AgentHubAgentHub
Compuute MCP Security Scanner icon

Compuute MCP Security Scanner MCP Setup & Guide

MCP Serversmithery

io.smithery.daniel-abbay.compuute-scan-api

Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly. POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review. Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.

Copy the install config on this page first, then verify docs and permissions upstream.

Popularity

Uses1.6k

Overview

Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly. POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review. Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo. Compuute MCP Security Scanner is a MCP Server listed from smithery. Transports: streamable-http. This page includes an overview, setup tutorial, install commands, and use cases for Trae, Tongyi Lingma, Cursor, Claude Code, and VS Code.

remote

AgentHub Verified AvailabilityTested & Ready

Automated pipeline validated install commands, protocol & client compatibility

Verified At2026-09-28
Install Snippets TestedCLI & JSON config syntax verified
Protocol Handshake ReadyComplies with JSON-RPC 2.0 specifications
Origin Registry ActiveSourced from smithery
Verified ClientsClaude Code、Claude Desktop、Cursor 等
Security Tier: A 级 · 标准受控运行 (A)·Scanned for high-risk vulnerabilities. Recommended to run with project-scoped permissions.

Copy by platform

Choose your platform

  1. Open or create .cursor/mcp.json in your project root
  2. Click Copy config and paste; if you already have MCPs, merge only this entry under mcpServers
  3. Save, then Cmd+Shift+P (Ctrl+Shift+P on Windows) → Reload Window
Click to copy snippet
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Setup tutorial

  1. Open the Compuute MCP Security Scanner page and confirm this MCP Server (source: smithery).
  2. Copy the Cursor, Claude Code, or VS Code snippet.
  3. Merge it into mcpServers and replace env placeholders with real secrets.
  4. Reload the window, then call the MCP tools from your agent chat.

Install commands

Install commands and setup steps are in the HTML so search engines and no-JS browsers can read them without running client JavaScript.

Claude Code (remote)

  1. Install Claude Code CLI (claude must work in your terminal)
  2. Click Copy config below, paste into terminal, and run
  3. Restart Claude Code after it succeeds
claude mcp add --transport http io-smithery-daniel-abbay-compuute-scan-api https://smithery.ai/servers/daniel-abbay/compuute-scan-api

Cursor — .cursor/mcp.json (remote)

  1. Open or create .cursor/mcp.json in your project root
  2. Click Copy config and paste; if you already have MCPs, merge only this entry under mcpServers
  3. Save, then Cmd+Shift+P (Ctrl+Shift+P on Windows) → Reload Window
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

VS Code — .vscode/mcp.json (remote)

  1. Install GitHub Copilot in VS Code with MCP support
  2. Open or create .vscode/mcp.json in your project root
  3. Click Copy config and paste; merge only this mcpServers entry if others exist
  4. Save and Developer: Reload Window
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Claude Desktop — claude_desktop_config.json (remote)

  1. Open Claude Desktop config: macOS ~/Library/Application Support/Claude/claude_desktop_config.json; Windows %APPDATA%\Claude\claude_desktop_config.json
  2. Click Copy config and merge under mcpServers
  3. Fully quit and restart Claude Desktop
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Trae — .trae/mcp.json (remote)

  1. Trae → Settings → MCP, or edit .trae/mcp.json (project) / global mcp.json
  2. Use Manual add / Raw JSON, click Copy config and paste; merge only this mcpServers entry
  3. Save, pick an MCP-capable agent (e.g. Builder with MCP), reload window if needed
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Cherry Studio — MCP settings (remote)

  1. Cherry Studio → Settings → MCP Servers
  2. Add via JSON import or SSE/HTTP with the URL
  3. Click Copy config, paste the mcpServers entry, then enable the server
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Tongyi Lingma — MCP config (remote)

  1. Tongyi Lingma: avatar → Settings → MCP (agent mode; plugin ~v2.5+)
  2. Click + → config file or manual SSE/HTTP with the service URL
  3. Click Copy config and merge JSON; a healthy icon means connected
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Cline — MCP Servers (remote)

  1. VS Code Cline panel → settings gear → MCP Servers
  2. Click Copy config and paste the mcpServers entry into Cline
  3. Save; Cline reconnects and shows tools
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

WorkBuddy — .workbuddy/mcp.json (remote)

  1. WorkBuddy: sidebar Plugins → MCP Servers → Configure MCP; or edit ~/.workbuddy/mcp.json (user) / .workbuddy/mcp.json (project)
  2. Click Copy config and merge under mcpServers (Tencent WorkBuddy / CodeBuddy)
  3. Save; status should turn green — fully restart the client if needed
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Windsurf — mcp_config.json (remote)

  1. Edit ~/.codeium/windsurf/mcp_config.json (Windows: %USERPROFILE%\.codeium\windsurf\mcp_config.json)
  2. Click Copy config and merge; remote MCP must use serverUrl (not url)
  3. Save and refresh MCP in Windsurf Cascade
{
  "mcpServers": {
    "io-smithery-daniel-abbay-compuute-scan-api": {
      "serverUrl": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
    }
  }
}

Troubleshooting & Common ErrorsFAQ

Common connection errors and verified fixes for Compuute MCP Security Scanner

Getting 'connection closed' or exit code 1 in Cursor / Claude Code for Compuute MCP Security Scanner?

