{"id":"b7c6f53e-ba5f-49c1-b642-b508e559969f","slug":"smithery-daniel-abbay-compuute-scan-api","name":"Compuute MCP Security Scanner","description":"Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.\n\n37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning).\n\nThis is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly.\n\nPOST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review.\n\nWraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.","capabilities":[],"protocols":["MCP"],"safetyScore":86,"overallRank":34.7,"trustScore":null,"trust":null,"source":"SMITHERY","updatedAt":"2026-10-09T01:19:40.948Z"}