Zfuzz
@Zfuzz-dev
About Zfuzz
Real security scanners for AI coding agents: SAST (441 rules), secret detection (419+ patterns), dependency CVEs, MCP/skill vetting, MITRE ATT&CK. Real scanners,
Config
Add this server to your MCP-compatible client using the configuration below.
{
"mcpServers": {
"zfuzz": {
"command": "npx",
"args": [
"-y",
"@zfuzz/mcp"
]
}
}
}Tools
No tools detected
Fetch the live tool list by running this server in a temporary sandbox using the button above.
Overview
What is Zfuzz?
Zfuzz is an MCP server that integrates ten real security tools into AI coding agents, enabling them to scan code, secrets, dependencies, MCP configs, and more. It runs 100% locally with no account or telemetry.
How to use Zfuzz?
Install via claude mcp add zfuzz -- npx -y @zfuzz/mcp or add the standard MCP client configuration with the command npx and args ["-y", "@zfuzz/mcp"]. No configuration keys are mentioned beyond the JSON snippet.
Key features of Zfuzz
- Plugs 10 real security tools into any AI agent.
- scan_code covers SAST with 441 rules, taint analysis, 7 languages.
- scan_secrets detects 419+ patterns plus entropy analysis.
- scan_dependencies checks CVEs via OSV.dev.
- scan_mcp_config and scan_skill vet for prompt injection and booby-trapped scripts.
- 100% local, no account, no telemetry.
Use cases of Zfuzz
- Prevent AI agents from shipping hardcoded keys or vulnerable dependencies.
- Vet MCP configurations and skills for security risks before use.
- Perform threat modeling and MITRE ATT&CK mapping during development.
- Search for security procedures and reconcile permissions across code.
FAQ from Zfuzz
What security tools does Zfuzz include?
It includes scan_code, scan_secrets, scan_dependencies, scan_mcp_config, scan_skill, check_mitre, threat_model, search_security_procedures, explain_finding, and reconcile_permissions.
Does Zfuzz require an internet connection or an account?
No, Zfuzz runs 100% locally with no required account and no telemetry.
What languages are supported for code scanning?
Seven languages are supported for SAST with taint analysis and 441 rules.
Is Zfuzz open source and licensed?
Yes, it is licensed under Apache-2.0 and the repository is at https://github.com/Zfuzz-dev/zfuzz-mcp.
Frequently asked questions
What security tools does Zfuzz include?
It includes scan_code, scan_secrets, scan_dependencies, scan_mcp_config, scan_skill, check_mitre, threat_model, search_security_procedures, explain_finding, and reconcile_permissions.
Does Zfuzz require an internet connection or an account?
No, Zfuzz runs 100% locally with no required account and no telemetry.
What languages are supported for code scanning?
Seven languages are supported for SAST with taint analysis and 441 rules.
Is Zfuzz open source and licensed?
Yes, it is licensed under Apache-2.0 and the repository is at https://github.com/Zfuzz-dev/zfuzz-mcp.
Basic information
More Developer Tools MCP servers
extentos
Asger mølgaardExtentos is a multi-vendor development platform for adding smart-glasses capabilities to existing iOS and Android apps. The simplest analogy is Stripe for smart glasses:
MCP Server By TestMu AI
TestMu AITestMu AI MCP Server lets developers run, debug, and triage tests through natural language directly from their IDE (Cursor, Claude, GitHub Copilot, and other MCP clients). It exposes five tools — HyperExecute (test orche
TranscriptFetch MCP Server
TranscriptFetchModel Context Protocol (MCP) server for TranscriptFetch: fetch YouTube transcripts, search, channels, and playlists from any MCP client.

Air Pipe
airpipeBuild, validate, deploy — HTTP APIs, cron jobs, webhooks and MCP tools — from your AI client.

PuzzleTide Puzzle Generator
Caravaca-LabsWord search generator, crossword generator, and sudoku generator + solver as a local-first MCP server. 15 deterministic tools: printable PDF puzzle worksheets, themed word banks, and verifiable LLM evals. From the makers
Comments