Code / Secret Protection |
|---|---|---|---|---|
| Official MCP in Cursor or Claude Code | Yes | Yes (Snyk Studio) | Yes (Guardian) | No official GHAS MCP |
| Editors | Cursor, Claude Code, VS Code, Windsurf | Cursor, Claude, Windsurf, Copilot, VS Code, JetBrains | Cursor, Claude Code, Copilot, VS Code, Windsurf | GitHub Copilot |
| First scan without a paid plan | Yes (npx, 10 scans, no signup) | Yes (Free, account required) | Yes (Free, ≤ 10 contributors) | Yes on public repos |
| Starting paid price | $15/mo flat | $25/mo per contributing dev | $30/mo per contributor (Code) | $19/mo Secret or $30 Code per committer |
| What you scan | 3 scanners free, 8 on Pro | SCA, SAST, IaC, container, secrets | SAST, SCA, secrets (modules) | CodeQL, Dependabot, secret scanning |
| Open-source engines | Yes | Partial | Yes | CodeQL source-available |
| Self-hosted / local | Yes, scanners run locally on Free/Pro | Enterprise / on-prem | Local CLI + hosted Guardian | GitHub Enterprise Server |
| CI/CD | CLI + GitHub Action (Free/Pro); checks on Cloud | Broad | Broad | GitHub-native |
Competitor details as of Aug 2026; check each vendor for current pricing and plans. Free tier includes SAST, secrets, and dependency scanning; all 8 scanners require Self-Hosted Pro or higher.
BUILT FOR YOU
Who is SafeWeave for?
Scan from your IDE. Ship with confidence.
SafeWeave runs as an MCP server inside Cursor, Claude Code, and VS Code. Just ask your AI to scan — no context switching, no dashboards, no config files. Free forever on the self-hosted tier.
Start Scanning FreeCI/CD
A security gate on every push
Two ways to gate CI, both first-class: run it yourself on Free / Self-Hosted Pro, or let the Cloud plan run it for you.
Run it yourself — CLI + GitHub Action
The same scanners as your editor, in any pipeline. Exits non-zero on findings and emits SARIF for GitHub code scanning.
# Any CI npx -y safeweave-mcp scan . --format sarif --fail-on high # …or the GitHub Action uses: nickfluxk/safeweave-action@v1
Managed — GitHub Check Runs
- 1Connect your repo. On the Cloud plan, connect a GitHub repository from your dashboard — no YAML, no runner to configure.
- 2Push or open a PR. Every push and pull request triggers a managed cloud scan against your entitled scanners.
- 3Read the check on the commit. Results post back as a GitHub Check Run with inline annotations on the exact file and line.
Auto-scan before every push
Install the secure-before-push skill and SafeWeave automatically scans your code before every git commit, push, and PR. No manual steps.
You write code
Build features as usual with your AI editor
Auto-scan triggers
SafeWeave scans before every commit and push
Issues blocked
Critical and high severity findings block the push
Ship secure code
Only clean code reaches your repository
Run in your terminal
mkdir -p ~/.claude/skills/secure-before-push
curl -sL https://raw.githubusercontent.com/nickfluxk/safeweave/main/skills/secure-before-push/SKILL.md \
-o ~/.claude/skills/secure-before-push/SKILL.mdWhat happens: Before every git commit, git push, or PR creation, Claude automatically runs a SafeWeave scan. Critical and high findings block the operation. Medium findings warn you. Low/info findings pass through.
Critical / High
Blocks push
Medium
Warns you
Low / Info
Passes through
Free Resource
Get our free OWASP AI security checklist
10 things to check before shipping AI-generated code to production. Delivered to your inbox.
No spam. Unsubscribe anytime.
Ready to find what your AI missed?
npx -y safeweave-mcp in your terminal.THE SAFEWEAVE PROMISE
Zero disruption or your money back
CI SPEED
If SafeWeave adds more than 30 seconds to your CI pipeline, we refund your first month.
ZERO LOCK-IN
Cancel anytime. Export all findings data. No contracts, no penalties, no exit fees.
NO ALERT FATIGUE
Smart deduplication and severity scoring. Deduplicated and severity-ranked findings.
14-day money-back guarantee on all paid plans · Cancel anytime
Pricing
Transparent pricing. No surprises.
Free forever with 3 scanners and 1 connected repo — run npx -y safeweave-mcp. First 10 scans need no signup; unlimited scans with a free account.
Free
First 10 scans need no signup. Unlimited scans with a free account.
- ✓Instant trial (10 scans, no signup)
- ✓SAST (top 20 curated rules)
- —SAST (the full upstream rule registry)
- ✓Secrets (Gitleaks default ruleset, no custom rules)
- ✓Dependency scanning
- —All 8 scanners
- —Compliance profiles (7 frameworks)
- ✓Runs locally via npx
- —Dashboard & reporting
- —Hosted scanning
- 1Connected repositories
- —No-code integrations
- —Team management
- —SSO
- —Custom profiles
Self-Hosted Pro
Most PopularRuns on your infrastructure. License + updates included.
