AI Security Harness: SAST, secrets, deps, containers, config & OWASP LLM. Scans locally.
Security scanning for the code Copilot writes: SAST, secrets, dependencies (SCA/SBOM), containers and configuration, including AI-specific risks like prompt injection and the OWASP LLM Top 10 — 3,000+ rules, scanned on your machine. Gadriel plugs into Copilot as an MCP server plus repository instructions, prompts, and reviewer agents.
Part of the Gadriel AI Security Harness, alongside VS Code, Claude Code, Codex, and Cursor.
Easiest — the VS Code extension. Install
Gadriel AI Security Harness
from the Marketplace. It registers the gadriel MCP server for Copilot
automatically and adds a Gadriel: Scan Repository command — no config to
edit.
Or add the MCP server yourself. The server is published to the
GitHub MCP Registry as
io.github.Gadriel-ai/gadriel, so it shows up in VS Code's MCP: Browse
Servers and Copilot Chat's @mcp search — add it in a click. To wire it
per-repo instead, drop this .vscode/mcp.json into your project (needs Node for
npx, or npm install -g gadriel):
{ "servers": { "gadriel": { "type": "stdio", "command": "npx", "args": ["-y", "gadriel@1.5.0", "code", "mcp"] } } }
Add the Copilot guidance (optional). Copy the .github/ directory into your
repo so Copilot knows how to use Gadriel:
| Path | What |
|---|---|
.github/copilot-instructions.md | repo-wide guidance, auto-applied |
.github/instructions/*.instructions.md | 17 topic rules, scoped by applyTo |
.github/prompts/*.prompt.md | /gadriel-scan, /gadriel-fix, /gadriel-status, … |
.github/agents/*.agent.md | 8 reviewer agents |
In Copilot Chat (agent mode), just ask: "Run a Gadriel security scan on this
repo and summarize the findings," or invoke a prompt like /gadriel-scan. The
gadriel MCP tools — validate_file, findings_for_path, fix_finding,
validate_buffer, and more — are available to Copilot directly.
gadriel MCP
server through managed MCP policy.app.gadriel.ai (a random device id — no
hostname, username, or keys); set GADRIEL_NO_ANONYMOUS_AUTH=1 to skip. See
the privacy policy.The registry listing is (re)published by .github/workflows/publish-mcp.yml
(GitHub OIDC — an org namespace can only be published from CI in a Gadriel-ai
repo). After a new gadriel npm release, bump server.json and the
.vscode/mcp.json pin, then re-run that workflow.
This repository is Apache-2.0. The gadriel scanner it runs is
proprietary, under the Gadriel terms.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y gadrielMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-gadriel-ai-gadriel": {
"command": "npx",
"args": [
"-y",
"gadriel"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceGadriel AI Security Harness works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.