MCP Contrast
M

MCP Contrast

Contrast MCP Server is a bridge that connects Contrast security data with AI agents/LLMs, helping developers and security professionals quickly fix vulnerabilities. It supports multiple deployment methods, including local running and Docker containers, and can be integrated with tools such as VS Code and Copilot.
2 points
6.6K

What is Contrast MCP Server?

Contrast MCP Server is a bridge that connects your Contrast data with the AI agent/LLM of your choice. It enables developers and security professionals to leverage AI capabilities to quickly identify and fix security vulnerabilities in code.

How to use Contrast MCP Server?

You can use the MCP Server in multiple ways: run it as a standalone Java application, deploy it via a Docker container, or integrate it into development tools such as VS Code, Cline plugins, and oterm.

Applicable scenarios

It is suitable for developers who need to quickly fix code vulnerabilities and security professionals who need to analyze the security status of applications. It is particularly suitable for scenarios where there are a large number of vulnerabilities to handle or automated repair suggestions are required.

Main features

Vulnerability repair
Provide detailed analysis and repair suggestions for code vulnerabilities
Third - party library analysis
Identify and update vulnerable third - party libraries
Security analysis
Provide vulnerability analysis of applications and servers for security professionals
Multi - platform integration
Support multiple development tools such as VS Code, Cline plugins, and oterm
Advantages
Combine Contrast's unique vulnerability data and AI capabilities to provide accurate repair suggestions
Support multiple deployment methods, flexible and easy to use
Seamlessly integrate with existing development tools
Provide detailed vulnerability analysis and context information
Limitations
Contrast API credentials are required for use
Data privacy depends on the AI agent/LLM you choose
Some advanced features may require technical knowledge for configuration

How to use

Get Contrast API credentials
You need to prepare Contrast API key, service key, username, and organization ID
Choose a deployment method
Decide whether to run directly with Java, use a Docker container, or integrate into a development tool
Configure the MCP Server
Configure the corresponding environment variables or parameters according to the deployment method you choose
Start querying
Enter queries through the interface you choose to get vulnerability information and repair suggestions

Usage examples

Developers fix code vulnerabilities
Developers find security vulnerabilities in the code and use the MCP Server to get detailed vulnerability descriptions and repair suggestions
Security professionals analyze library vulnerabilities
The security team needs to identify all high - risk third - party library vulnerabilities in the application
Update vulnerable libraries
Developers need to update vulnerable libraries to secure versions

Frequently Asked Questions

Will the MCP Server send my code to Contrast?
What kind of Contrast account do I need to use the MCP Server?
Which AI agents/LLMs does the MCP Server support?
How to use the MCP Server behind a corporate proxy?

Related resources

GitHub repository
Source code and issue tracking for Contrast MCP Server
Contrast Security official website
Official website for Contrast security products
Maven Central
Maven Central repository for the MCP Server

Installation

Copy the following command to your Client for configuration
"mcpServers": {
    "contrast-mcp": {
      "command": "/usr/bin/java", "args": ["-jar","/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
        "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
        "--CONTRAST_API_KEY=xxx",
        "--CONTRAST_SERVICE_KEY=xxx",
        "--CONTRAST_USERNAME=xxx.xxx@contrastsecurity.com",
        "--CONTRAST_ORG_ID=xxx"]
    }
}

{
  "mcpServers": {
    "contrastmcp": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "CONTRAST_HOST_NAME",
        "-e",
        "CONTRAST_API_KEY",
        "-e",
        "CONTRAST_SERVICE_KEY",
        "-e",
        "CONTRAST_USERNAME",
        "-e",
        "CONTRAST_ORG_ID",
        "-i",
        "--rm",
        "contrast/mcp-contrast:latest",
        "-t",
        "stdio"
      ],
      "env": {
        "CONTRAST_HOST_NAME": "example.contrastsecurity.com",
        "CONTRAST_API_KEY": "example",
        "CONTRAST_SERVICE_KEY": "example",
        "CONTRAST_USERNAME": "example@example.com",
        "CONTRAST_ORG_ID": "example"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

"mcpServers": {
  "contrast-assess": {
    "command": "/usr/bin/java", 
    "args": [
      "-Dhttp.proxyHost=proxy.example.com", 
      "-Dhttp.proxyPort=8080", 
      "-Dhttps.proxyHost=proxy.example.com", 
      "-Dhttps.proxyPort=8080",
      "-jar",
      "/Users/name/workspace/mcp-contrast/mcp-contrast/target/mcp-contrast-0.0.1-SNAPSHOT.jar",
      "--CONTRAST_HOST_NAME=example.contrastsecurity.com",
      "--CONTRAST_API_KEY=example",
      "--CONTRAST_SERVICE_KEY=example",
      "--CONTRAST_USERNAME=example@example.com",
      "--CONTRAST_ORG_ID=example"
    ]
  }
}
Note: Your key is sensitive information, do not share it with anyone.

Alternatives

R
Rsdoctor
Rsdoctor is a build analysis tool specifically designed for the Rspack ecosystem, fully compatible with webpack. It provides visual build analysis, multi - dimensional performance diagnosis, and intelligent optimization suggestions to help developers improve build efficiency and engineering quality.
TypeScript
8.6K
5 points
N
Next Devtools MCP
The Next.js development tools MCP server provides Next.js development tools and utilities for AI programming assistants such as Claude and Cursor, including runtime diagnostics, development automation, and document access functions.
TypeScript
10.4K
5 points
T
Testkube
Testkube is a test orchestration and execution framework for cloud-native applications, providing a unified platform to define, run, and analyze tests. It supports existing testing tools and Kubernetes infrastructure.
Go
6.9K
5 points
M
MCP Windbg
An MCP server that integrates AI models with WinDbg/CDB for analyzing Windows crash dump files and remote debugging, supporting natural language interaction to execute debugging commands.
Python
8.9K
5 points
R
Runno
Runno is a collection of JavaScript toolkits for securely running code in multiple programming languages in environments such as browsers and Node.js. It achieves sandboxed execution through WebAssembly and WASI, supports languages such as Python, Ruby, JavaScript, SQLite, C/C++, and provides integration methods such as web components and MCP servers.
TypeScript
9.7K
5 points
N
Netdata
Netdata is an open-source real-time infrastructure monitoring platform that provides second-level metric collection, visualization, machine learning-driven anomaly detection, and automated alerts. It can achieve full-stack monitoring without complex configuration.
Go
10.4K
5 points
M
MCP Server
The Mapbox MCP Server is a model context protocol server implemented in Node.js, providing AI applications with access to Mapbox geospatial APIs, including functions such as geocoding, point - of - interest search, route planning, isochrone analysis, and static map generation.
TypeScript
9.3K
4 points
U
Uniprof
Uniprof is a tool that simplifies CPU performance analysis. It supports multiple programming languages and runtimes, does not require code modification or additional dependencies, and can perform one-click performance profiling and hotspot analysis through Docker containers or the host mode.
TypeScript
7.5K
4.5 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
31.8K
5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
22.6K
4.3 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
67.3K
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
20.6K
4.5 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
30.3K
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
60.3K
4.5 points
M
Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
44.7K
4.8 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
20.3K
4.5 points
AIBase
Zhiqi Future, Your AI Solution Think Tank
© 2026AIBase