</>MCP Agents Market
Skill

Kunlun-M

by LoRexxar2.4kPythonUpdated 2026-09-01

KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java and C/C++, with AST-based semantic scanning and one-click AI Agent integration (OpenClaw, Codex, Claude Code, Hermes, and more).

Claude CodeCodexOpenClawHermes

Kunlun-M is an open-source static code analysis tool with built-in agent skills for AI-powered vulnerability scanning across PHP, Node.js/JavaScript, Python, Java, Go, and C/C++. It uses AST-based semantic analysis to detect security issues and supports one-click integration with AI agents including Claude Code, Codex, OpenClaw, and Hermes through its skill interface. Security researchers can leverage console, CLI, web dashboard, or CI/CD modes to audit source code, and AI agents can automatically load the kunlun-m-general skill to perform scans with natural language instructions. The tool evolved from Cobra-W with a focus on detection accuracy and security researcher workflows.

Key Features

AST-based semantic scanning for PHP, Node.js, Python, Java, Go, and C/C++ with high accuracy
One-click AI agent integration via skills/kunlun-m-general/ directory for Claude Code, Codex, OpenClaw, and Hermes
Multiple operation modes: CLI scanning, console mode, web dashboard (port 9999), and CI/CD integration
PHP deserialization chain discovery plugin that auto-generates PoC files
Customizable rule engine (CVI_xxxx.py format) and tamper detection patterns
Export scan results in JSON, Markdown, or HTML formats for reporting
CI/CD scan driver with exit codes and gating on severity levels (high/medium/low)
API access via token for programmatic task and result retrieval

Use Cases

  • 01AI agents automatically scanning repositories for security vulnerabilities via skill commands
  • 02Security researchers auditing large PHP codebases to discover hidden entry points with entrance_finder plugin
  • 03CI/CD pipelines enforcing security gates with automated code scans and fail-on-high settings
  • 04Web application security teams using the dashboard to manage and track multiple scan tasks
  • 05Penetration testers generating PHP deserialization chain PoCs from target applications
  • 06Development teams exporting vulnerability reports in HTML/Markdown for stakeholder review

Related Skills

View more

Kunlun-M — FAQ

What is Kunlun-M and what does it do?+

Kunlun-M is an open-source static code analysis tool that detects security vulnerabilities in PHP, Node.js, Python, Java, Go, and C/C++ codebases using AST-based semantic analysis. It includes built-in skills that allow AI agents like Claude Code, Codex, and Hermes to perform automated security scans through natural language commands.

How do I install Kunlun-M for use with AI agents?+

Install Python 3.10+ (3.13+ recommended), clone the repository, install dependencies with pip, copy the settings template, and initialize the database. AI agents can automatically load the kunlun-m-general skill from the skills/ directory when instructed to download and load the repository.

Which AI clients and agents work with Kunlun-M?+

Kunlun-M supports integration with OpenClaw, Codex, Claude Code, Hermes, and other AI agents that can load skill directories and execute shell commands. The tool can also be used standalone via CLI, console, or web modes.

Do I need API keys or prerequisites to use Kunlun-M?+

No API keys are required. Prerequisites include Python 3.10 or higher, dependencies from requirements.txt, and SQLite (default) or optionally MySQL for the database. Docker installation is also available.

Is Kunlun-M free and open source?+

Yes, Kunlun-M is fully open source and free to use. It is actively maintained and available on GitHub under an open-source license.

How do I use Kunlun-M in CI/CD pipelines?+

Use the ci_scan.py driver with parameters like --target, --output, and --fail-on to run scans with clear exit codes and JSON reports. The tool supports integration with GitHub Actions, GitLab CI, and Jenkins as documented in docs/ci.md.

How do I install Kunlun-M?+

Open the source repository on GitHub and follow its README. Kunlun-M is a skill — MCP Agents Market links you directly to the official repo.

Is Kunlun-M free?+

Kunlun-M is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches