Open Innovation AyedontnoSubmitted July 26, 2026

Vulnix — an AI-powered security scanner and defensive advisor MCP server

An MCP app on the Model Context Protocol built by Ayedontno at the Amrita University Coimbatore NitroStack × MCP To The Moon hackathon and deployed on NitroStack.

About this project

Vulnix is an AI-powered, defensive security assistant built to secure web applications and codebases directly from the developer's workspace. Operating as a lightweight, low-friction Model Context Protocol (MCP) server engineered with the "NitroStack TypeScript SDK", Vulnix bridges the gap between static analysis, endpoint monitoring, and AI-assisted remediation. Core Capabilities:- Vulnix exposes granular auditing and remediation tools directly to your AI agents through two primary vectors: 1. Passive Endpoint Audits Instantly probes target server response headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options) to evaluate compliance, identify missing configurations, and map surface-level security flaws. 2. Context-Aware Code Remediation Scans source code for critical security bugs (such as SQL injection vectors, unsafe execution contexts, and hardcoded secrets) and generates drop-in, type-safe, parameterized alternatives. Who is it for? * Software Engineers: Fix code vulnerabilities inside your IDE before checking in code, keeping your development loop unbroken. * AppSec & DevSecOps Teams :Enforce baseline security posture and audit endpoints continuously without writing manual testing pipelines. * Engineering Leaders: Scale secure-by-default practices across distributed teams by leveraging agentic automation. What Makes Vulnix Special ? Traditional application security forces developers to navigate disconnected, heavy scanning dashboards. Vulnix shifts security completely left` by integrating directly with modern AI-native clients and IDEs (such as Claude Desktop, Cursor, and ChatGPT) via the MCP standard. By empowering agentic AI in the development loop, Vulnix doesn't just flag security issues—it enables agents to autonomously audit endpoints, diagnose vulnerabilities, and commit precise, context-aware code patches directly to your workspace. It's security analysis, automated remediation, and code generation, combined into a single protocol.

Open Innovation track

Solve any real-world problem with AI, regardless of industry or domain.

Team Ayedontno

  • Jesan N JLead

  • Magibalan V.S

  • Rahul Ganesh R

  • KARTHIK KS

Frequently asked questions

What does Vulnix — an AI-powered security scanner and defensive advisor MCP server do?
Vulnix is an AI-powered, defensive security assistant built to secure web applications and codebases directly from the developer's workspace. Operating as a lightweight, low-friction Model Context Protocol (MCP) server engineered with the "NitroStack TypeScript SDK", Vulnix bridges the gap between static analysis, endpoint monitoring, and AI-assisted remediation. Core Capabilities:- Vulnix exposes granular auditing and remediation tools directly to your AI agents through two primary vectors: 1. Passive Endpoint Audits Instantly probes target server response headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options) to evaluate compliance, identify missing configurations, and map surface-level security flaws. 2. Context-Aware Code Remediation Scans source code for critical security bugs (such as SQL injection vectors, unsafe execution contexts, and hardcoded secrets) and generates drop-in, type-safe, parameterized alternatives. Who is it for? * Software Engineers: Fix code vulnerabilities inside your IDE before checking in code, keeping your development loop unbroken. * AppSec & DevSecOps Teams :Enforce baseline security posture and audit endpoints continuously without writing manual testing pipelines. * Engineering Leaders: Scale secure-by-default practices across distributed teams by leveraging agentic automation. What Makes Vulnix Special ? Traditional application security forces developers to navigate disconnected, heavy scanning dashboards. Vulnix shifts security completely left` by integrating directly with modern AI-native clients and IDEs (such as Claude Desktop, Cursor, and ChatGPT) via the MCP standard. By empowering agentic AI in the development loop, Vulnix doesn't just flag security issues—it enables agents to autonomously audit endpoints, diagnose vulnerabilities, and commit precise, context-aware code patches directly to your workspace. It's security analysis, automated remediation, and code generation, combined into a single protocol.
Who built Vulnix — an AI-powered security scanner and defensive advisor MCP server?
Vulnix — an AI-powered security scanner and defensive advisor MCP server was built by team Ayedontno at the Amrita University Coimbatore NitroStack × MCP To The Moon hackathon, in the Open Innovation track.
What is an MCP app and how is it built?
An MCP app is an application built on the Model Context Protocol — an open standard that lets AI agents connect to tools, data, and APIs. This project exposes MCP tools and resources that agentic AI systems can call. It was built and deployed on NitroStack, the full-stack platform for shipping MCP apps and servers.