PluginBench
MCP Server
Maintained
MIT

io.github.mythos-agent/mythos-agent MCP Server

io.github.mythos-agent/mythos-agent

AI code-review assistant that hunts security issues via hypothesis-driven scanning, variant analysis, and multi-stage verification.

What is the io.github.mythos-agent/mythos-agent MCP server?

mythos-agent is an open-source AI security agent that reviews code for application security vulnerabilities using SAST, DAST, and policy-as-code over MCP. It combines hypothesis-driven scanning, variant analysis of known CVEs, and multi-stage verification to identify and explain security issues with suggested fixes.

mythos-agent automates security code review by reasoning about what could go wrong in your codebase, finding variants of known CVEs, and verifying findings through pattern scanning, AI analysis, and dynamic testing. It integrates 15+ wired scanners covering SQL injection, XSS, secrets, dependencies, IaC, JWT, session management, business logic, and more—plus external tools like Semgrep, Gitleaks, Trivy, and Nuclei. Use it to scan code, hunt for security hypotheses, analyze CVE variants, generate PoCs, and enforce compliance policies.

How to install io.github.mythos-agent/mythos-agent

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mythos-agent": {
      "command": "npx",
      "args": [
        "-y",
        "mythos-agent",
        "mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • hunt — Full autonomous multi-agent scan combining reconnaissance, hypothesis generation, analysis, and exploitation stages
  • scan — Standard security scan with pattern matching, secrets detection, dependency checking, IaC analysis, and AI verification
  • variants — Find structurally similar code in your codebase that shares the root cause of known CVEs
  • ask — Natural language security queries to investigate specific security concerns
  • fix — AI-generated security patches with optional automatic application
  • taint — AI-powered data flow and taint analysis
  • watch — Continuous monitoring that scans code on file save
  • dashboard — Local web UI with findings visualization, charts, and results table
  • report — Export findings in terminal, JSON, HTML, or SARIF format
  • policy — Policy-as-code engine for SOC2, HIPAA, PCI-DSS, and OWASP compliance mapping
  • rules — Community rule pack registry for searching, installing, and publishing custom rules
  • tools — Check which external security tools are installed and available

Use cases

  • Scan codebases for SQL injection, XSS, command injection, SSRF, and other OWASP Top 10 vulnerabilities
  • Find variants of known CVEs (e.g., Log4Shell) in your code that share the same root cause but different syntax
  • Generate proof-of-concept exploits and vulnerability chains to validate security findings
  • Enforce compliance policies (SOC2, HIPAA, PCI-DSS) and security standards across your codebase
  • Integrate security scanning into CI/CD pipelines via GitHub Actions and get inline PR review comments

io.github.mythos-agent/mythos-agent MCP server FAQ

What is mythos-agent?

mythos-agent is an open-source AI code-review assistant that hunts security vulnerabilities using hypothesis-driven scanning, variant analysis of known CVEs, and multi-stage verification. It combines pattern scanning, AI reasoning, and dynamic testing to identify and explain security issues with suggested fixes.

Is mythos-agent free?

Yes, mythos-agent is open-source under the MIT license. Pattern scanning, secrets detection, dependency checks, and IaC analysis work without any API key. AI-powered features (hypothesis generation, variant analysis, PoC generation) require an API key from Anthropic, OpenAI, or compatible providers.

How do I install mythos-agent in Cursor or Claude?

mythos-agent is available as an npm package (`npm install -g mythos-agent`) and exposes its capabilities via MCP (Model Context Protocol). You can configure it as an MCP server in Cursor or Claude to enable AI agents to run security scans, ask security questions, and generate fixes directly within your editor.

What authentication is required?

Pattern scanning, secrets detection, dependency analysis, and IaC checks require no authentication. AI-powered features (hypothesis generation, variant analysis, PoC generation, auto-fix) require an API key from Anthropic Claude, OpenAI, Ollama, LM Studio, or any OpenAI-compatible provider.