- —Instant trial (10 scans, no signup)
- —SAST (top 20 curated rules)
- ✓SAST (the full upstream rule registry)
- ✓Secrets (Gitleaks default ruleset, no custom rules)
- ✓Dependency scanning
- ✓All 8 scanners
- ✓Compliance profiles (7 frameworks)
- ✓Runs locally via npx
- ✓Dashboard & reporting
- —Hosted scanning
- 1Connected repositories
- —No-code integrations
- —Team management
- —SSO
- —Custom profiles
Cloud
- —Instant trial (10 scans, no signup)
- —SAST (top 20 curated rules)
- ✓SAST (the full upstream rule registry)
- ✓Secrets (Gitleaks default ruleset, no custom rules)
- ✓Dependency scanning
- ✓All 8 scanners
- ✓Compliance profiles (7 frameworks)
- —Runs locally via npx
- ✓Dashboard & reporting
- ✓Hosted scanning
- 10Connected repositories
- —No-code integrations
- —Team management
- —SSO
- —Custom profiles
Cloud Plus
- —Instant trial (10 scans, no signup)
- —SAST (top 20 curated rules)
- ✓SAST (the full upstream rule registry)
- ✓Secrets (Gitleaks default ruleset, no custom rules)
- ✓Dependency scanning
- ✓All 8 scanners
- ✓Compliance profiles (7 frameworks)
- ✓Runs locally via npx
- ✓Dashboard & reporting
- ✓Hosted scanning
- 25Connected repositories
- ✓No-code integrations
- —Team management
- —SSO
- —Custom profiles
Team
Up to 25 seats · Unlimited repos
- —Instant trial (10 scans, no signup)
- —SAST (top 20 curated rules)
- ✓SAST (the full upstream rule registry)
- ✓Secrets (Gitleaks default ruleset, no custom rules)
- ✓Dependency scanning
- ✓All 8 scanners
- ✓Compliance profiles (7 frameworks)
- ✓Runs locally via npx
- ✓Dashboard & reporting
- ✓Hosted scanning
- UnlimitedConnected repositories
- ✓No-code integrations
- ✓Team management
- ✓SSO
- ✓Custom profiles
Invite your team — get 1 month free
From the Blog
Security insights for vibe coders
AI Security Patches Fail 74% of the Time: 6,080 Tested
1Password's Off-by-1 Labs had ChatGPT 5.5 and Claude Opus 4.8 write 6,080 patches for six real CVEs. Only 26.0% were complete fixes that preserved application behavior. Here is the failure mode, in code you will recognize.
GitSpawn: Claude Code Runs Untrusted Repo Code Before You Type
A repository sent to you as a zip can run commands on your machine the moment you open it with Claude Code, Cursor or Codex. Here is how GitSpawn works, what is still unpatched, and the one check that actually stops it.
CVE-2026-35603: Cursor Still Trusts a World-Writable Folder
Claude Code, Cursor, Codex CLI and Gemini CLI on Windows all load machine-wide config from a ProgramData folder any standard user can write to. Anthropic fixed it and got CVE-2026-35603 assigned. Three of the four vendors had not fixed it at disclosure.
FAQ
Frequently asked questions
Do I need to sign up before my first scan?
No. Run npx -y safeweave-mcp, point your AI editor at it, and you get 10 free scans with no account. After that, register for free (still no card) for unlimited scans on the free scanners — SAST, secrets, and dependencies.
Does SafeWeave transmit my source code?
On Free and Self-Hosted Pro, the scanners run locally on your machine, so your source code stays local — the only network calls are downloading the scanner binaries and a license check. The Cloud plan is different and opt-in: when you connect a repo, file contents are sent over HTTPS to api.safeweave.dev to be scanned (secret-bearing files like .env are withheld). Self-Hosted Pro’s dashboard syncs only findings metadata, never source.
How is this different from Snyk, Semgrep, or GitHub?
All of them are good, and Snyk (Snyk Studio) and Semgrep (Guardian) both have official Cursor/Claude Code MCP now, so “MCP-native” isn’t unique. SafeWeave’s angle is simpler adoption for a small team: a flat $15/mo for all 8 scanners (no per-seat math), scanners that run locally on Free and Pro, and a first scan over npx before you ever create an account.
Is there a CI gate?
Two ways. Free / Self-Hosted Pro: run `npx -y safeweave-mcp scan . --format sarif --fail-on high` in any CI (or use the SafeWeave GitHub Action) — it exits non-zero on findings, so the check fails, and it can upload SARIF to GitHub code scanning. Cloud plan: connect a GitHub repo and every push and pull request gets a managed scan that posts a GitHub Check Run with inline annotations on the exact file and line.
Does it need internet access?
On Free and Self-Hosted Pro, scanning is local — internet is needed only to download scanner binaries on first run and to verify your license. On Cloud, file contents are sent to api.safeweave.dev to be scanned.
What do I get free vs paid?
Free: SAST, secrets, and dependency scanning, running locally. Self-Hosted Pro ($15/mo) unlocks all 8 scanners (adds IaC, container, DAST, license, posture) and compliance profiles while keeping scanning local. Cloud ($20) and Cloud Plus ($29) add hosted scans, a dashboard, history, and GitHub checks; Team ($99/mo, 25 seats) adds org management.