Keysnag MCP Server
Cybersecurity for AI founders and vibe coders. A pre-push security gate for apps built with Claude Code, Cursor, Codex, Lovable and Bolt: 12 offline checks for leaked keys, Supabase RLS, cross-account (IDOR) access, injection, Stripe webhooks, known CVEs
context tax
queued
security
queued
cold start
queued
freshness
Active13d ago
Install Keysnag MCP server
Install in Claude Code
claude mcp add keysnag -- npx -y keysnagInstall in Cursor
{
"mcpServers": {
"keysnag": {
"command": "npx",
"args": [
"-y",
"keysnag"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"keysnag": {
"command": "npx",
"args": [
"-y",
"keysnag"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"keysnag": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"keysnag"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"keysnag": {
"command": "npx",
"args": [
"-y",
"keysnag"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Freshness
Active — last maintenance signal 13d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-27 · 13d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
no data · official registry
FAQ
›How do I install the Keysnag MCP server in Claude Code?
Run: claude mcp add keysnag -- npx -y keysnag. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Keysnag require an API key?
No required environment variables are declared in its published metadata.
›Can I use Keysnag as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Keysnag in the official MCP registry?
No. It was indexed from npm.
Alternatives to Keysnag
Other database MCP servers.