XploitScan MCP Server
io.github.bgage72590/xploitscan-mcpv1.7.0
Security scanner for AI-generated code. 30 free rules; all 223 with a paid-plan API key.
context tax
queued
security
queued
cold start
queued
freshness
Active6d ago
Install XploitScan MCP server
Install in Claude Code
claude mcp add xploitscan -e XPLOITSCAN_API_KEY='<xploitscan-api-key>' -- npx -y xploitscan-mcpInstall in Cursor
{
"mcpServers": {
"xploitscan": {
"command": "npx",
"args": [
"-y",
"xploitscan-mcp"
],
"env": {
"XPLOITSCAN_API_KEY": "<xploitscan-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"xploitscan": {
"command": "npx",
"args": [
"-y",
"xploitscan-mcp"
],
"env": {
"XPLOITSCAN_API_KEY": "<xploitscan-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"xploitscan": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"xploitscan-mcp"
],
"env": {
"XPLOITSCAN_API_KEY": "<xploitscan-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"xploitscan": {
"command": "npx",
"args": [
"-y",
"xploitscan-mcp"
],
"env": {
"XPLOITSCAN_API_KEY": "<xploitscan-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| XPLOITSCAN_API_KEY | — | yes | Optional. An xpls_ API key from a paid-plan account. Without it, the 30 free rules run; with it, all 223. |
Freshness
Active — last maintenance signal 6d ago. The newest of the signals below sets the band.
Last commit (default branch)
no data · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-10-04 · 6d ago · official registry · v1.7.0
FAQ
›How do I install the XploitScan MCP server in Claude Code?
Run: claude mcp add xploitscan -e XPLOITSCAN_API_KEY='<xploitscan-api-key>' -- npx -y xploitscan-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does XploitScan require an API key?
Yes. It expects XPLOITSCAN_API_KEY, of which 1 is a secret.
›Can I use XploitScan as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is XploitScan in the official MCP registry?
Yes, as io.github.bgage72590/xploitscan-mcp.
Alternatives to XploitScan
Other security MCP servers.