MCP connector
Audit a GitHub repository from inside Claude
Add SystemAudit as a connector and ask about any public repository in plain English. Claude gets back a health score out of 100, the highest-ranked risks, how the code is structured, and how many credentials look exposed, with the number of files read out of the total every time.
Connector URL
https://systemaudit.dev/api/mcpFree, read-only, no account needed. Works in any MCP client that supports remote servers.
Add it
Claude (web and desktop)
- Open Customize, then Connectors.
- Click "+", then "Add custom connector".
- Paste the connector URL and click Add. No sign-in or OAuth settings are needed.
Works on every plan; the Free plan allows one custom connector. On Team and Enterprise, an owner adds it under Organization settings, then Connectors, and members connect it from Customize.
Claude Code
claude mcp add --transport http --scope user systemaudit https://systemaudit.dev/api/mcp--scope user makes it available in every project; leave it out to add it to the current project only.
Cursor
Add this to ~/.cursor/mcp.json for every project, or .cursor/mcp.json for one:
{"mcpServers":{"systemaudit":{"url":"https://systemaudit.dev/api/mcp"}}}What to ask
- Scan github.com/vercel/next.js and tell me the three risks I should look at first.
- Is this repository safe to hand to a new developer? github.com/owner/repo
- How is github.com/owner/repo structured, and which files does nothing import?
- Does github.com/owner/repo have credentials committed to it?
The three tools
Scan a public repository
scan_repositoryRuns a static health check on a public GitHub repository and returns a health score out of 100, the highest-ranked risks in plain English, how the project is built (ecosystem, languages, dependencies, structural signals), counts of potential exposed credentials, and how many files were read out of how many the repository contains. One call answers most questions about a repository. Use it when someone is deciding whether to depend on, adopt, fork, contribute to, invest in or acquire a public GitHub project; asks whether a repository is well built, maintained, safe or production-ready; or wants a second opinion on a codebase. To compare projects, call it once per repository. Credentials are counts only; the full report on systemaudit.dev shows locations for critical and high findings, as it does for any public repository scan. Reads a capped subset of files through the GitHub API; no code is executed and no file contents are returned. Public repositories only.
Describe a repository's structure
get_architectureReturns how a public GitHub repository is put together: its package ecosystem, detected architecture pattern, language mix, dependency count, and structural signals such as circular imports and files that nothing else imports. Use it when someone asks only how a repository is built, for example before reading, extending or contributing to it; scan_repository already includes these figures alongside the health check. Public repositories only.
Count exposed credentials
secrets_summaryReports how many potential hardcoded credentials and committed environment files were found in a public GitHub repository, counted by severity. Use it when someone asks only whether a repository leaks API keys, passwords, tokens or .env files; scan_repository already includes these counts alongside the health check. The connector returns counts only; the full report on systemaudit.dev shows locations for critical and high findings, as it does for any public repository scan. Public repositories only.
Each takes a public repository as a URL or owner/name, and each answer links to the full report on systemaudit.dev.
What it does and doesn't do
- Public GitHub repositories only. A private or unreadable repository is refused before anything is scanned.
- Read-only: no code is executed, nothing is changed, and no file contents are returned.
- The connector returns counts only; the full report on systemaudit.dev shows locations for critical and high findings, as it does for any public repository scan.
- Every answer states how many files were read out of how many the repository contains. The scanner reads a capped subset over the GitHub API and never clones.
- At most 3 new scans an hour per person and 10 an hour in total. Questions answered from a recent scan of an unchanged repository do not count.
- No AI model is called. Every figure comes from the deterministic scan.
More on how findings are produced and where they stop: methodology and privacy.
When you need more than a summary
The connector answers “should I worry?” For the file and line of every finding, private repositories, and a plan of what to fix first, run the audit on systemaudit.dev. If you are raising, selling or buying, the technical due diligence review adds a person's name to it.
Questions
Is the SystemAudit connector free?
Yes. It needs no account and no sign-in. The limits are 3 new scans an hour per person and 10 across everyone; answers served from a recent scan are not counted.
Can it scan a private repository?
No. The connector reads public repositories only and refuses anything else before scanning. Private repositories can be scanned on systemaudit.dev by connecting your GitHub account.
Why doesn't it tell me where an exposed credential is?
The connector's answers stay at counts and severity, so a conversation never carries where a live key sits. The full report on systemaudit.dev shows locations for critical and high findings, as it does for any public repository scan, so they can be found and fixed.
Does it store my code?
No source files are stored. The resulting report is kept, as for any scan on systemaudit.dev, so the link in the answer works. The connector keeps no record of who asked.
How is this different from scanning on the website?
It runs the same deterministic scan and returns a summary inside your conversation, with a link to the full report. Paid analysis, private repositories and credential locations are only on systemaudit.dev.