Skip to main content
Glama
ZeeshanSultan

DefectDojo Intelligence MCP Server

DefectDojo Intelligence MCP Server

권한을 보존하는 Model Context Protocol 서버로, DefectDojo OSS v2.58.4 REST API v2 위에서 동작합니다. 공식 DefectDojo Pro 내장 MCP 서버(읽기 도구 M. The(12개 + Security Landscape 프롬프트)와 **전컴 기능 패러티 (capability parity)**를 달성하며, 여기에 결정적(etermin) 분석/리포트 **상위 집합(superset)**을 추가합니다. Pro 내부 MCP는 Pro에디션과 인스턴스 v2.51.2+를 요구하고 OSS 2.58.4 호스트에서는 사용할 수 없으므로, 외부 어데터(adapter)로 구현합니다.

모든 호출은 호者자 자신의 DefectDojo API 토큰을 사용함으로, 표시 가능 범위는 DefectDojo가 결정합니다. 토큰은 메모리에만 보관되며, 로그에 기록되지 않고 LLM에 전송되지 않습니다.

  • 상태: Phase 0–4 완료, 강화 및 도커라이즈 완료. 테스트 140개, ruff-clean.

  • 배포: 도커라이즈된 https://dojo.example.com/mcp/ 구성은 deploy/DEPLOY.md를 참고하세요. 참고: 이 배포는 쓰기 및 DB-히스토リ 도구 그룸을 활성화합니다(보안 모델 및 DPLOY.md 참고). 사양: PRD.md.

도구

도구 26개 — 기본적으로 20개 활성 (읽기 14개 + 분석/리포트 6개), 6는 기본적으로 게이트 오프. 추가로 MCP 프롬프트 프리미디브 1개.

분류

도구

기본값

핵심 읽기 (Pro 패리티 + 소스 리콜버)

dd_get_findings, dd_get_finding_by_id, dd_get_products, dd_get_product_by_id, dd_get_product_types, dd_get_engagements, dd_get_tests, dd_resolve_finding_source, dd_get_users, dd_get_user_by_id, dd_get_groups, dd_get_group_by_id, dd_get_dojo_group_members, dd_get_roles

✅ 켜짐

분석 / 리포트 (superset에서)

dd_get_sla_breaches, dd_get_top_cwes, dd_prioritize_findings, dd_generate_product_security_summary, dd_generate_executive_report, dd_generate_engineering_report

✅ 짐

DB 히스토리 (읽기 reverse 사용, API 게이트)

dd_get_finding_history, dd_get_reopened_findings, dd_get_product_risk_trend

⛔ 꺼짐 (enable_db_tools + reporting DB)

쓰기 (확인 게이트)

dd_add_finding_note, dd_mark_finding_false_positive, dd_close_finding

⛔ 꺼짐 (enable_write_tools)

프롬프트

security_landscape_report

✅ 짐

분석 도구은 서버 측에서 결정적으로 계산됩니다(LLM 없음, 창(invented) 데이터 없음 — 모둔 수치는 findings-API 리로 추적됨)(하고, 타입된 구조화된 출역을 반환합니다. SLA는 ActDojo 자체의 external_of_sla 필터를, 우선순위화는 실제 KEV/EPSS/SLA 시 호를 사용합니다.

Related MCP server: Kuroko MCP Server

Pro와의 기패러티

Pro 도구

이 서버

get_findings, get_finding_by_id

dd_get_findings, dd_get_finding_by_id

get_products, get_product_types

dd_get_products, dd_get_product_types (+ dd_get_product_by_id)

get_engagements, get_tests

dd_get_engagements, dd_get_tests

get_users, get_user_by_id

dd_get_users, dd_get_user_by_id

get_groups, get_group_by_id, get_dojo_group_members

dd_get_groups, dd_get_group_by_id, dd_get_dojo_group_members

get_roles

dd_get_roles

(Pro에 대 존재 없음)

dd_resolve_finding_source — finding → clone할 저장구/브랜치/커밋 (superset)

📊 Security Landscape Report (프롬프트)

security_landscape_report (MCP 프롬프트 프리미티브)

SAST Review Report (프롬프트)

의도하지 않게 제외 — DAST/펜테스트 데이터에는 낮은 가치

보안 모델

  • 토큰: Authorization: Token <token> (Bearer 아님)을 사용합니다. HTTP 섭버시스템에서 입력 헤더에서 요청머다 토큰을 읽습니다(요청자의 for own). stdio는 DD_API_TOKEN을 사용합니다. streamable-http에서는 환경 변수 대체(fallback)가 비활성화됩니다 — Authorization 헤더의 없거나 손성된 요청은 거부되고, 서버의 환경 변수 토큰으로 조용히 실행되지 않습니다.

