SAST MCP Server
by skyrxinio.github.Skyrxin/sast-mcp-serverv0.8.3
SAST/DAST scanners (Bandit, Semgrep, Trivy, CodeQL, OWASP ZAP and more) with closed-loop remediation, SARIF/SBOM/VEX export and compliance reporting.
context tax
queued
security
queued
cold start
queued
freshness
Slowing4mo ago
Install SAST MCP server
Install in Claude Code
claude mcp add sast -e SAST_MCP_API_KEY='<sast-mcp-api-key>' -e SAST_MCP_JWT_SECRET='<sast-mcp-jwt-secret>' -- uvx sast-mcp-serverInstall in Cursor
{
"mcpServers": {
"sast": {
"command": "uvx",
"args": [
"sast-mcp-server"
],
"env": {
"SAST_MCP_API_KEY": "<sast-mcp-api-key>",
"SAST_MCP_JWT_SECRET": "<sast-mcp-jwt-secret>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"sast": {
"command": "uvx",
"args": [
"sast-mcp-server"
],
"env": {
"SAST_MCP_API_KEY": "<sast-mcp-api-key>",
"SAST_MCP_JWT_SECRET": "<sast-mcp-jwt-secret>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"sast": {
"type": "stdio",
"command": "uvx",
"args": [
"sast-mcp-server"
],
"env": {
"SAST_MCP_API_KEY": "<sast-mcp-api-key>",
"SAST_MCP_JWT_SECRET": "<sast-mcp-jwt-secret>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"sast": {
"command": "uvx",
"args": [
"sast-mcp-server"
],
"env": {
"SAST_MCP_API_KEY": "<sast-mcp-api-key>",
"SAST_MCP_JWT_SECRET": "<sast-mcp-jwt-secret>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SAST_MCP_TIMEOUT | — | — | Per-scan timeout in seconds (default: 300). |
| SAST_MCP_LOG_LEVEL | — | — | Logging level: DEBUG, INFO, WARNING, ERROR (default: INFO). |
| SAST_MCP_API_KEY | — | yes | Optional static API key to require auth (legacy mode; HTTP transports). |
| SAST_MCP_JWT_SECRET | — | yes | Optional HMAC secret to require JWT auth with scopes (HTTP transports). |
Freshness
Slowing — last maintenance signal 4mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-06-23 · 4mo ago · GitHub
Latest release
2026-06-23 · 4mo ago · GitHub · v0.8.3
Package published
no data · npm/PyPI
Registry entry updated
2026-06-24 · 4mo ago · official registry · v0.8.3
FAQ
›How do I install the SAST MCP server in Claude Code?
Run: claude mcp add sast -e SAST_MCP_API_KEY='<sast-mcp-api-key>' -e SAST_MCP_JWT_SECRET='<sast-mcp-jwt-secret>' -- uvx sast-mcp-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does SAST require an API key?
Yes. It expects SAST_MCP_API_KEY, SAST_MCP_JWT_SECRET, of which 2 are secrets.
›Can I use SAST as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is SAST in the official MCP registry?
Yes, as io.github.Skyrxin/sast-mcp-server.
Alternatives to SAST
Other security MCP servers.