ToolCabana

Agent tools / Dependency and security inspection

Scan a supplied code diff for configured risks

Flag credential patterns and risky code constructs.

Status: implemented. Runtime: browser-or-local. Version: 1.0.0.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Supported profile

This tool accepts the schema below. Its result includes data and versioned runtime metadata. Read warnings in returned data for algorithm coverage and assumptions.

Input schema
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
Output schema
{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "type": "object",
  "properties": {
    "data": {
      "type": "object",
      "properties": {
        "findings": {
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "start": {
                "type": "integer",
                "minimum": 0,
                "maximum": 9007199254740991
              },
              "end": {
                "type": "integer",
                "minimum": 0,
                "maximum": 9007199254740991
              },
              "type": {
                "type": "string",
                "maxLength": 200000
              }
            },
            "required": [
              "start",
              "end",
              "type"
            ],
            "additionalProperties": false,
            "maxProperties": 2000
          },
          "maxItems": 2000
        },
        "warning": {
          "type": "string",
          "maxLength": 200000
        }
      },
      "required": [
        "findings",
        "warning"
      ],
      "additionalProperties": false,
      "maxProperties": 2000
    },
    "metadata": {
      "type": "object",
      "properties": {
        "tool": {
          "const": "security.diff_scan"
        },
        "version": {
          "const": "1.0.0"
        },
        "runtime": {
          "type": "string",
          "enum": [
            "local",
            "browser",
            "server"
          ]
        },
        "elapsedMs": {
          "type": "integer",
          "minimum": 0,
          "maximum": 9007199254740991
        },
        "retained": {
          "const": false
        }
      },
      "required": [
        "tool",
        "version",
        "runtime",
        "retained"
      ],
      "additionalProperties": false,
      "maxProperties": 2000
    }
  },
  "required": [
    "data",
    "metadata"
  ],
  "additionalProperties": false,
  "$defs": {
    "json": {
      "anyOf": [
        {
          "type": "null"
        },
        {
          "type": "boolean"
        },
        {
          "type": "number"
        },
        {
          "type": "string",
          "maxLength": 200000
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/json"
          },
          "maxItems": 2000
        },
        {
          "type": "object",
          "maxProperties": 2000,
          "additionalProperties": {
            "$ref": "#/$defs/json"
          }
        }
      ]
    }
  }
}

Example arguments

{
  "text": "+password=abcdefghijk"
}

Local MCP tool name: security__diff_scan. Browser and local execution work without a key.

Hosted REST and MCP execution are disabled in this release. Run the example in the browser console below, or use the local MCP server from this repository.

Privacy and limits

256 KiB arguments, 512 KiB output, 20 nesting levels and 2,000 array entries. No input/output logging in this layer. Browser/local utilities do not submit inputs remotely. Optional network operations disclose destination requests. Caller-supplied policies and guardrail findings never grant execution privileges.

136 matching tools

Scan a supplied code diff for configured risks

Flag credential patterns and risky code constructs.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Contract and limitations

Result

Run a tool to see its structured result.

Let a browser agent use this console

Enable WebMCP when your browser supports it. Inputs run locally and results remain visible here.

Full integration guide