  • 토큰 isolation (pooling): 공유 연결 풀에는 no-store 쿠키 jar를 사용하므로, 업스트림 Set-Cookie가 다른 호출자의 토큰끼리 재생되지 않습니다. 인증은 요청 단위로만 수행합니다.

  • 검증: 토큰은 TTL 당 한 번 검증합니다 (토큰 자체가 아니라 128비트 description으로 헤시; 캐시크기 제한 있음). 첫 번째 도구 호출 전에 검증됩니다.

  • **** 삭제:** redact_secrets / treat_finding_text_as_untrusted 설정 시 모든 도구 결과에 중앙 적용되고, 비밀 정보는 제거됩니다 (URL 내 자격 증명 포함) — omit_user_pii 설정 시 PII(개인 식별 정보) 제함, 자유 텍스트는 max_evidence_chars 만큼 잘립니다.

  • 오류: 실패(401/403/404/타임아웃…)는 성공 반환 본문이 아닌 MCP 도구 오류(isError)로 나타납니다 — 클라이언트가 거부를 데이터로 오한하지 않습니다.

  • 쓰기: 기이트, 기본 끼짐. 활성하면 모든 쓰기에는 비어 있지 않은 사유 + 명시적 confirm=true이 필요합니다(그렇지 않으면 preview만). 상태 해시의 변환을 감사합니다. REST API만 — DB에 직접 쓰지 않습니다.

  • DB 히스토리: 기본 끼짐. 각 도구들은 REST를 통한 객체 권 인증을 먼저 받고, 그 다음에 **허용된 읽기전 목억 (allowlisted view)**을 반드입니다 (임의 SQL 아님).

  • 네트워크 transport: streamable-httpmcp.allowed_hosts / allowed_origins에서 명시적 TransportSecuritySettings(DNS 재바인딩/Origin 보허다)를 적용합니다. Loopback은 health check을 위해 항상 허용됩니다.

  • Deprecated endpoints: (credentials, credential_maps, stub_findings)는 차단합니다. 배포 시점에 disallowed-tool 허가목록(cohort)이 단언(assert)됩니다.

  • Audit(감시): 각 도구 발생 시마다 구조화된 JSON 이벤트 1개가 stderr로 기록됩니다(stdout 은 MCP 스트림입니다).

강화(Hardening)

대기의 GET 실패(429/502/503/504/타임아웃; Retry-After·HTTP-date 형식 존증)에 대해 bounded retry/backoff · 재시도는 쓰기와 4xx에는 하지 않음 · 프로세스 광역 동시성 Semaphore · 공유 Pool httpx client(요청 단위 인증, lifespan 종료 시 연결 닫음) · Token별 roles TTL cache. tests/test_hardening.py를 참고합니다.

Production deployment (dockerized, /mcp/)

전체 가이드는 **deploy/DEPLOY.md**를 참고하세요. 요약:

cd deploy
# Optional: set DOJO_NETWORK / DD_URL / DD_MCP_REPORTING_DB_DSN in a deploy/.env
# (docker compose reads ${...} env defaults; there is no committed .env template —
#  config lives in deploy/config.prod.yaml, bind-mounted at /app/config.yaml).
docker compose up -d --build
curl -s http://127.0.0.1:9900/healthz   # -> {"status":"ok","transport":"streamable-http"}

그 다음 호스트 nginx에 deploy/nginx-mcp.conflocation ~ ^/(mcp|sse|messages)를 추가하고 reload 하세요. 클라이언트는 각자 가진 Authorization: Token <token>(mcp-remote를 ↔해서) https://dojo.example.com/mcp/에 연결합니다. 컨테이너는 내부에서0.0.0.0:9000으로 바인딩되며, 호스트에서는 127.0.0.1:9900으로만 공개되고, DefectDojo에는 내부적으로 http://nginx:8080으로 접근합니다. 운영 구성에서는 쓰기 및 DB history 도구 그룹을 enabled하지만(enable_write_tools/ enable_db_tools), 쓰기는 여전히 확인 게이트를 거치며 DB 도구는 REST API로 사전 허가(백엔드) 를 받습니다 — DEPLOY.md 참고.

