GoThreatScope

by anotherik

Not rated
GitHub

About

Go-based SBOM, vulnerability, and secret scanner with MCP support.

Details

Author
anotherik
Categories
Developer Tools, Security, Infrastructure

Setup

Install GoThreatScope in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/anotherik/gothreatscope

Follow the installation instructions in the repository README, then restart your MCP client.

GoThreatScopeis a modular, educational security toolchain written in Go.
It generates a lightweight SBOM, checks dependencies againstosv.devfor vulnerabilities and known malicious packages, scans for hardcoded secrets (usingGitleakswhen available, or a builtin fallback), and records metrics for each run (usingpipedream).

This tool also acts as aModel Context Protocol (MCP)server, allowing IDEs such asCursororVisual Studio Codeto query its results using natural language.
For example, you can ask:

"Analyze my project and show me which dependencies look risky."

The MCP interface exposes tools and resources so other systems or LLMs can retrieve structured SBOMs, vulnerability reports, and secret findings directly from the local filesystem.

GoThreatScope performs an high-level security inspection of a project directory and organizes the results for both human and automated analysis.

It combines several capabilities into a single workflow:

- SBOM generation: creates a simple inventory of project dependencies.
- Vulnerability and malware detection: checks each dependency against
osv.devto identify known vulnerabilities and malicious packages.
- Secrets detection: searches for API keys, passwords, and private tokens using
Gitleaksor a simple builtin fallback scanner.
- Metrics collection: stores structured metrics for every run, allowing comparison between scans (configured with
pipedream).

Each module works independently or as part of theanalyzepipeline.
All results are stored locally undergothreatscope_store/and reused when no changes are detected.

GoThreatScope is organized into clear, modular packages.
Each package handles a specific security function or integration point, making the tool easy to extend or reuse in other projects.

GoThreatScope │ ├── cmd/gothreatscope/ # CLI entrypoint and MCP server mode │ └── main.go # CLI commands and MCP wiring │ ├── pkg/ │ ├── sbom/ # SBOM generation logic │ ├── vuln/ # OSV-based vulnerability and malware detection │ ├── secrets/ # Gitleaks and builtin secret scanner │ ├── analysis/ # Full pipeline and storage/diff logic │ ├── metrics/ # Local and remote metrics sender │ └── mcp/ # MCP tools and resources implementation │ └── gothreatscope_store/ # Automatically generated per-project store └── <project_id>/ ├── latest/ │ ├── sbom.json │ ├── vuln.json │ ├── secrets.json │ ├── metrics.json │ └── bundle.json └── history/<run_id>/

Each project scanned by GoThreatScope receives its own identifier, derived from the SHA-256 hash of its absolute path. All results are written into that project’s folder under gothreatscope_store/, and new files are only created when differences are detected compared to the previous run.

GoThreatScope operates through independent modules that can run individually or together as part of a complete analysis pipeline.

Every scanned project is assigned a unique identifier derived from the SHA-256 hash of its absolute path.
This ensures consistent tracking across runs without revealing directory names.

Scan results are stored under thegothreatscope_store/directory, grouped by project ID.
Each module writes its own JSON artifact inside alatest/folder, and keeps a short history of past results.

gothreatscope_store/ └── a93bf44e3e9c/ ├── latest/ │ ├── sbom.json │ ├── vuln.json │ ├── secrets.json │ └── metrics.json └── history/20251007T215959Z/

Before saving, GoThreatScope compares digests (hashes) of the new results with those from the previous run. If there are no changes, the stored files remain untouched, avoiding redundant writes and unnecessary history entries.

Each scan produces ametrics.jsonfile summarizing timing, findings, and environment details. Metrics are always stored locally and can optionally be sent to a remote endpoint defined by theGOTHREATSCOPE_METRICS_URLvariable.

When running in--mcpmode, GoThreatScope exposes its analysis capabilities as tools that can be invoked directly by LLMs or IDEs. Results are returned as structured JSON withfile://URIs pointing to saved artifacts, allowing the calling system to read or display them without rerunning scans.