What scanners and tools does mythos-agent include?

mythos-agent ships with 15 wired scanners covering SQL injection, XSS, secrets, dependencies (SCA), IaC, JWT, session management, business logic, crypto, privacy/GDPR, race conditions, and more. It integrates external tools like Semgrep, Gitleaks, Trivy, Checkov, and Nuclei, plus AI-powered analyses: call-graph, taint engine, DAST fuzzing, and variant analysis.

Can mythos-agent generate fixes?

Yes. mythos-agent can generate AI-powered security patches via the `fix` command with an optional `--apply` flag to automatically apply patches. It also generates proof-of-concept exploits and vulnerability chains to validate findings.

README (reference)

Source of truth, from the repository.

<p align="center"> <strong>English</strong> · <a href="README.zh-CN.md">简体中文</a> </p> <p align="center"> <img alt="mythos-agent — Cerby the guard puppy" src="assets/cerby-banner.svg" width="640"> </p> <p align="center"> <img alt="mythos-agent — 10-second security check demo" src="assets/demo.gif" width="720"> </p> <p align="center"> <h1 align="center">mythos-agent</h1> <p align="center"><strong>AI code-review assistant for application security.</strong></p> <p align="center"><em>Open-source. Reads your code, flags likely security issues, explains its reasoning, suggests fixes.</em></p> </p> <p align="center"> <a href="https://github.com/mythos-agent/mythos-agent/actions"><img src="https://github.com/mythos-agent/mythos-agent/workflows/CI/badge.svg" alt="CI"></a> <a href="https://www.npmjs.com/package/mythos-agent"><img src="https://img.shields.io/npm/v/mythos-agent" alt="npm"></a> <a href="https://github.com/mythos-agent/mythos-agent/blob/main/LICENSE"><img src="https://img.shields.io/badge/license-MIT-blue" alt="License"></a> <a href="https://mythos-agent.com/discord"><img src="https://img.shields.io/badge/discord-join-5865F2?logo=discord&logoColor=white" alt="Discord"></a> <img src="https://img.shields.io/badge/node-%3E%3D20-green" alt="Node"> <img src="https://img.shields.io/badge/scanners-15_wired-5B2A86" alt="Wired scanners"> <img src="https://img.shields.io/badge/experimental-28-6B7280" alt="Experimental scanners"> <img src="https://img.shields.io/badge/rules-329%2B-FB923C" alt="Rules"> </p> <p align="center"> <strong><a href="https://mythos-agent.com">mythos-agent.com</a></strong> </p> <p align="center"> <a href="#quick-start">Quick Start</a> &bull; <a href="#how-it-works">How It Works</a> &bull; <a href="#commands">Commands</a> &bull; <a href="#hunt-mode">Hunt Mode</a> &bull; <a href="#variant-analysis">Variant Analysis</a> &bull; <a href="#integrations">Integrations</a> &bull; <a href="#contributing">Contributing</a> &bull; <a href="VISION.md">Vision</a> &bull; <a href="ROADMAP.md">Roadmap</a> </p>

mythos-agent reviews your code the way a reviewer on a security-focused team would. It walks through likely issue patterns, checks for variants of known CVEs, ranks findings by confidence, and suggests fixes you can accept or reject. See VISION.md for the full framing.

For new contributors: the active 6-month working plan is in the pinned issue [Roadmap] mythos-agent H1 2026 Goals. Look for 🙋 markers to spot items where help is wanted. New here? See CONTRIBUTING.md for good-first-issue guidance.

For security teams and EU CRA-compliant downstream manufacturers: see SECURITY.md for our vulnerability disclosure SLAs, docs/security/cra-stance.md for our EU CRA role declaration, docs/security/threat-model.md for our public threat model, and RELEASES.md for our versioning, LTS, and EOL policy. OpenSSF Best Practices Badge (Passing) submission targeted June 2026; releases are signed via Sigstore and ship with CycloneDX SBOMs for downstream Manufacturer compliance.

