PluginBench
MCP Server
Active
MIT

SAST MCP Server MCP Server

io.github.Skyrxin/sast-mcp-server

What is the SAST MCP Server MCP server?

11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations

How to install SAST MCP Server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • SAST_MCP_TIMEOUT

    Per-scan timeout in seconds (default: 300).

  • SAST_MCP_LOG_LEVEL

    Logging level: DEBUG, INFO, WARNING, ERROR (default: INFO).

  • SAST_MCP_API_KEY
    secret

    Optional static API key to require auth (legacy mode; HTTP transports).

  • SAST_MCP_JWT_SECRET
    secret

    Optional HMAC secret to require JWT auth with scopes (HTTP transports).

Claude Desktop
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "sast-mcp-server": {
      "command": "uvx",
      "args": [
        "sast-mcp-server"
      ],
      "env": {
        "SAST_MCP_TIMEOUT": "<YOUR_SAST_MCP_TIMEOUT>",
        "SAST_MCP_LOG_LEVEL": "<YOUR_SAST_MCP_LOG_LEVEL>",
        "SAST_MCP_API_KEY": "<YOUR_SAST_MCP_API_KEY>",
        "SAST_MCP_JWT_SECRET": "<YOUR_SAST_MCP_JWT_SECRET>"
      }
    }
  }
}
Cursor
~/.cursor/mcp.json
{
  "mcpServers": {
    "sast-mcp-server": {
      "command": "uvx",
      "args": [
        "sast-mcp-server"
      ],
      "env": {
        "SAST_MCP_TIMEOUT": "<YOUR_SAST_MCP_TIMEOUT>",
        "SAST_MCP_LOG_LEVEL": "<YOUR_SAST_MCP_LOG_LEVEL>",
        "SAST_MCP_API_KEY": "<YOUR_SAST_MCP_API_KEY>",
        "SAST_MCP_JWT_SECRET": "<YOUR_SAST_MCP_JWT_SECRET>"
      }
    }
  }
}
Windsurf
~/.codeium/windsurf/mcp_config.json
{
  "mcpServers": {
    "sast-mcp-server": {
      "command": "uvx",
      "args": [
        "sast-mcp-server"
      ],
      "env": {
        "SAST_MCP_TIMEOUT": "<YOUR_SAST_MCP_TIMEOUT>",
        "SAST_MCP_LOG_LEVEL": "<YOUR_SAST_MCP_LOG_LEVEL>",
        "SAST_MCP_API_KEY": "<YOUR_SAST_MCP_API_KEY>",
        "SAST_MCP_JWT_SECRET": "<YOUR_SAST_MCP_JWT_SECRET>"
      }
    }
  }
}
VS Code
.vscode/mcp.json
{
  "servers": {
    "sast-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "sast-mcp-server"
      ],
      "env": {
        "SAST_MCP_TIMEOUT": "<YOUR_SAST_MCP_TIMEOUT>",
        "SAST_MCP_LOG_LEVEL": "<YOUR_SAST_MCP_LOG_LEVEL>",
        "SAST_MCP_API_KEY": "<YOUR_SAST_MCP_API_KEY>",
        "SAST_MCP_JWT_SECRET": "<YOUR_SAST_MCP_JWT_SECRET>"
      }
    }
  }
}
Claude Code
claude mcp add sast-mcp-server --env SAST_MCP_TIMEOUT=<YOUR_SAST_MCP_TIMEOUT> --env SAST_MCP_LOG_LEVEL=<YOUR_SAST_MCP_LOG_LEVEL> --env SAST_MCP_API_KEY=<YOUR_SAST_MCP_API_KEY> --env SAST_MCP_JWT_SECRET=<YOUR_SAST_MCP_JWT_SECRET> -- uvx sast-mcp-server

Related MCP servers

Give your AI agent stealth web scraping with Cloudflare bypass and CSS selection, powered by Scrapling.

67k
Python
BSD-3-Clause
View repository →

Give your AI coding agent full control of a live Chrome browser for automation, debugging, and performance analysis.

45k
TypeScript
Apache-2.0
View repository →

Let AI agents manage your Puter files, websites, and serverless workers over MCP.

43k
TypeScript
AGPL-3.0
View repository →

Browser automation for AI agents via MCP, powering ByteDance's Agent TARS hybrid GUI/DOM browser control.

37k
TypeScript
Apache-2.0
View repository →

Run arbitrary shell commands from an MCP-connected AI agent.

37k
TypeScript
Apache-2.0
View repository →

Filesystem access MCP server from ByteDance's UI-TARS/Agent TARS ecosystem.

37k
TypeScript
Apache-2.0
View repository →