VA-MCP
VA-MCP is a Vulnerability Analyzer MCP server that performs OWASP Top 10 security checks on API endpoints and returns detailed reports.
Available Tools:
ping— Verify the MCP server connection and statuslist_supported_checks— Retrieve all supported vulnerability check items (e.g., SQL Injection, IDOR, JWT validation)analyze_endpoint— Full analysis pipeline: profile parsing → feature extraction → scenario planning → automated OWASP check execution → result summarizationIndividual security checks (callable directly or via planner):
sql_injection,idor_bola,jwt_validation, and others
Report Generation:
Produces human-readable Markdown and structured JSON reports saved to the
reports/directoryReturns summarized results directly in the MCP response
Optionally dumps step-by-step JSON artifacts to
outputs/runs/for debugging (viaDUMP_ARTIFACTS=true)
In short, you provide an API endpoint profile (method, path, base URL, auth, request/response examples) and the server automatically plans and executes OWASP Top 10 vulnerability checks, then delivers a detailed report.
Provides vulnerability scanning capabilities for OWASP Top 10 security risks during development testing, analyzing APIs for security vulnerabilities and generating analysis reports.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@VA-MCPcheck my login API for OWASP vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
VA-MCP
This is an MCP designed to check for OWASP Top 10 vulnerabilities during functional unit testing in the development phase. This MCP receives API information, analyzes it, and returns the analysis output.
Scope (MVP)
MCP stdio server execution
Basic tools provided:
pinglist_supported_checks
Future expansion of OWASP Top 10 scenarios
Related MCP server: MCP-QA
Prerequisites
Team members must have the following installed before starting development:
Git
uv(Recommended) Python 3.11+
Verify installation:
git --version
uv --version
python3 --versionQuick Start
# 1) 저장소 클론
git clone <repo-url>
cd VA-MCP
# 2) 의존성/가상환경 동기화
uv sync
# 3) 테스트 확인
uv run pytest -q
# 4) MCP 서버 실행
uv run va-mcpSince va-mcp operates via stdio transport, it is used by connecting to the server from an MCP client (IDE/Agent).
Development Rules
Refer to dev-guide.md for team development rules (branch strategy, testing, PR, commit rules).
Test Guide
After developing a feature, test it in the following order:
# 1) 의존성 동기화
uv sync
# 2) 테스트 실행
uv run pytest -qWrite test code in the root
tests/folder.When adding a new feature, you must also add the corresponding tests.
Minimum criteria:
At least 1 functional unit test
tests/test_smoke.pymust continue to pass
Directory Roles
src/va_mcp/: Application source code rootsrc/va_mcp/server.py: MCP server entry point (file started when runningva-mcp)src/va_mcp/app.py:FastMCPapp creation and initializationsrc/va_mcp/config.py: Environment variable loading, output directory configurationsrc/va_mcp/registry/: Place to register which features (tools) and data (resources) to expose to MCPsrc/va_mcp/tools/: Functional functions actually executed by MCP (e.g.,ping, execution of checks)src/va_mcp/resources/: Collection of common reference data used by features (e.g., list of supported checks)tests/: Test code (must be executed after development is complete)outputs/: Storage for execution result outputs
Notes
Currently designed based on local integration (stdio).
We plan to switch to HTTP mode during the future AWS deployment phase.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Tools
Related MCP Servers
- AlicenseCqualityDmaintenanceA Model Context Protocol server designed for testing backend APIs for security vulnerabilities like authentication bypass, injection attacks, and data leakage.1415MIT
- Flicense-qualityDmaintenanceAn MCP server for the comprehensive analysis of Swagger 2.0 and OpenAPI 3.x contracts. It allows users to extract detailed information about endpoints, request/response schemas, parameters, and security configurations from API documentation.
- AlicenseBqualityDmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.6MIT
- Alicense-qualityDmaintenanceAn MCP server for AI-powered API testing that enables automated positive, negative, and security testing directly from AI chat interfaces. It supports multiple AI providers and generates detailed security reports.34Inno Setup
Related MCP Connectors
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
MCP server for AI access to Swagger by SmartBear.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/KTTechUp-Team304/VA_MCP'
If you have feedback or need assistance with the MCP directory API, please join our Discord server