npx mythos-agent hunt
🔐 mythos-agent hunt — AI Code-Review Assistant

✔ Phase 1: Reconnaissance — 12 entry points, express, typescript, postgresql
✔ Phase 2: Hypothesis — 8 security hypotheses generated
✔ Phase 3: Analysis — 15 findings (semgrep, gitleaks, trivy, built-in), 22 false positives dismissed
✔ Phase 4: Reproduction — 2 finding chains, 3 reproductions

🧪 Security Hypotheses

  [HIGH] HYPO-001 — Race condition: concurrent payment requests could double-charge
    src/payments.ts:45 (race-condition)
  [HIGH] HYPO-002 — Auth bypass: JWT token not validated after password change
    src/auth.ts:78 (auth-bypass)

📊 Confidence Summary

  3 confirmed | 8 likely | 4 possible | 22 dismissed

⛓️ FINDING CHAINS

 CRITICAL  SQL Injection → Auth Bypass → Data Exfiltration
  ├── src/api/search.ts:45      — unsanitized input in SQL query
  ├── src/middleware/auth.ts:88  — JWT verification skippable
  └── src/api/export.ts:23      — bulk export has no ACL

🧪 Reproductions

  SPX-0001 — SQL injection in search endpoint
    See repro steps in docs/reproductions/SPX-0001.md

  Trust Score: 2.3/10 — critical issues found

Quick Start

# Install
npm install -g mythos-agent

# Quick scan (no API key needed)
mythos-agent scan

# Full autonomous hunt (needs API key)
mythos-agent init
mythos-agent hunt

# Find variants of known CVEs
mythos-agent variants CVE-2021-44228

# Ask security questions
mythos-agent ask "are there any auth bypasses?"

# Check available tools
mythos-agent tools

How It Works

mythos-agent combines three things no other open-source tool does together:

1. Hypothesis-Driven Scanning

Instead of matching known patterns, the AI reasons about what COULD go wrong, generating hypotheses like "this transaction doesn't lock the row, potential race condition" or "this auth check uses string comparison, potential timing attack."

2. Variant Analysis (Big Sleep technique)

Given a known CVE, mythos-agent finds structurally similar but syntactically different code in your codebase. Same root cause, different location. This is how Google's Big Sleep found 20 real zero-days.

3. Multi-Stage Verification

Every finding goes through a confidence pipeline:

  • Pattern scan → candidate
  • AI hypothesis → theoretical risk confirmed
  • Smart fuzzer → dynamically tested
  • PoC generator → concrete exploit proves it's real

Only findings that survive multiple stages are reported as "confirmed."

Commands

CommandDescription
hunt [path]Full autonomous multi-agent scan (Recon → Hypothesize → Analyze → Exploit)
scan [path]Standard scan (patterns + secrets + deps + IaC + AI)
variants [cve-id]Find variants of known CVEs in your codebase
fix [path]AI-generated patches with --apply
ask [question]Natural language security queries
taint [path]AI data flow / taint analysis
watchContinuous monitoring that scans on file save
dashboardLocal web UI with charts and findings table
report [path]Export as terminal / JSON / HTML / SARIF
policyPolicy-as-code with SOC2/HIPAA/PCI/OWASP compliance
rulesCommunity rule pack registry (search/install/publish)
toolsCheck which external security tools are installed
initSetup wizard (Anthropic, OpenAI, Ollama, LM Studio)

Hunt Mode

mythos-agent hunt runs the full multi-agent pipeline:

┌──────────────┐     ┌──────────────┐     ┌──────────────┐     ┌──────────────┐
│    Recon     │ →   │  Hypothesis  │ →   │   Analyze    │ →   │   Exploit    │
│    Agent     │     │    Agent     │     │    Agent     │     │    Agent     │
├──────────────┤     ├──────────────┤     ├──────────────┤     ├──────────────┤
│ Map entry    │     │ Reason about │     │ All scanners │     │ Chain vulns  │
│ points, auth │     │ what could   │     │ + external   │     │ + generate   │
│ boundaries,  │     │ go wrong per │     │ tools + AI   │     │ PoC exploits │
│ data stores  │     │ function     │     │ verification │     │              │
└──────────────┘     └──────────────┘     └──────────────┘     └──────────────┘

Variant Analysis

Find code in your project that has the same root cause as known CVEs:

# Search for Log4Shell-like patterns
mythos-agent variants CVE-2021-44228

# Auto-detect and scan for variants
mythos-agent variants --auto

The variant analyzer extracts the root cause pattern from the CVE (not the surface syntax) and searches your codebase for structurally similar code.

