SA

Sast MCP

A standard MCP server for SAST/DAST tools (Bandit, njsscan, Bearer, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP

Grade A Local · stdio No auth needed tools not listed v0.8.3
No reviews yet by skyrxinGitHub Runs on your machine, nothing hosted
p95 latency
call success
local
runs on your machine
calls last 7d

What it does

A standard MCP server for SAST/DAST tools (Bandit, njsscan, Bearer, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP) — scan code for security vulnerabilities from any AI agent

Quickstart

# 1 — install (mcprush login holds a key from your dashboard) npx mcprush@latest add sast-mcp # 2 — ask your agent something > A standard MCP server for SAST/DAST tools (Bandit, njsscan, Bearer, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP

Sast is free: there is no plan to choose, no cap to set and nothing that can bill you.

Publishernot claimed
SK
skyrxin1 server
1 category

Collected from a public index. Nobody has claimed this account, so nothing here was written by its author — claim it if it is yours.

All 1 server
Often installed together

Pairs well with

See all