Aikido Security
SAST, secrets, and IaC vulnerability scanning for Claude Code powered by the Aikido MCP server.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Aikido Security, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
This plugin connects Claude Code to Aikido Security via its MCP server, enabling static analysis, secrets detection, and infrastructure-as-code vulnerability scanning of the working codebase. The agent can trigger scans and read findings to fix issues before they land. It brings Aikido's consolidated AppSec results into the coding loop.
Key features and capabilities
- SAST code scanning
- Secrets detection
- IaC vulnerability scanning
- Aikido MCP server integration
Use cases
- Catching vulnerabilities during development
- Blocking secrets and IaC misconfigurations