Feldspar free repository security scan MCP server

Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.

80/100?Number 32 of 1,193 in Developer Tools

verified publishersource repositoryupdated recentlyhosted endpointactive entryno credentials

How this score is calculated

Hosted VERIFIED Developer Tools

Details

Registry name
com.project-feldspar/scan
Publisher
project-feldspar
Version
0.2.0
Distribution
Hosted. the publisher runs this server and your client connects to their URL over HTTP. Nothing to install, but your requests go to a third party.
Transports
streamable-http
First published
Registry updated
Credentials required
-
Schema generation
2025-12-11

Hosted endpoints

Endpoint 1

URL
https://project-feldspar.com/mcp
Transport
streamable-http
Authentication
not declared

Install Feldspar free repository security scan

Pick your client. The configuration below is generated from this server's published package and endpoint data.

Claude Code command line

Configuration file: .mcp.json or ~/.claude.json

Hosted endpoint
claude mcp add scan-project-feldspar --transport http https://project-feldspar.com/mcp

Nothing to install. The client connects to the publisher's URL.

Check it worked: Run claude mcp list and check the server reports connected.

Official Claude Code MCP documentation

Cursor IDE

Configuration file: .cursor/mcp.json or ~/.cursor/mcp.json

Hosted endpoint
{
  "mcpServers": {
    "scan-project-feldspar": {
      "type": "http",
      "url": "https://project-feldspar.com/mcp"
    }
  }
}

Nothing to install. The client connects to the publisher's URL.

Check it worked: The server appears under Settings, then MCP with a green dot.

Official Cursor MCP documentation

Claude Desktop desktop app

Configuration file: ~/Library/Application Support/Claude/claude_desktop_config.json or %APPDATA%\Claude\claude_desktop_config.json

Hosted endpoint
{
  "mcpServers": {
    "scan-project-feldspar": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://project-feldspar.com/mcp"]
    }
  }
}

Nothing to install. The client connects to the publisher's URL.

Quit the app completely and reopen it.

Check it worked: Look for the tools icon in the message composer.

Official Claude Desktop MCP documentation

Visual Studio Code IDE

Configuration file: .vscode/mcp.json or user settings.json under mcp

Hosted endpoint
{
  "servers": {
    "scan-project-feldspar": {
      "type": "http",
      "url": "https://project-feldspar.com/mcp"
    }
  }
}

Nothing to install. The client connects to the publisher's URL.

Check it worked: Open the Copilot chat tools picker and confirm the server is listed.

Official Visual Studio Code MCP documentation

Codex CLI command line

Configuration file: ~/.codex/config.toml

Hosted endpoint
codex mcp add scan-project-feldspar --transport http https://project-feldspar.com/mcp

Nothing to install. The client connects to the publisher's URL.

Check it worked: Run codex mcp list and check the server is present.

Official Codex CLI MCP documentation

More clients (9), including automation platforms

Tools

Could not determine.

Command line alternative

Could not determine. The available signals were not conclusive enough to say either way, so this is left open rather than guessed.

Repository signals

Not checked yet. Stars, licence, language and last commit date are read from the source host, and that pass has not run against this record.

Security, privacy and enterprise use

The publisher's website links no privacy policy, terms, security page or enterprise information that could be found automatically. It may still exist somewhere less obvious on their site.

Publisher

Profiles
none listed on the publisher's site
Community
no subreddit linked from the publisher's site

Review platforms

CAPTERRA G2 OMR TRUSTPILOT

Ratings are not shown. G2, Trustpilot and Capterra all prohibit republishing their scores without a licence, and marking up a borrowed rating as our own would breach search engine policy. These are profile links only, and a profile may not exist for every publisher.

Frequently asked questions

What does the Feldspar free repository security scan MCP server do?
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
Do I need to install anything to use Feldspar free repository security scan?
No. Feldspar free repository security scan is published as a hosted endpoint, so a compatible client connects to it over the network.
How do I install Feldspar free repository security scan?
Point your client at the hosted endpoint https://project-feldspar.com/mcp. No local install is needed.
Which transport does Feldspar free repository security scan use?
Streamable http. Your client has to support that transport to connect.
Where is the source code for Feldspar free repository security scan?
The publisher lists https://github.com/project-feldspar-resources/feldspar-scan as the source repository.
Is Feldspar free repository security scan an official server?
It is published under the namespace com.project-feldspar, which means the publisher proved control of that domain when registering. That confirms who published it, not that it has been reviewed for quality or security.
Which version of Feldspar free repository security scan is listed here?
Version 0.2.0, taken from the latest registry entry.