M

MCP Contrast

Contrast MCP Server is a bridge that connects Contrast security data with AI agents/LLMs, helping developers and security professionals quickly fix vulnerabilities. It supports multiple deployment methods, including local running and Docker containers, and can be integrated with tools such as VS Code and Copilot.
2 points
23

What is Contrast MCP Server?

Contrast MCP Server is a bridge that connects your Contrast data with the AI agent/LLM of your choice. It enables developers and security professionals to leverage AI capabilities to quickly identify and fix security vulnerabilities in code.

How to use Contrast MCP Server?

You can use the MCP Server in multiple ways: run it as a standalone Java application, deploy it via a Docker container, or integrate it into development tools such as VS Code, Cline plugins, and oterm.

Applicable scenarios

It is suitable for developers who need to quickly fix code vulnerabilities and security professionals who need to analyze the security status of applications. It is particularly suitable for scenarios where there are a large number of vulnerabilities to handle or automated repair suggestions are required.

Main features

Vulnerability repairProvide detailed analysis and repair suggestions for code vulnerabilities
Third - party library analysisIdentify and update vulnerable third - party libraries
Security analysisProvide vulnerability analysis of applications and servers for security professionals
Multi - platform integrationSupport multiple development tools such as VS Code, Cline plugins, and oterm

Advantages and limitations

Advantages
Combine Contrast's unique vulnerability data and AI capabilities to provide accurate repair suggestions
Support multiple deployment methods, flexible and easy to use
Seamlessly integrate with existing development tools
Provide detailed vulnerability analysis and context information
Limitations
Contrast API credentials are required for use
Data privacy depends on the AI agent/LLM you choose
Some advanced features may require technical knowledge for configuration

How to use

Get Contrast API credentials
You need to prepare Contrast API key, service key, username, and organization ID
Choose a deployment method
Decide whether to run directly with Java, use a Docker container, or integrate into a development tool
Configure the MCP Server
Configure the corresponding environment variables or parameters according to the deployment method you choose
Start querying
Enter queries through the interface you choose to get vulnerability information and repair suggestions

Usage examples

Developers fix code vulnerabilitiesDevelopers find security vulnerabilities in the code and use the MCP Server to get detailed vulnerability descriptions and repair suggestions
Security professionals analyze library vulnerabilitiesThe security team needs to identify all high - risk third - party library vulnerabilities in the application
Update vulnerable librariesDevelopers need to update vulnerable libraries to secure versions

Frequently Asked Questions

Will the MCP Server send my code to Contrast?
What kind of Contrast account do I need to use the MCP Server?
Which AI agents/LLMs does the MCP Server support?
How to use the MCP Server behind a corporate proxy?

Related resources

GitHub repository
Source code and issue tracking for Contrast MCP Server
Contrast Security official website
Official website for Contrast security products
Maven Central
Maven Central repository for the MCP Server
Installation
Copy the following command to your Client for configuration
"mcpServers": {
    "contrast-mcp": {
      "command": "/usr/bin/java", "args": ["-jar","/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
        "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
        "--CONTRAST_API_KEY=xxx",
        "--CONTRAST_SERVICE_KEY=xxx",
        "--CONTRAST_USERNAME=xxx.xxx@contrastsecurity.com",
        "--CONTRAST_ORG_ID=xxx"]
    }
}

{
  "mcpServers": {
    "contrastmcp": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "CONTRAST_HOST_NAME",
        "-e",
        "CONTRAST_API_KEY",
        "-e",
        "CONTRAST_SERVICE_KEY",
        "-e",
        "CONTRAST_USERNAME",
        "-e",
        "CONTRAST_ORG_ID",
        "-i",
        "--rm",
        "contrast/mcp-contrast:latest",
        "-t",
        "stdio"
      ],
      "env": {
        "CONTRAST_HOST_NAME": "example.contrastsecurity.com",
        "CONTRAST_API_KEY": "example",
        "CONTRAST_SERVICE_KEY": "example",
        "CONTRAST_USERNAME": "example@example.com",
        "CONTRAST_ORG_ID": "example"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

"mcpServers": {
  "contrast-assess": {
    "command": "/usr/bin/java", 
    "args": [
      "-Dhttp.proxyHost=proxy.example.com", 
      "-Dhttp.proxyPort=8080", 
      "-Dhttps.proxyHost=proxy.example.com", 
      "-Dhttps.proxyPort=8080",
      "-jar",
      "/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
      "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
      "--CONTRAST_API_KEY=example",
      "--CONTRAST_SERVICE_KEY=example",
      "--CONTRAST_USERNAME=example@example.com",
      "--CONTRAST_ORG_ID=example"
    ]
  }
}
Note: Your key is sensitive information, do not share it with anyone.
S
Search1api
The Search1API MCP Server is a server based on the Model Context Protocol (MCP), providing search and crawling functions, and supporting multiple search services and tools.
TypeScript
348
4 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
837
4.3 points
M
MCP Alchemy
Certified
MCP Alchemy is a tool that connects Claude Desktop to multiple databases, supporting SQL queries, database structure analysis, and data report generation.
Python
332
4.2 points
P
Postgresql MCP
A PostgreSQL database MCP service based on the FastMCP library, providing CRUD operations, schema inspection, and custom SQL query functions for specified tables.
Python
115
4 points
M
MCP Scan
MCP-Scan is a security scanning tool for MCP servers, used to detect common security vulnerabilities such as prompt injection, tool poisoning, and cross-domain escalation.
Python
624
5 points
A
Agentic Radar
Agentic Radar is a security scanning tool for analyzing and assessing agentic systems, helping developers, researchers, and security experts understand the workflows of agentic systems and identify potential vulnerabilities.
Python
562
5 points
C
Cloudflare
Changesets is a build tool for managing versions and releases in multi - package or single - package repositories.
TypeScript
1.5K
5 points
E
Edgeone Pages MCP Server
EdgeOne Pages MCP is a service that quickly deploys HTML content to EdgeOne Pages via the MCP protocol and obtains a public URL
TypeScript
258
4.8 points
Featured MCP Services
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
837
4.3 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
1.7K
5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
97
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
150
4.5 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
572
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
6.7K
4.5 points
C
Context7
Context7 MCP is a service that provides real-time, version-specific documentation and code examples for AI programming assistants. It is directly integrated into prompts through the Model Context Protocol to solve the problem of LLMs using outdated information.
TypeScript
5.2K
4.7 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
288
4.5 points
AIbase
Zhiqi Future, Your AI Solution Think Tank
© 2025AIbase