SAST MCP Server
Related Servers
Alternatives to SAST MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to scan code for security and quality issues and receive machine-readable reports with suggested fixes and verification criteria.48 npm2MIT

Draugrofficial
AlicenseNot gradedqualityAmaintenanceSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.7Apache 2.0- AlicenseNot gradedqualityDmaintenanceProvides AI agents with 25 security analysis tools including vulnerability scanning, package hallucination detection, prompt injection firewall, and CI/CD integration.1MIT
- AlicenseNot gradedqualityCmaintenanceProvides security checks for AI agents, including secret scanning, CVE lookup, and dependency vulnerability scanning, all running locally except for CVE lookups.MIT
- AlicenseNot gradedqualityBmaintenanceIntegrates 15+ static application security testing tools (Semgrep, Bandit, TruffleHog, etc.) with Claude Code AI, enabling automated vulnerability scanning and security analysis through natural language commands. Supports cross-platform operation with remote execution on dedicated security VMs.6MIT
- AlicenseAqualityDmaintenanceEnables AI assistants to scan project dependencies and Infrastructure as Code files for security vulnerabilities and misconfigurations. It also provides automated fixing capabilities to remediate identified security issues.183MIT
TDQS
Scored across 27 tools
Each tool has a clear and distinct purpose. Scanning tools are differentiated by scope (directory, git history, image, DAST, all), and fixing/reporting/integration tools are unique in function.
Most tools follow a verb_noun pattern, but there are exceptions like 'compliance_report' (noun_noun) and 'remediate_and_verify' (verb_and_verb), and some include prepositions ('upload_to_defectdojo'). The style is inconsistent but still readable.
27 tools is on the high side but appropriate for a comprehensive SAST server covering scanning, fixing, reporting, integration, baselines, and notifications. Each tool earns its place.
The tool surface covers the entire security scanning lifecycle: multiple scan types, fix generation and verification, baselines, compliance mapping, reporting, notifications, and integrations with Jira, Slack, Teams, GitHub, and DefectDojo. No obvious gaps.