- Go 1.21 or newer
- (Optional)
Gitleaks v8+for extended secret detection

go install github.com/anotherik/gothreatscope/cmd/gothreatscope@latest

After installation, the binary gothreatscope will be available in your $GOBIN path.

# Navigate to the project directory cd /path/to/GoThreatScope # Build the binary go build -o ./bin/gothreatscope ./cmd/gothreatscope # Make it executable chmod +x ./bin/gothreatscope

You can run GoThreatScope in a container using the providedDockerfile.

Build image metadata from your local Git state:

# Docker docker build -t gothreatscope:latest \ --build-arg VERSION=0.0.0 \ --build-arg COMMIT=$(git rev-parse --short HEAD) \ --build-arg DATE=$(date -u +%Y-%m-%dT%H:%M:%SZ) . # Podman podman build -t gothreatscope:latest \ --build-arg VERSION=0.0.0 \ --build-arg COMMIT=$(git rev-parse --short HEAD) \ --build-arg DATE=$(date -u +%Y-%m-%dT%H:%M:%SZ) .

Run a full analysis against the current repository:

# Docker docker run --rm -v "$PWD":/workspace gothreatscope:latest analyze --path /workspace # Podman podman run --rm -v "$PWD":/workspace gothreatscope:latest analyze --path /workspace
# Docker docker run --rm -i -v "$PWD":/workspace gothreatscope:latest --mcp # Podman podman run --rm -i -v "$PWD":/workspace gothreatscope:latest --mcp

The runtime image includes HTTPS CA certificates and runs as a non-root user. Ifgitleaksis not present in the container, GoThreatScope automatically uses the builtin secret scanner.

IfGitleaksis not installed, GoThreatScope automatically uses its internal secret-scanning engine.

GoThreatScope can be used directly from the command line to perform individual scans or run the full analysis pipeline.

# Generate a Software Bill of Materials (SBOM) gothreatscope sbom --path ./project # Check dependencies for vulnerabilities and malicious packages gothreatscope vuln --path ./project # Scan for hardcoded secrets gothreatscope secrets --path ./project [--engine auto|gitleaks|builtin] # Run the complete pipeline (SBOM + Vulnerabilities + Secrets) gothreatscope analyze --path ./project # Display version and global help gothreatscope --version gothreatscope --help

Each command stores its results undergothreatscope_store/<project_id>/latest/and updates them only if new findings are detected. This makes it easy to keep long-term records of project scans without unnecessary reprocessing.

GoThreatScope can also run as aModel Context Protocol (MCP)server, allowing IDEs or LLMs to interact with its analysis results through structured JSON responses.

The Model Context Protocol (MCP) is a standard that allows AI assistants to securely connect to data sources and tools. GoThreatScope implements an MCP server that exposes security analysis tools to IDEs like Cursor.

When running in MCP mode, GoThreatScope exposes several tools and resources that can be invoked programmatically or through compatible editors such as Cursor or VS Code (with MCP support).

GoThreatScope exposes the following tools via theModel Context Protocol (MCP).
These tools are automatically registered and described in
tools.json.

Once a scan is completed, GoThreatScope also exposesresourcesthat can be accessed by compatible MCP clients (e.g., Cursor, VS Code). These resources allow the MCP clients to fetch structured analysis outputs like:

- SBOMs— stored assbom.json
- Vulnerability reports— stored asvuln.json
- Secrets findings— stored assecrets.json
- Metrics— stored asmetrics.json

Resources are automatically listed through the MCP protocol methods:

- resources/listlists all stored artifacts across scanned projects.
- resources/readretrieves the content of a specific file via afile://URI (e.g., local artifact path).

{ "uri": "file:///home/user/gothreatscope_store/a93bf44e3e9c/latest/vuln.json", "changed": true, "counts": { "vulns": 5 }, "note": "Vulnerability report updated (change detected)" }

Using these endpoints, IDEs or connected LLMs can request analysis results, open the corresponding JSON artifacts, or cross-reference findings without rerunning the scans.