Local develop

Phase 0 — live schema 먼저 확인

DD_URL=https://dojo.internal DD_API_TOKEN=xxxx ./scripts/check_schema.sh

필요한 컨텐츠 엔드포인트가 존재하는지 확인하고, deprecated된 것들을 표시합니다. src/defectdojo_mcp/tools/*의 DRF 필터 룩업(lookup)은 DefectDojo 2.58.4 source와 대조 확인된 상황입니다 — 실제 라이브 스키마에서는 여기서 다시 확인하세요.

Install & Run

pip install -e ".[dev]"
cp config.example.yaml config.yaml          # edit base_url
# stdio reads the token from the DD_API_TOKEN env var (and DD_URL) directly — no .env file.

# stdio (single user / desktop client)
DD_URL=https://dojo.internal DD_API_TOKEN=xxxx DD_MCP_CONFIG=config.yaml defectdojo-mcp

# streamable-http (multi-user; token per-request). Set mcp.allowed_hosts for a 0.0.0.0 bind.
DD_MCP_TRANSPORT=streamable-http DD_MCP_HOST=0.0.0.0 DD_MCP_PORT=9000 defectdojo-mcp
# endpoint: http://<host>:9000/mcp   health: http://<host>:9000/healthz

Claude Desktop (stdio)

{
  "mcpServers": {
    "defectdojo": {
      "command": "defectdojo-mcp",
      "env": {
        "DD_URL": "https://dojo.internal",
        "DD_API_TOKEN": "your-token",
        "DD_MCP_CONFIG": "/path/to/config.yaml"
      }
    }
  }
}

Test

pytest          # 140 tests: redaction/sanitize, params, paging, auth+validator, context,
                # server gating, intelligence scoring, source resolution, writes, history,
                # hardening (retry/pool/semaphore/cache)
ruff check .

설정

주요 config.yaml knobs (config.example.yaml/deploy/config.prod.yaml 참고):

  • mcp.transport (stdio | streamable-http), mcp.host/port

  • mcp.enable_write_roles, mcp.enable_db_tools — 기본 꺼짐 그룹의 게이트

  • mcp.enable_dns_rebinding_protection, mcp.allowed_hosts, mcp.allowed_origins

  • security.redact_secrets, omit_user_pii, require_confirmation_for_writes

  • limits.max_concurrent_api_calls, max_retries, max_evidence_chars, roles_cache_ttl_seconds

  • database.enabled, dsn_env, allowed_views (Phase 3: reporting DB)

확장성 / 발견

모든 도구는 ToolAnnotations를 포함합니다(readOnlyHint/idempotentHint/title; 쓰기는 non-read-only). enum 파라미터는 enum을 공개하며; list 도구에는 Page 출력 schema가 type-safe로 정의; 서버는 instructions를 표시합니다. 프롬프트는 제목 + documented된 인자를 가집니다. 도구는 (module, predicate) 레지스트 /server.py로 등록합니다(각 그룹 단일 default-off게이트). ServerContext.execute() / execute_db_gated() / execute_write()를 지나 토큰 검증, 출력 변환, 로그, 오류 매핑이 일원화됩니다.

License

GNU Affero General Public License v3.0 only (AGPL-3.0-only). 전체 text is at LICENSE.

(Copyright (C) 2026 Zeeshan Sultan.)

Security

보안 취약점, 보안 관련 문제는 공개 이슈로 올리지 말고 SECURITY.md의 절차에 따라 비공개로 보고해 주세요.

이 서버는 ShadowDSO와 함께 구축된, DefectDojo를 system of record로 사용하는 별도-대역 보안 스캔 플랫폼입니다. 이 서버는 독립적으로 동작하며 그 프로젝트에 의존하지 않습니다.

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Enables triage of SAST findings by exposing a read-only MCP server with tools to access hash-verified source-to-sink code slices, unguarded sinks, and layered enrichment for local LLM analysis.
    10
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables security agents to interact with the Kuroko web security testing platform through MCP, providing access to traffic history, site graph entities, findings, and scan jobs with read-only defaults and scoped, approved tools for testing operations.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables authorized bug bounty automation via a scope-enforced MCP bridge, supporting web, secrets, mobile, and LLM red-team scanning, with reporting and advisory.
    MIT

View all related MCP servers

Related MCP Connectors

  • Read-only MCP access to sessions, funnels, campaigns, errors, live visitors, and anomalies.

  • Remote MCP for A2A caller identity, scope policy, verdict receipts, and audit history.

  • 34 production API tools over one hosted MCP endpoint.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ZeeshanSultan/DefectDojo-MCP-Server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server