Scanners (15 wired + 28 experimental, 329+ rules)

The Default scanners run on every mythos-agent scan. Experimental scanners are implemented + unit-tested classes that ship in the tarball but are not yet reachable from any CLI, HTTP, MCP, or agent entry point. They are tracked by KNOWN_EXPERIMENTAL in the wiring-invariant test.

CategoryWhat it findsRulesStatus
Code patternsSQLi, XSS, command injection, eval, SSRF, etc.25+Default
Framework rulesReact, Next.js, Express, Django, Flask, Spring, Go27Default
SecretsAWS, GitHub, Stripe, API keys, DB URLs, private keys + entropy22Default
Dependencies (SCA)Known CVEs via OSV API (10 lockfile formats)OSVDefault
IaCDocker, Terraform, Kubernetes misconfigurations13Default
AI/LLM SecurityPrompt injection, unsafe eval of AI output, cost attacks13Default
API SecurityOWASP API Top 10: BOLA, mass assignment, broken auth12Default
Cloud MisconfigAWS/Azure/GCP: public storage, wildcard IAM, open firewalls14Default
Security HeadersCSP, HSTS, X-Frame-Options, Referrer-Policy8Default
JWTAlgorithm, expiry, storage, revocation, audience9Default
SessionFixation, expiry, cookie flags, localStorage tokens7Default
Business LogicNegative amounts, coupon reuse, inventory races, role escalation6Default
Crypto AuditWeak hashes, ECB mode, hardcoded keys, deprecated TLS11Default
Privacy/GDPRPII handling, consent, data retention (GDPR article mapping)9Default
Race ConditionsTOCTOU, non-atomic ops, double-spend, missing transactions7Default
ReDoSCatastrophic backtracking in regex (nested quantifiers, overlapping alternatives)—Default
Supply ChainTyposquatting, dependency confusion, dangerous install scripts12Experimental
Zero TrustService trust, mTLS, network segmentation, IP-based auth8Experimental
GraphQLIntrospection, depth limit, field auth, batching8Experimental
WebSocketAuth, origin check, message validation, broadcast XSS7Experimental
CORSOrigin reflection, credentials handling, substring bypass7Experimental
OAuth/OIDCMissing state, no PKCE, implicit flow, client secret exposure7Experimental
SSTIJinja2, EJS, Handlebars, Pug, Nunjucks, Twig, Go templates7Experimental
<details> <summary>Additional experimental scanners (21 more, not yet wired into default scan)</summary>

SQL injection deep, XSS deep, NoSQL, command injection, deserialization, path traversal, open redirect, XXE, input validation, clickjacking, DNS rebinding, subdomain enumeration, dep confusion, environment variables, logging, error handling, cache, email, upload, memory safety, permissions.

Each exists as a class under src/scanner/ and has unit tests in src/scanner/__tests__/coverage-scanners.test.ts / new-scanners.test.ts, but is not invoked by any CLI command, HTTP API route, MCP handler, or agent pipeline. See KNOWN_EXPERIMENTAL in the wiring-invariant test for each scanner's deferral reason. Wiring one up follows the pattern of the HeadersScanner / JwtScanner / SessionScanner / BusinessLogicScanner commits on main.

</details>

Beyond the scanners above, mythos-agent ships complementary analyses (not counted in the scanner totals): call-graph + taint engine, DAST smart fuzzer, AI hypothesis agent, variant analysis, and git-history mining.

