The service
secure-mcp is a local Model Context Protocol server that helps coding agents perform defensive, remediation-focused security review of source repositories. The source is publicly available under the Apache License 2.0.
Open-source license
Your rights to use, reproduce, modify, and distribute the software are governed by the Apache License 2.0. Nothing on this page narrows the rights granted by that license.
Defensive project scope
The project is designed for defensive review of codebases the reviewer is authorized to assess. Its maintained tools identify potential weaknesses, classify evidence, and recommend remediation; exploit generation, credential use, and live-target interaction are outside the project's supported scope.
Findings are candidates
Findings are evidence-oriented candidates produced by bounded static inspection. They are not guarantees, vulnerability declarations, or permission to act. Confirm findings in code and understand the runtime context before remediating. Coverage reports state what was and was not reviewed — read them before relying on an empty result.
No warranty
The software is provided on an “as is” basis, without warranties or conditions, as stated in the Apache License 2.0. Review the license for the complete warranty disclaimer and limitation of liability.
Intellectual property
Project names and marks are not licensed except for reasonable use in describing the origin of the work, as set out in Apache-2.0. Third-party material remains subject to its own attribution and license terms.
Changes
These terms may be updated from time to time; the version on this page always applies to current use.
Contact
Questions about these terms? Use the project support page to find the appropriate public or private GitHub channel.