Gadriel — AI Security Harness for GitHub Copilot

MCP serverSecurity

AI Security Harness: SAST, secrets, deps, containers, config & OWASP LLM. Scans locally.

Unavailable. This server has no hosted endpoint yet, so ahel can't serve it.

Connect ahel once, and every AI you use reads what you have installed.

From the project's README

As published by gadriel-ai/gadriel-copilot-plugin in README.md.

Security scanning for the code Copilot writes: SAST, secrets, dependencies (SCA/SBOM), containers and configuration, including AI-specific risks like prompt injection and the OWASP LLM Top 10 — 3,000+ rules, scanned on your machine. Gadriel plugs into Copilot as an MCP server plus repository instructions, prompts, and reviewer agents.

Part of the Gadriel AI Security Harness, alongside VS Code, Claude Code, Codex, and Cursor.

Get it

Easiest — the VS Code extension. Install Gadriel AI Security Harness from the Marketplace. It registers the gadriel MCP server for Copilot automatically and adds a Gadriel: Scan Repository command — no config to edit.

Or add the MCP server yourself. The server is published to the GitHub MCP Registry as io.github.Gadriel-ai/gadriel, so it shows up in VS Code's MCP: Browse Servers and Copilot Chat's @mcp search — add it in a click. To wire it per-repo instead, drop this .vscode/mcp.json into your project (needs Node for npx, or npm install -g gadriel):

{ "servers": { "gadriel": { "type": "stdio", "command": "npx", "args": ["-y", "gadriel@1.4.1", "code", "mcp"] } } }

Add the Copilot guidance (optional). Copy the .github/ directory into your repo so Copilot knows how to use Gadriel:

PathWhat
.github/copilot-instructions.mdrepo-wide guidance, auto-applied
.github/instructions/*.instructions.md17 topic rules, scoped by applyTo
.github/prompts/*.prompt.md/gadriel-scan, /gadriel-fix, /gadriel-status, …
.github/agents/*.agent.md8 reviewer agents

Use

In Copilot Chat (agent mode), just ask: "Run a Gadriel security scan on this repo and summarize the findings," or invoke a prompt like /gadriel-scan. The gadriel MCP tools — validate_file, findings_for_path, fix_finding, validate_buffer, and more — are available to Copilot directly.

Good to know

  • No automatic edit guardrail here. Copilot/VS Code has no edit-time hook (Cursor and Codex do), so scanning runs on request via the MCP tools and prompts rather than blocking each edit.
  • Enterprise: Copilot Business/Enterprise can allowlist the gadriel MCP server through managed MCP policy.
  • Privacy: code is scanned locally and never uploaded. First run registers an anonymous device credential with app.gadriel.ai (a random device id — no hostname, username, or keys); set GADRIEL_NO_ANONYMOUS_AUTH=1 to skip. See the privacy policy.

Maintainers

The registry listing is (re)published by .github/workflows/publish-mcp.yml (GitHub OIDC — an org namespace can only be published from CI in a Gadriel-ai repo). After a new gadriel npm release, bump server.json and the .vscode/mcp.json pin, then re-run that workflow.

License

This repository is Apache-2.0. The gadriel scanner it runs is proprietary, under the Gadriel terms.

Signals

Last commit
Sep 2026
Weekly downloads
154
Advanced
Delivery
gadriel MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
Catalog kind
mcp-server
Gateway key
io-github-gadriel-ai-gadriel
Source
github.com/gadriel-ai/gadriel-copilot-plugin