MCP Contrast
M

MCP Contrast

Contrast MCP Server is a bridge that connects Contrast security data with AI agents/LLMs, helping developers and security professionals quickly fix vulnerabilities. It supports multiple deployment methods, including local running and Docker containers, and can be integrated with tools such as VS Code and Copilot.
2 points
6.6K

What is Contrast MCP Server?

Contrast MCP Server is a bridge that connects your Contrast data with the AI agent/LLM of your choice. It enables developers and security professionals to leverage AI capabilities to quickly identify and fix security vulnerabilities in code.

How to use Contrast MCP Server?

You can use the MCP Server in multiple ways: run it as a standalone Java application, deploy it via a Docker container, or integrate it into development tools such as VS Code, Cline plugins, and oterm.

Applicable scenarios

It is suitable for developers who need to quickly fix code vulnerabilities and security professionals who need to analyze the security status of applications. It is particularly suitable for scenarios where there are a large number of vulnerabilities to handle or automated repair suggestions are required.

Main features

Vulnerability repair
Provide detailed analysis and repair suggestions for code vulnerabilities
Third - party library analysis
Identify and update vulnerable third - party libraries
Security analysis
Provide vulnerability analysis of applications and servers for security professionals
Multi - platform integration
Support multiple development tools such as VS Code, Cline plugins, and oterm
Advantages
Combine Contrast's unique vulnerability data and AI capabilities to provide accurate repair suggestions
Support multiple deployment methods, flexible and easy to use
Seamlessly integrate with existing development tools
Provide detailed vulnerability analysis and context information
Limitations
Contrast API credentials are required for use
Data privacy depends on the AI agent/LLM you choose
Some advanced features may require technical knowledge for configuration

How to use

Get Contrast API credentials
You need to prepare Contrast API key, service key, username, and organization ID
Choose a deployment method
Decide whether to run directly with Java, use a Docker container, or integrate into a development tool
Configure the MCP Server
Configure the corresponding environment variables or parameters according to the deployment method you choose
Start querying
Enter queries through the interface you choose to get vulnerability information and repair suggestions

Usage examples

Developers fix code vulnerabilities
Developers find security vulnerabilities in the code and use the MCP Server to get detailed vulnerability descriptions and repair suggestions
Security professionals analyze library vulnerabilities
The security team needs to identify all high - risk third - party library vulnerabilities in the application
Update vulnerable libraries
Developers need to update vulnerable libraries to secure versions

Frequently Asked Questions

Will the MCP Server send my code to Contrast?
What kind of Contrast account do I need to use the MCP Server?
Which AI agents/LLMs does the MCP Server support?
How to use the MCP Server behind a corporate proxy?

Related resources

GitHub repository
Source code and issue tracking for Contrast MCP Server
Contrast Security official website
Official website for Contrast security products
Maven Central
Maven Central repository for the MCP Server

Installation

Copy the following command to your Client for configuration
"mcpServers": {
    "contrast-mcp": {
      "command": "/usr/bin/java", "args": ["-jar","/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
        "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
        "--CONTRAST_API_KEY=xxx",
        "--CONTRAST_SERVICE_KEY=xxx",
        "--CONTRAST_USERNAME=xxx.xxx@contrastsecurity.com",
        "--CONTRAST_ORG_ID=xxx"]
    }
}

{
  "mcpServers": {
    "contrastmcp": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "CONTRAST_HOST_NAME",
        "-e",
        "CONTRAST_API_KEY",
        "-e",
        "CONTRAST_SERVICE_KEY",
        "-e",
        "CONTRAST_USERNAME",
        "-e",
        "CONTRAST_ORG_ID",
        "-i",
        "--rm",
        "contrast/mcp-contrast:latest",
        "-t",
        "stdio"
      ],
      "env": {
        "CONTRAST_HOST_NAME": "example.contrastsecurity.com",
        "CONTRAST_API_KEY": "example",
        "CONTRAST_SERVICE_KEY": "example",
        "CONTRAST_USERNAME": "example@example.com",
        "CONTRAST_ORG_ID": "example"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

"mcpServers": {
  "contrast-assess": {
    "command": "/usr/bin/java", 
    "args": [
      "-Dhttp.proxyHost=proxy.example.com", 
      "-Dhttp.proxyPort=8080", 
      "-Dhttps.proxyHost=proxy.example.com", 
      "-Dhttps.proxyPort=8080",
      "-jar",
      "/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
      "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
      "--CONTRAST_API_KEY=example",
      "--CONTRAST_SERVICE_KEY=example",
      "--CONTRAST_USERNAME=example@example.com",
      "--CONTRAST_ORG_ID=example"
    ]
  }
}
Note: Your key is sensitive information, do not share it with anyone.

Alternatives

M
MCP
The Microsoft official MCP server provides search and access functions for the latest Microsoft technical documentation for AI assistants
10.5K
5 points
A
Aderyn
Aderyn is an open - source Solidity smart contract static analysis tool written in Rust, which helps developers and security researchers discover vulnerabilities in Solidity code. It supports Foundry and Hardhat projects, can generate reports in multiple formats, and provides a VSCode extension.
Rust
6.1K
5 points
D
Devtools Debugger MCP
The Node.js Debugger MCP server provides complete debugging capabilities based on the Chrome DevTools protocol, including breakpoint setting, stepping execution, variable inspection, and expression evaluation.
TypeScript
6.5K
4 points
S
Scrapling
Scrapling is an adaptive web scraping library that can automatically learn website changes and re - locate elements. It supports multiple scraping methods and AI integration, providing high - performance parsing and a developer - friendly experience.
Python
8.3K
5 points
M
Mcpjungle
MCPJungle is a self-hosted MCP gateway used to centrally manage and proxy multiple MCP servers, providing a unified tool access interface for AI agents.
Go
0
4.5 points
C
Cipher
Cipher is an open-source memory layer framework designed for programming AI agents. It integrates with various IDEs and AI coding assistants through the MCP protocol, providing core functions such as automatic memory generation, team memory sharing, and dual-system memory management.
TypeScript
0
5 points
N
Nexus
Nexus is an AI tool aggregation gateway that supports connecting multiple MCP servers and LLM providers, providing tool search, execution, and model routing functions through a unified endpoint, and supporting security authentication and rate limiting.
Rust
0
4 points
S
Shadcn Ui MCP Server
An MCP server that provides shadcn/ui component integration for AI workflows, supporting React, Svelte, and Vue frameworks. It includes functions for accessing component source code, examples, and metadata.
TypeScript
11.2K
5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
17.0K
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
15.0K
4.5 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
24.0K
5 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
44.9K
4.3 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
20.5K
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
45.5K
4.5 points
M
Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
31.0K
4.8 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
16.1K
4.5 points
AIBase
Zhiqi Future, Your AI Solution Think Tank
© 2025AIBase