Usually caused by missing runtime paths or IDE environment inheritance. Fix steps: 1. Verify Node.js 18+ (npx) or Python 3.10+ (uvx) is installed; 2. Run 'which npx' or 'which uvx' in terminal, and replace 'command' with absolute path; 3. Reload or restart the client window after modifying config.

Fix Snippet
# Check binary path in terminal:
which npx
node -v
Getting 'spawn npx ENOENT' or 'command not found'?

The editor background process does not inherit your full terminal PATH. Solution: Globally install the package, or set the absolute binary path (e.g. C:\Program Files\nodejs\npx.cmd on Windows, or /usr/local/bin/npx on macOS).

Tool calls timing out or failing to download packages?

First-time package downloading might be slow or timeout due to network limits. Configure a reliable mirror or check outbound proxy settings.

Tool Mock Playground

Sandbox

Compuute MCP Security Scanner Tool Interface Simulation · Preview tool schema & outputs without local runtime

Sandbox Ready
fn: io_smithery_daniel_abbay_compuutExecute the core tool interface of Compuute MCP Security Scanner
Request ArgumentsJSON Schema
{
  "target": "Compuute MCP Security Scanner",
  "action": "execute",
  "options": {
    "mode": "standard",
    "timeoutMs": 5000
  }
}
💡Parameters generated dynamically by Agent runtime
Agent Tool Output

Click 'Run Mock' above

to preview the raw response returned to the LLM

Env: AgentHub Virtual SandboxJSON-RPC 2.0

Decision Guide: Why & When to Use

Assess suitability before installing to save trial-and-error time

Best Suited For
  • When your AI Agent needs tool calling capabilities in this domain
  • Automating repetitive workflows in your IDE or terminal
  • Pairing with modern clients supporting MCP/Skill standards
When NOT to Use
  • When missing required API secrets or local runtime prerequisites
  • Pure conversational requests that don't need external system access
Recommended Workflow Pairing:

Compuute MCP Security Scanner + Scenario Prompt → Complete Agent Automation

MCP hands-on: install to visible results

Follow the full lab (expected UI/output + contrast checks). After installing this item, verify with the tutorial prompts.

Open tutorial →

Related resources

Often paired with

PC Build Assistant

v0.1.43

SkillClawHub5.1k

io.clawhub.gongyu0918-debug/pc-builder-assistant

Use for budget desktop PC build planning and recommendations, PC hardware DIY, upgrades, configuration completion, compatibility checks, hardware guidance, local LLM GPU/VRAM/RAM sizing, and gaming, streaming, creator, aesthetic, compact or ITX builds. Bundled prices are China-market CNY references; explicit user overlays keep currencies separate. 中文支持预算装机、装机 DIY、整机推荐、旧机升级、配置补全、搭配或兼容检查、硬件问答,以及游戏直播、生产力、本地 AI、外观海景房和紧凑或 ITX 主机。 Do not use for laptops, server procurement, ordering or payment, remote control, security isolation, or standalone software, game or agent tutorials.

source

Keep exploring AgentHub

Most people compare similar tools or check scenario guides before installing—start here.

Listing badge: put AgentHub on your site

Copy either snippet into your project homepage, docs, or GitHub README. The badge is a hotlinked SVG — nothing to host — and it links back to this page so visitors can find the install steps.

PreviewListed on AgentHub: Compuute MCP Security Scanner
HTML
<a href="https://myagenthub.cn/p/io.smithery.daniel-abbay.compuute-scan-api" title="Listed on AgentHub: Compuute MCP Security Scanner" target="_blank" rel="noopener">
  <img src="https://myagenthub.cn/badge/io.smithery.daniel-abbay.compuute-scan-api?lang=en" alt="Listed on AgentHub: Compuute MCP Security Scanner" height="20" style="border:0"/>
</a>
Markdown (GitHub README)
[![Listed on AgentHub: Compuute MCP Security Scanner](https://myagenthub.cn/badge/io.smithery.daniel-abbay.compuute-scan-api?lang=en)](https://myagenthub.cn/p/io.smithery.daniel-abbay.compuute-scan-api)

Badges are generated on the fly from /badge/<package-id>, so name and listing changes propagate automatically. Keep the link target unchanged — it is what counts as the referral.

Unified Manifest

{
  "id": "io.smithery.daniel-abbay.compuute-scan-api",
  "type": "mcp-server",
  "version": "latest",
  "displayName": "Compuute MCP Security Scanner",
  "description": "Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.\n\n37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning).\n\nThis is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly.\n\nPOST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review.\n\nWraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.",
  "iconUrl": "https://www.google.com/s2/favicons?domain=scan.compuute.se&sz=64",
  "homepage": "https://scan.compuute.se",
  "distribution": {
    "packages": [],
    "remotes": [
      {
        "transport": "streamable-http",
        "url": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api"
      }
    ]
  },
  "dependencies": [],
  "installTargets": [
    "claude-code",
    "claude-desktop",
    "cursor",
    "vscode",
    "trae",
    "cherry-studio",
    "lingma",
    "windsurf",
    "cline",
    "workbuddy"
  ],
  "keywords": [
    "use_count:1597",
    "remote"
  ],
  "provenance": {
    "origin": "smithery",
    "originalId": "daniel-abbay/compuute-scan-api",
    "originalUrl": "https://smithery.ai/servers/daniel-abbay/compuute-scan-api",
    "isOfficial": false,
    "status": "active"
  }
}