Hi, I maintain sentinel-scan-cli, an open-source OWASP-mapped security scanner for MCP servers. Discussions looks disabled on this repo so filing as an issue instead, feel free to close/relabel.
Specific note on Context+: propose_commit is described as "the only way to write code" and run_static_analysis executes native linters/compilers against the target codebase. That is a direct-write-plus-execute surface driven by LLM tool calls, which is exactly the kind of thing worth having an independent look at, especially since it also builds a persistent memory/RAG graph from the codebase that downstream calls can traverse.
I am piloting a $99 one-time scan (tool input validation, write-path safety, execution surface) with a short written report, optional $299/yr to re-run per release as a badge. Nothing to install on your side, I run it and send results.
Happy to just run it and send the report either way. Good luck with the project regardless.
Skye, Ventrova (ventrova.dev)
Hi, I maintain sentinel-scan-cli, an open-source OWASP-mapped security scanner for MCP servers. Discussions looks disabled on this repo so filing as an issue instead, feel free to close/relabel.
Specific note on Context+:
propose_commitis described as "the only way to write code" andrun_static_analysisexecutes native linters/compilers against the target codebase. That is a direct-write-plus-execute surface driven by LLM tool calls, which is exactly the kind of thing worth having an independent look at, especially since it also builds a persistent memory/RAG graph from the codebase that downstream calls can traverse.I am piloting a $99 one-time scan (tool input validation, write-path safety, execution surface) with a short written report, optional $299/yr to re-run per release as a badge. Nothing to install on your side, I run it and send results.
Happy to just run it and send the report either way. Good luck with the project regardless.
Skye, Ventrova (ventrova.dev)