MCP Contrast
M

MCP Contrast

Contrast MCP Server is a bridge that connects Contrast security data with AI agents/LLMs, helping developers and security professionals quickly fix vulnerabilities. It supports multiple deployment methods, including local running and Docker containers, and can be integrated with tools such as VS Code and Copilot.
2 points
8.7K

What is Contrast MCP Server?

Contrast MCP Server is a bridge that connects your Contrast data with the AI agent/LLM of your choice. It enables developers and security professionals to leverage AI capabilities to quickly identify and fix security vulnerabilities in code.

How to use Contrast MCP Server?

You can use the MCP Server in multiple ways: run it as a standalone Java application, deploy it via a Docker container, or integrate it into development tools such as VS Code, Cline plugins, and oterm.

Applicable scenarios

It is suitable for developers who need to quickly fix code vulnerabilities and security professionals who need to analyze the security status of applications. It is particularly suitable for scenarios where there are a large number of vulnerabilities to handle or automated repair suggestions are required.

Main features

Vulnerability repair
Provide detailed analysis and repair suggestions for code vulnerabilities
Third - party library analysis
Identify and update vulnerable third - party libraries
Security analysis
Provide vulnerability analysis of applications and servers for security professionals
Multi - platform integration
Support multiple development tools such as VS Code, Cline plugins, and oterm
Advantages
Combine Contrast's unique vulnerability data and AI capabilities to provide accurate repair suggestions
Support multiple deployment methods, flexible and easy to use
Seamlessly integrate with existing development tools
Provide detailed vulnerability analysis and context information
Limitations
Contrast API credentials are required for use
Data privacy depends on the AI agent/LLM you choose
Some advanced features may require technical knowledge for configuration

How to use

Get Contrast API credentials
You need to prepare Contrast API key, service key, username, and organization ID
Choose a deployment method
Decide whether to run directly with Java, use a Docker container, or integrate into a development tool
Configure the MCP Server
Configure the corresponding environment variables or parameters according to the deployment method you choose
Start querying
Enter queries through the interface you choose to get vulnerability information and repair suggestions

Usage examples

Developers fix code vulnerabilities
Developers find security vulnerabilities in the code and use the MCP Server to get detailed vulnerability descriptions and repair suggestions
Security professionals analyze library vulnerabilities
The security team needs to identify all high - risk third - party library vulnerabilities in the application
Update vulnerable libraries
Developers need to update vulnerable libraries to secure versions

Frequently Asked Questions

Will the MCP Server send my code to Contrast?
What kind of Contrast account do I need to use the MCP Server?
Which AI agents/LLMs does the MCP Server support?
How to use the MCP Server behind a corporate proxy?

Related resources

GitHub repository
Source code and issue tracking for Contrast MCP Server
Contrast Security official website
Official website for Contrast security products
Maven Central
Maven Central repository for the MCP Server

Installation

Copy the following command to your Client for configuration
"mcpServers": {
    "contrast-mcp": {
      "command": "/usr/bin/java", "args": ["-jar","/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
        "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
        "--CONTRAST_API_KEY=xxx",
        "--CONTRAST_SERVICE_KEY=xxx",
        "--CONTRAST_USERNAME=xxx.xxx@contrastsecurity.com",
        "--CONTRAST_ORG_ID=xxx"]
    }
}

{
  "mcpServers": {
    "contrastmcp": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "CONTRAST_HOST_NAME",
        "-e",
        "CONTRAST_API_KEY",
        "-e",
        "CONTRAST_SERVICE_KEY",
        "-e",
        "CONTRAST_USERNAME",
        "-e",
        "CONTRAST_ORG_ID",
        "-i",
        "--rm",
        "contrast/mcp-contrast:latest",
        "-t",
        "stdio"
      ],
      "env": {
        "CONTRAST_HOST_NAME": "example.contrastsecurity.com",
        "CONTRAST_API_KEY": "example",
        "CONTRAST_SERVICE_KEY": "example",
        "CONTRAST_USERNAME": "example@example.com",
        "CONTRAST_ORG_ID": "example"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

"mcpServers": {
  "contrast-assess": {
    "command": "/usr/bin/java", 
    "args": [
      "-Dhttp.proxyHost=proxy.example.com", 
      "-Dhttp.proxyPort=8080", 
      "-Dhttps.proxyHost=proxy.example.com", 
      "-Dhttps.proxyPort=8080",
      "-jar",
      "/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
      "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
      "--CONTRAST_API_KEY=example",
      "--CONTRAST_SERVICE_KEY=example",
      "--CONTRAST_USERNAME=example@example.com",
      "--CONTRAST_ORG_ID=example"
    ]
  }
}
Note: Your key is sensitive information, do not share it with anyone.

Alternatives

V
Vestige
Vestige is an AI memory engine based on cognitive science. By implementing 29 neuroscience modules such as prediction error gating, FSRS - 6 spaced repetition, and memory dreaming, it provides long - term memory capabilities for AI. It includes a 3D visualization dashboard and 21 MCP tools, runs completely locally, and does not require the cloud.
Rust
8.9K
4.5 points
M
Moltbrain
MoltBrain is a long-term memory layer plugin designed for OpenClaw, MoltBook, and Claude Code, capable of automatically learning and recalling project context, providing intelligent search, observation recording, analysis statistics, and persistent storage functions.
TypeScript
10.4K
4.5 points
B
Bm.md
A feature-rich Markdown typesetting tool that supports multiple style themes and platform adaptation, providing real-time editing preview, image export, and API integration capabilities
TypeScript
15.2K
5 points
S
Security Detections MCP
Security Detections MCP is a server based on the Model Context Protocol that allows LLMs to query a unified security detection rule database covering Sigma, Splunk ESCU, Elastic, and KQL formats. The latest version 3.0 is upgraded to an autonomous detection engineering platform that can automatically extract TTPs from threat intelligence, analyze coverage gaps, generate SIEM-native format detection rules, run tests, and verify. The project includes over 71 tools, 11 pre-built workflow prompts, and a knowledge graph system, supporting multiple SIEM platforms.
TypeScript
6.4K
4 points
P
Paperbanana
Python
9.2K
5 points
B
Better Icons
An MCP server and CLI tool that provides search and retrieval of over 200,000 icons, supports more than 150 icon libraries, and helps AI assistants and developers quickly obtain and use icons.
TypeScript
9.7K
4.5 points
A
Assistant Ui
assistant - ui is an open - source TypeScript/React library for quickly building production - grade AI chat interfaces, providing composable UI components, streaming responses, accessibility, etc., and supporting multiple AI backends and models.
TypeScript
8.2K
5 points
A
Apify MCP Server
The Apify MCP Server is a tool based on the Model Context Protocol (MCP) that allows AI assistants to extract data from websites such as social media, search engines, and e-commerce through thousands of ready-to-use crawlers, scrapers, and automation tools (Apify Actors). It supports OAuth and Skyfire proxy payment and can be integrated into MCP clients such as Claude and VS Code through HTTPS endpoints or local stdio.
TypeScript
9.9K
5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
26.1K
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
23.9K
4.5 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
79.1K
4.3 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
36.6K
5 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
36.8K
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
68.6K
4.5 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
23.1K
4.5 points
C
Context7
Context7 MCP is a service that provides real-time, version-specific documentation and code examples for AI programming assistants. It is directly integrated into prompts through the Model Context Protocol to solve the problem of LLMs using outdated information.
TypeScript
102.5K
4.7 points
AIBase
Zhiqi Future, Your AI Solution Think Tank
© 2026AIBase