External tool integrations: Semgrep (30+ languages), Gitleaks (100+ patterns), Trivy (SCA + containers), Checkov (1000+ IaC policies), Nuclei (9000+ DAST templates)

Integrations

PlatformWhat
VS CodeExtension with inline diagnostics + one-click AI fix
GitHub ActionScan on push/PR + SARIF upload to Code Scanning
PR Review BotInline comments on vulnerable lines in pull requests
DashboardLocal web UI at mythos-agent dashboard
SARIFGitHub Code Scanning, VS Code, any SARIF tool
Policy EngineSOC2, HIPAA, PCI-DSS, OWASP compliance mapping

AI Providers

TierProvidersStatus
1 — PrimaryAnthropic (Claude Sonnet / Opus / Haiku)Fully tested. Published catch-rate numbers in docs/benchmarks/external-scores.md are produced with this tier.
2 — Compatible (proxy today, native in stage 2)Anything OpenAI-compatible — OpenAI, Qwen via DashScope/OpenRouter, Gemini, Mistral, vLLM, Ollama, LM Studio, Bedrock, etc.Today: route through any Anthropic-compatible proxy (LiteLLM, OpenRouter, Vercel AI Gateway, Bedrock) by setting baseURL in .mythos.yml or ANTHROPIC_BASE_URL env. Native OpenAI SDK support lands in stage 2.
3 — Local / communityLocal Ollama / LM Studio / vLLMSame code path as Tier 2; called out separately because privacy and cost-of-zero are the use case. Best-effort; agentic tool-use quality depends on local model size.

Pattern scanning, secrets, deps, and IaC work without any API key.

See docs/multi-model.md for the full tier-system policy + the staged rollout (this README is the summary; that doc is the canonical reference).

Comparison

Featuremythos-agentSemgrepSnykCodeQLNuclei
Pattern scanningYesBestYesYesTemplates
Hypothesis scanningYesNoNoNoNo
Variant analysisYesNoNoPartialNo
AI-guided fuzzingYesNoNoNoTemplates
PoC generationYesNoNoNoNo
AI deep analysisYesNoLimitedNoNo
Vuln chainingYesNoNoNoNo
AI auto-fixYesNoFix PRsNoNo
NL queriesYesNoNoNoNo
SecretsYesYesYesNoNo
SCAYesNoBestNoNo
IaCYesNoYesNoTemplates
DASTYesNoNoNoBest
Open sourceYesPartialNoYesYes

This feature table is a capability comparison, not an accuracy claim. For reproducible, third-party-runnable accuracy numbers vs Semgrep CE / Snyk Code / CodeQL on OWASP Benchmark, CyberSecEval 3, Vul4J, and our CVE replay harness, see docs/benchmarks/external-scores.md.

Contributing

See CONTRIBUTING.md for details.

git clone https://github.com/mythos-agent/mythos-agent.git
cd mythos-agent && npm install && npm run build && npm test

Architecture

src/
  agents/         Multi-agent orchestrator + Recon/Hypothesis/Analyzer/Exploit agents
  analysis/       Code parser, call graph, taint engine, variant analyzer, service mapper
  agent/          AI integration, prompts, tools, fix validator
  cli/            44 CLI commands
  dast/           Smart fuzzer, PoC generator, payload library
  policy/         Policy engine + compliance mapping
  report/         Terminal, JSON, HTML, SARIF, dashboard
  rules/          Built-in + custom YAML + community registry
  scanner/        Pattern, secrets, deps, IaC, diff scanners
  store/          Results persistence + incremental cache
  tools/          External tool wrappers (Semgrep, Trivy, etc.)
vscode-extension/ VS Code extension
action/           GitHub Actions
bot/              PR Review Bot

License

MIT

Related MCP servers

Mzizi design system MCP: components, tokens, skills and docs. Free; sign-in only for Fundi.

View repository →

政府統計 (e-Stat) の API を通じて、統計データやメタ情報を取得するためのサービスです。

中小企業庁が公開している公共調達情報を検索するためのサービスです。

国土交通省の不動産情報ライブラリから不動産価格データを取得するためのサービスです。

AI video clipping with ClipMaster (clipmaster.app): clips, exports, scheduling.

0
Python
View repository →

Search, retrieve, compare, and render SVG icons visually for AI agents.

1
Rust
View repository →