Free, MIT-licensed application security CLI. Rules are embedded in the binary — run it locally, offline.
What's new in v0.7.0
Shield is now an MCP server — shield mcp. The same binary speaks the Model Context Protocol over stdio, so Claude Code, Cursor, Windsurf, Codex, Copilot CLI, Gemini CLI, Qwen Code or any MCP client can use Shield as a native tool: scan a repository, page through findings by priority, read the flagged code with fix guidance, look up a rule, apply a gate and generate an SBOM — all on your machine.
# Claude Code
claude mcp add shield -- shield mcp
# Cursor, Windsurf and other MCP clients (mcp.json)
{ "mcpServers": { "shield": { "command": "shield", "args": ["mcp"] } } }
Tools: shield_scan, shield_findings, shield_finding, shield_rule, shield_gate, shield_sbom.
How it behaves:
- Same engine, rules and offline behaviour as
shield scan. Source never leaves the machine; only a scan withdeps=trueuses the network (OSV.dev, FIRST EPSS, CISA KEV), exactly likeshield scan --deps. - Scan results stay in memory for the server session (last 8 scans), so the agent scans once and asks follow-up questions. Each finding has a per-scan id and a stable
fingerprint(the same value SARIF and--baselineuse) so an agent can tell what it fixed after a rescan. - Outputs are bounded (pages of at most 200 findings or components, clipped snippets, paths and titles) and credential values in secret findings are masked before they reach the agent.
- One scan at a time, a scan timeout (
--scan-timeout, default 10m), and--root DIRto confine scans to one directory tree. System roots are refused.
Hardening that also applies to shield scan: a malformed .shieldignore line (invalid UTF-8, over-long) is now skipped and counted instead of aborting the scan; --exclude accepts at most 64 patterns of at most 512 bytes.
Accuracy is unchanged: OWASP Benchmark v1.2 score +0.582 (precision 92.5%, recall 63.7%, FPR 5.5%, 2,740 cases), re-scored on this release's shield-linux-amd64 binary.
Install
# macOS / Linux
curl -sSL https://zennoxa.com/install | sh
# macOS / Linux (Homebrew)
brew install zennoxa/tap/shield
# direct download — replace OS/ARCH: linux-amd64 · linux-arm64 · darwin-amd64 · darwin-arm64 · windows-amd64.exe
curl -fsSL https://github.com/Zennoxa/shield/releases/download/v0.7.0/shield-linux-amd64 -o shield
chmod +x shield && ./shield version
Verify your download
sha256sum -c SHA256SUMS