CodeInspectus adds local AI-code security scanning to Codex through MCP
hibzy7 · reddit · 2026-07-26
CodeInspectus is a free, MIT-licensed local security MCP server for AI-generated web apps. It lets Codex scan a project, explain findings, suggest fixes, and rescan after approval, all without telemetry or network egress during scans.
The project ships with 32 application-security checks and more than 200 secret/API-key patterns, including rules aimed at AI-generated code such as browser-exposed secrets, unsafe Supabase usage, prompt-injection paths, and rendering untrusted model output through raw HTML APIs. Under the hood it combines Opengrep, Gitleaks, and Trivy, then normalizes their results into one format.
More from coding & agent
- Codex backs up old high-school hard drives and resurfaces deeply awkward files — shakoistsLog · 2026-07-26
- Elon Musk reposts praise for Grok Build as a favorite agentic coding CLI — elonmusk · 2026-07-26
- whatbroke diffs agent traces and shows a 1B model can call the wrong tool with fluent text — Impossible-Alarm-738 · 2026-07-26
- MCP success is not correctness: builders debate who verifies side effects after tool calls — marcin_michalak · 2026-07-26
- Open Minis open-sources its full iOS and Android on-device agent stack — dotey · 2026-07-26
- Sam Altman says Codex was a “kamikaze mission” to catch Claude Code — soumitrashukla9 · 2026-07-26