Skip to main content
Glama

🛡️ Scan Your AI Toolkit

Open-source AI governance tools. Each works standalone as an MCP server or CLI — together they form a governance mesh.

scan_your_ai_toolkit MCP server scan_your_ai_toolkit MCP server

CI CodeQL npm scope License MCP Conformance PRs Welcome

Built by Maiife — Enterprise AI Control Plane.

Tools

Package

Description

Published

@maiife-ai-pub/shared

Shared types and formatters used by all toolkit packages

@maiife-ai-pub/probe

AI environment scanner — discover IDE extensions, MCP servers, agent frameworks, API keys, local models

@maiife-ai-pub/mcp-audit

MCP server security scanner — score configs on permissions, data sensitivity, blast radius

@maiife-ai-pub/ai-stack

"What's Your AI Stack?" — shareable profile card of your AI toolkit

@maiife-ai-pub/mcp-doctor

MCP health check & auto-fixer — brew doctor for your MCP setup

@maiife-ai-pub/ai-journal

Personal AI usage diary — track how you use AI, get reflective insights

@maiife-ai-pub/context-sync

Cross-tool AI memory sync — one context.json, synced to Cursor, Claude, MCP

@maiife-ai-pub/prompt-score

Prompt quality analyzer — score, improve, and lint your AI prompts

@maiife-ai-pub/eval

LLM-as-judge evaluation engine — score agent outputs with structured rubrics

@maiife-ai-pub/trace

Agent workflow tracer — trace, view, and analyze execution spans

@maiife-ai-pub/cost

AI spend calculator + optimizer — unified cost report across vendors

@maiife-ai-pub/prompt-craft

Gamified prompt coach — levels, streaks, badges for prompt improvement

@maiife-ai-pub/sub-audit

Personal AI subscription auditor — find waste in your AI spending

@maiife-ai-pub/model-match

Personal model recommender — find the best model for YOUR tasks

@maiife-ai-pub/weekly-ai-report

AI week in review — Spotify Wrapped for your AI usage, weekly

Related MCP server: Mund

Quick Start

# Scan your AI environment
npx @maiife-ai-pub/probe scan

# Audit your MCP server security
npx @maiife-ai-pub/mcp-audit scan

# Generate your AI Stack profile card
npx @maiife-ai-pub/ai-stack --format svg --output my-stack.svg

# Health check your MCP servers
npx @maiife-ai-pub/mcp-doctor check

# Log an AI interaction
npx @maiife-ai-pub/ai-journal log --tool claude --task coding --duration 30

# Sync AI context across tools
npx @maiife-ai-pub/context-sync push

# Score your AI prompts
npx @maiife-ai-pub/prompt-score analyze --input prompt.txt

# Evaluate agent outputs with rubrics
npx @maiife-ai-pub/eval score --rubric code-review --input review.txt

# Trace agent workflows
npx @maiife-ai-pub/trace list --days 7

# Track AI spend across vendors
npx @maiife-ai-pub/cost report --period last-30d

# Gamified prompt coaching
npx @maiife-ai-pub/prompt-craft score --input prompt.txt

# Audit AI subscriptions for waste
npx @maiife-ai-pub/sub-audit

# Find the best model for your tasks
npx @maiife-ai-pub/model-match recommend --task coding

# Generate your AI week in review
npx @maiife-ai-pub/weekly-ai-report generate

Use as MCP Server

Every tool with an MCP server can be added to Claude Desktop, Cursor, or any MCP-compatible client. Each exposes tools over stdio transport.

~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "maiife-probe": {
      "command": "npx",
      "args": ["@maiife-ai-pub/probe", "mcp"]
    },
    "maiife-mcp-audit": {
      "command": "npx",
      "args": ["@maiife-ai-pub/mcp-audit", "mcp"]
    },
    "maiife-mcp-doctor": {
      "command": "npx",
      "args": ["@maiife-ai-pub/mcp-doctor", "mcp"]
    },
    "maiife-eval": {
      "command": "npx",
      "args": ["@maiife-ai-pub/eval", "mcp"]
    },
    "maiife-prompt-score": {
      "command": "npx",
      "args": ["@maiife-ai-pub/prompt-score", "mcp"]
    },
    "maiife-prompt-craft": {
      "command": "npx",
      "args": ["@maiife-ai-pub/prompt-craft", "mcp"]
    },
    "maiife-cost": {
      "command": "npx",
      "args": ["@maiife-ai-pub/cost", "mcp"]
    },
    "maiife-model-match": {
      "command": "npx",
      "args": ["@maiife-ai-pub/model-match", "mcp"]
    },
    "maiife-ai-stack": {
      "command": "npx",
      "args": ["@maiife-ai-pub/ai-stack", "mcp"]
    },
    "maiife-context-sync": {
      "command": "npx",
      "args": ["@maiife-ai-pub/context-sync", "mcp"]
    },
    "maiife-sub-audit": {
      "command": "npx",
      "args": ["@maiife-ai-pub/sub-audit", "mcp"]
    },
    "maiife-trace": {
      "command": "npx",
      "args": ["@maiife-ai-pub/trace", "mcp"]
    }
  }
}

Pick the tools you need — you don't have to add all of them. Once configured, Claude can call tools like probe_scan, mcp_audit_scan, eval_score, prompt_score_analyze, cost_report, and more directly from chat.

