Skip to content

shyshlakov/pci-dss-mcp

MCP Security & Auth

Static analysis MCP server that scans Go payment‑service codebases and maps every detected PCI DSS v4.0.1 violation to its specific requirement ID before the code ships

Go Latest v0.7.1 · 2mo ago Security brief →

Features

  • Runs 12 specialized scanners plus an orchestrator and AI triage engine over Go payment‑service projects
  • Each finding carries a `requirement_id` linked to a concrete PCI DSS v4.0.1 line item
  • Provides detailed taint‑flow detection for HTTP input flowing into log, error, or panic sinks across major Go frameworks and loggers

Recent releases

View all 14 releases →
Review required
v0.7.1 Breaking risk
Auth RCE / SSRF

PCI DSS mapping change for apikey

Review required
v0.7.0 New feature
Auth RBAC Dependencies

HTTP input taint tracking

Config change
v0.6.3 Breaking risk
Breaking upgrade

Mode removal enforces privacy

Config change
v0.6.2 Breaking risk
Breaking upgrade

CycloneDX 1.6 bump

Monitor
v0.5.3 New feature

Native Go fuzz coverage

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
3
Forks
0
Languages
Go Shell Makefile

Install & Platforms

Install via
go docker

Alternative to

Semgrep CodeQL gosec

Beta — feedback welcome: [email protected]