ZipLoom
Home
PricingSign inGet Your Live URL

own

MCP Server For Coding Agents

Ask your coding agent whether it's safe to ship — and get a real answer.

What you get

The scanner, inside the editor

Your agent can start a ZipLoom scan of the commit it just wrote, wait for it, and read the findings — title, severity, file, line and fix — without you leaving the editor or pasting anything.

One endpoint, every major agent

The leading coding agents and editors connect natively over Streamable HTTP; anything else connects through mcp-remote. Copy-paste setup for each is on the MCP page and in Settings → API Keys.

Read-only GitHub tools, fenced to your repos

35 read-only tools from the Agent Ops registry — files, pull requests, workflow runs, security advisories — run under the key creator's GitHub access and only against repositories your organization has connected. Nothing over MCP writes to GitHub.

How it connects

  1. 1

    Create an IDE Agent key in Settings → API Keys (Owner or Admin). It is shown once and stored hashed.

  2. 2

    Paste the setup snippet for your agent — it reads the key from an environment variable or a secret prompt, never from the file.

  3. 3

    Your agent lists your projects, scans one, and reads findings, attack chains, deploy status and live posture.

  4. 4

    Agent scans reuse an in-flight scan and are capped per hour, so a looping agent can't burn your CI quota.

What this check inspects

  • The same code, secrets, dependency and workflow scan your deploys and pull requests get — one source of truth, three entry points.

  • Deploy status with each gate's verdict — passed, blocked, advisory or error — so an agent never reads a failed-open gate as a pass.

  • Live posture of the deployed URL, so the agent can check the running app, not just the code.

What it means when this fails

Without it, the agent that wrote the code is the only reviewer it gets before you merge. It will tell you the change looks fine, because it cannot see what a scanner sees — and the first independent check happens after the code is already live.

Questions

Can the agent change my repository or deploy through MCP?
No. Everything exposed over MCP is read-only apart from starting a scan. Write tools are not listed and are refused if called.
Is a CI key enough?
No — CI keys are scan-only and deliberately cannot reach the MCP endpoint. Create an IDE Agent key for agents.
Does the agent see how detection works?
No. It gets what is wrong, where and how to fix it. Detection internals never enter an agent's context, so they can't be talked out of it.

Related features