Run with Docker

Each MCP server is published as a Docker image on GHCR. Useful for sandboxed environments or Glama integration.

# Pull and run any server
docker run -i ghcr.io/sakthivelchan89/maiife-probe
docker run -i ghcr.io/sakthivelchan89/maiife-mcp-audit
docker run -i ghcr.io/sakthivelchan89/maiife-eval
# ... same pattern for all 12 packages

# Or build from source
docker build -f packages/probe/Dockerfile -t maiife-probe .
docker run -i maiife-probe

Docker images use stdio transport (no ports exposed). Pass -i for interactive stdin/stdout communication with MCP clients.

Quality & Compliance

This toolkit aims to meet MCP Tier 1 quality standards (per MCP SEP-1730). Here's what that means:

Dimension

Status

License

Apache 2.0 — canonical SPDX, OSI-approved

Transport

stdio only (no network exposure)

CI/CD

GitHub Actions: lint + type-check + tests on Node 18, 20, 22

Test coverage

vitest + @vitest/coverage-v8, reported per-package

MCP conformance

Protocol compliance suite for all 12 MCP servers

Security scanning

CodeQL (weekly + on PR), Dependabot (weekly)

Vulnerability response

48h CRITICAL / 7d HIGH (see DEPENDENCY_POLICY.md)

Issue triage SLA

2 business days (see CONTRIBUTING.md)

Versioning

SemVer, lockstep across packages, CHANGELOG.md

Supply chain

pnpm-lock.yaml committed, --frozen-lockfile in CI

Container security

Non-root user, no exposed ports, GHCR-signed

Conformance test suite

Every MCP server in this repo is validated against the MCP protocol contract:

  • ✅ stdio transport invariant (no non-JSON output on stdout)

  • initialize handshake responds with valid serverInfo + capabilities

  • tools/list returns the documented tool set

  • ✅ All tool inputSchema fields are valid JSON Schema objects

  • ✅ Unknown tool calls return structured errors (not crashes)

Run the suite:

pnpm test:conformance      # all packages
cd packages/probe && pnpm test:conformance   # single package

Documentation

Contributing

Contributions are welcome! Read CONTRIBUTING.md for the full guide. Quick version:

  1. Fork the repo on GitHub

  2. Create a branch: git checkout -b feat/my-improvement

  3. Make your changes — each package lives in packages/<name>/

  4. Run tests: pnpm test && pnpm test:conformance

  5. Open a PR against main — describe what you changed and why

Please follow the existing code style (TypeScript, ESM, Vitest for tests). Each package should work as both a CLI and an MCP server where applicable.

License

Apache 2.0 — free to use, modify, and distribute.


Part of the Maiife platform — Enterprise AI Control Plane.

Available Tools

1 tool
probe_scanA

Scan the current environment for AI tools, MCP servers, agent frameworks, API keys, and local models

ParametersJSON Schema
NameRequiredDescriptionDefault
pathNoRoot path to scan (defaults to current directory)
scopeNoScan scope: full=everything, quick=IDE+MCP only, category=specificfull
categoriesNoComma-separated categories: ide,mcp,agents,keys,models,deps
includeProjectDepsNoScan package.json/requirements.txt for AI dependencies

TDQS

A3.6/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must disclose behavioral traits. The word 'Scan' suggests a read operation, but there is no mention of side effects, permissions, safety, or potential impact on the environment. For a tool that scans files and possibly accesses sensitive data (API keys), this is a significant omission.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence that front-loads the action and key details. Every word contributes to understanding the tool's purpose, with no filler or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema and 4 optional parameters, the description fails to cover what the tool returns (e.g., a list of found items, JSON output). The agent lacks information on how to interpret results, which is critical for a scanning tool. Additionally, it does not explain the behavior of different scopes or categories beyond what the schema provides.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description does not add any additional meaning beyond the schema; it simply restates the categories listed in the 'categories' parameter description. No deeper semantics are provided.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('Scan') and the specific resources ('AI tools, MCP servers, agent frameworks, API keys, local models'), making it easy for an AI agent to understand the tool's purpose. No sibling tools exist, so differentiation is not required.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

While there are no sibling tools to compare against, the description implies the tool is for enumeration and discovery, which is sufficient. However, it lacks explicit guidance on when to use it (e.g., initial reconnaissance vs. targeted search), leaving some ambiguity.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool update
    • Addedprobe_scan
  2. 1 tool update
    • Removedprobe_scan
  3. 1 tool updatev0.1.3
    • First observedprobe_scan

TDQS

A3.6/5.0
Disambiguation5/5

Only one tool exists, so there is no possibility of ambiguity.

Naming Consistency5/5

With a single tool, naming consistency is not applicable; the name 'probe_scan' is clear and descriptive.

Tool Count2/5

One tool is too few for a toolkit; it feels thin and does not provide a meaningful set of capabilities.

Completeness2/5

The single scan tool likely misses complementary operations like listing previous scans, filtering, or exporting results, leaving the surface incomplete.

Maintenance

ActivityInactive
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/sakthivelchan89/scan_your_ai_toolkit'

If you have feedback or need assistance with the MCP directory API, please join our Discord server