Coding agents & AI review
Bring security feedback into the coding loop.
An assistant can generate a change faster than a reviewer can inspect it. Magdox's v1.3 integration gives compatible agents access to the licensed scanner through a private MCP bridge. The agent can inspect findings, work on a correction and rescan the repository, while your existing tests and release gates remain part of the workflow.
01
Establish a baseline
Scan the allowed repository.
02
Generate a change
Keep the task and permissions explicit.
03
Inspect the evidence
Read findings and missing coverage.
04
Test and rescan
Verify the final revision in CI.
Workflow illustration. Agent suggestions and prompts do not replace enforced repository checks.
01 / Coding agents & AI review
Put a repeatable security check beside code generation
Start with a repository baseline. After the assistant proposes a change, request the supported source scan and inspect its findings before continuing. Separate secret, dependency and inventory tools cover different questions; one source scan does not imply all checks ran.
Snippet checks can provide early feedback while a change is being written, but the repository scan is needed for the available file and project context. A useful final response from the agent names the checks it ran, unresolved findings and incomplete coverage. A secure-coding prompt guides behaviour; it is not an enforced merge control.
02 / Coding agents & AI review
Choose the client and understand what it receives
Setup guidance covers Claude Code, Codex and other MCP-capable hosts. The current integration evidence identifies Claude Code as the end-to-end validated host; other host templates need environment-specific verification. POSIX hooks run on macOS and Linux, while supported Windows CLI and MCP operation has its own boundaries.
Local stdio tools are limited to configured roots and invoke the licensed CLI. Matched source is excluded by default from scan responses unless the client explicitly requests it. An assistant can send the findings it receives to its model provider, so review that provider's data handling before allowing snippets or sensitive repository metadata.
03 / Coding agents & AI review
Keep optional AI review separate from detection
The CLI's optional model review is a separate workflow. An operator selects a provider and approves a repository before code excerpts are sent for an advisory verdict or a proposed fix. The original scanner remains responsible for its findings; the model does not silently remove a finding or reduce its severity.
A proposed fix can be checked with a rescan. That checks whether the original finding remains under the scanner's analysis; it does not replace functional tests or establish that the patch is correct in every context. Review the change and run the project's tests before merging.
Reviewable output
The information behind the next decision.
Let a configured coding assistant request local scans through MCP, and optionally review findings using a model your team chooses.
| Workflow | What it does | Required review |
|---|---|---|
| MCP scan tools | Let a configured assistant request local analysis | Client compatibility, explicit roots and output sharing |
| Secure-coding prompt / hooks | Guide checks around supported coding workflows | Host setup and enforcement in the actual environment |
| Optional model review | Add advisory verdicts and proposed corrections | Provider choice, repository consent and patch review |
| CI quality gate | Apply configured checks to the final repository change | Complete coverage, test results and release policy |
Put it to work
Make review part of the team's working process.
Authorise and scope the tools
Provision compatible components, allow the intended repository root and complete your host's setup. Keep credentials out of client configuration examples.
Generate, inspect and revise
Use scan findings as evidence for the code change. Treat repository text and tool output as untrusted data rather than instructions to reveal secrets or run arbitrary commands.
Verify the final repository
Run the appropriate scans and project tests after the last edit. Report incomplete work and preserve CI enforcement for the actual change being merged.
magdox login
magdox mcp install
magdox mcp config generic --root /absolute/path/to/repositoryv1.3 workflow: requires matching authorised private components and client-specific setup. Review and merge the generated configuration into your client. It does not automatically configure every host.
Before you start
Scope and practical questions.
Will this guarantee that an agent only writes secure code?
No. The integration provides feedback and review tools. It cannot guarantee agent compliance, complete detection or the correctness of generated code.
Is a local MCP configuration a hosted scanning endpoint?
No. Remote agents need their own authorised execution environment. Do not expose the local transport as a public scanning service.
Explore Code Security
Source-code analysis
Local SAST with affected locations, supported flow evidence, severity, confidence and explicit analysis coverage.
Dependency security
Review known vulnerabilities, malicious-package indicators and unresolved dependency versions from the repository's own manifests and lockfiles.
Secrets & configuration
Review source, infrastructure definitions and delivery configuration locally, with redacted secret findings and file-level context.
Code Security · next step
Evaluate the workflow on your own code.
Use a repository your team understands, review the findings with its engineers and decide how the result fits your delivery process.
14-day self-service trial. Card required; cancel before the trial ends to avoid the first charge.