mcp-server-moyan
v1.0.0
Published
MCP server exposing Moyan security audit tools to Claude Desktop, Cursor, Codex
Maintainers
Readme
mcp-server-moyan
MCP (Model Context Protocol) server that exposes Moyan security audit capabilities to any MCP-compatible client — Claude Desktop, Cursor, VS Code with Codex, and more.
Installation
npm install -g mcp-server-moyanPrerequisites
Set your Moyan API key:
export MOYAN_API_KEY="your-api-key"The MCP server reads MOYAN_API_KEY from the environment at startup. If it is missing, the server will fail with a clear error.
Client Configuration
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"moyan": {
"command": "npx",
"args": ["-y", "mcp-server-moyan"],
"env": {
"MOYAN_API_KEY": "your-api-key"
}
}
}
}Cursor / VS Code
In Cursor settings or .cursor/mcp.json:
{
"mcpServers": {
"moyan": {
"command": "npx",
"args": ["-y", "mcp-server-moyan"],
"env": {
"MOYAN_API_KEY": "your-api-key"
}
}
}
}Generic MCP Client (mcp.json)
{
"mcpServers": {
"moyan": {
"command": "npx",
"args": ["-y", "mcp-server-moyan"],
"env": {
"MOYAN_API_KEY": "your-key"
}
}
}
}Available Tool
moyan_audit
Run a security audit on source code using the Moyan Agent-native engine.
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
| code | string | Yes | — | Source code to audit |
| language | string | Yes | — | sql / python / javascript / typescript / java / go / rust / solidity |
| audit_level | string | No | "L1" | L1=quick scan, L2=deep analysis, L3=full audit |
Returns: A JSON object with:
{
"audit_id": "audit_abc123",
"pmi_score": 85,
"severity": "warn",
"violations": [
{
"rule_id": "SQLI-001",
"severity": "high",
"message": "Potential SQL injection detected in query construction",
"line": 12,
"snippet": "SELECT * FROM users WHERE id = ' + userId",
"fix": "Use parameterized queries or an ORM with bound parameters"
}
],
"recommendation": "Replace string concatenation with parameterized queries."
}API Endpoint
All audit requests are sent to:
POST https://sixu-ai.net.cn/api/v1/audit
Authorization: Bearer <MOYAN_API_KEY>
Content-Type: application/jsonLicense
MIT