GoThreatScope can be used directly insideCursoror any IDE that supports theModel Context Protocol (MCP).

Once installed, configure Cursor to recognize GoThreatScope as an MCP server:

Option A: Global ConfigurationAdd to your Cursor settings (File → Preferences → Settings → Extensions → MCP):

{ "mcpServers": { "gothreatscope": { "command": "/absolute/path/to/gothreatscope", "args": ["--mcp"], "env": { "GTS_MCP_MODE": "1" } } } }

Option B: Workspace ConfigurationCreate a.cursor/mcp.jsonfile in your workspace root:

{ "mcpServers": { "gothreatscope": { "command": "./gothreatscope", "args": ["--mcp"], "env": { "GTS_MCP_MODE": "1" } } } }

After restarting Cursor, you can interact with GoThreatScope using natural language prompts.
For example:
- Open a repositoryin Cursor
- Use the chat interfaceto request security analysis:

- "GoThreatScope, analyze my current project and show me if any dependencies look risky or contain secrets."
- "Analyze this repository for security issues"
- "Generate an SBOM for this project"
- "Check for vulnerabilities in dependencies"
- "Scan for secrets in this codebase"

Cursor will automatically call the MCP tools (analyzeRepo,scanRepoSBOM,vulnCheck,secretScan), read the stored JSON artifacts, and reason over the SBOM, vulnerabilities, and secrets results to provide an AI-driven assessment.

For debug purposes, here you can find some examples to test the MCP server.

`echo '{"id":2,"jsonrpc":"2.0","method":"ping"}' | gothreatscope --mcp

- All at once (or copy the one you want to test):

printf '%s\n' \ '{"id":1,"jsonrpc":"2.0","method":"initialize"}' \ '{"id":2,"jsonrpc":"2.0","method":"ping"}' \ '{"id":3,"jsonrpc":"2.0","method":"tools/list"}' \ '{"id":4,"jsonrpc":"2.0","method":"tools/call","params":{"name":"scanRepoSBOM","arguments":{"path":"."}}}' \ '{"id":5,"jsonrpc":"2.0","method":"tools/call","params":{"name":"vulnCheck","arguments":{"path":"."}}}' \ '{"id":6,"jsonrpc":"2.0","method":"tools/call","params":{"name":"secretScan","arguments":{"path":".","engine":"auto"}}}' \ '{"id":7,"jsonrpc":"2.0","method":"tools/call","params":{"name":"analyzeRepo","arguments":{"path":"."}}}' \ '{"id":8,"jsonrpc":"2.0","method":"resources/list"}' \ | gothreatscope --mcp`

Created byanotherik
Released for educational and research use under theApache-2.0 License.

GoThreatScope is an open, educational project that aims to demonstrate best practices in secure software analysis and model-integrated scanning.
Contributions, feedback, and research collaborations are always welcome.

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.

Enable AI agents to secure code with Semgrep.

An engineering governance and safety control plane for AI coding agents to enforce strict SDLC discipline, quality gates, and security branch protections.

AI-powered security scanning. Scans code, files, and git diffs for vulnerabilities in real-time using the Armis scanning API.

MCP server that vets LLM-emitted shell commands BEFORE execution. 30 detection rules across destructive file ops, package managers, system, database, git, network, exfiltration, privilege escalation. Sub-second, local, free.

Give your coding agent the dependency graph it is about to change: scan a source tree, SBOM, Git ref, or container image; explain why a package is present; diff two graphs; check findings against policy.

BoostSecurity MCP acts as a safeguard preventing agents from adding vulnerable packages into projects. It analyzes every package an AI agent introduces, flags unsafe dependencies, and recommends secure, maintained alternatives to keep projects protected.

A secure MCP server for executing controlled command-line operations with comprehensive security features.

Access the Codacy API to analyze code quality, coverage, and security for your repositories.

Execute pre-approved shell commands securely on a server.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.