Skip to main content
Glama
bhayanak

Qualys MCP Server

by bhayanak
README.md
<p align="center">
  <img src="logo.png" alt="Qualys MCP Server" width="300" height="300" />
</p>

<h1 align="center">Qualys MCP Server</h1>

<p align="center">
  MCP server enabling AI assistants to interact with the Qualys vulnerability management platform.
</p>

<p align="center">
  <img src="https://img.shields.io/badge/license-MIT-blue.svg" alt="License: MIT" />
  <img src="https://img.shields.io/badge/node-%3E%3D20-green.svg" alt="Node.js >= 20" />
  <img src="https://img.shields.io/badge/MCP-compatible-purple.svg" alt="MCP Compatible" />
  <img src="https://img.shields.io/badge/tools-7-orange.svg" alt="7 Tools" />
</p>

---

## Overview

A TypeScript MCP server that gives AI assistants (Claude, GitHub Copilot, Cursor) access to the Qualys platform. Investigate CVEs, assess risk, check compliance, plan remediation, and generate reports — all through natural language.

### Capabilities

| Category | What the AI Can Do |
|---|---|
| **Investigation** | Deep-dive any CVE, threat actor, host, IP, or free-text topic |
| **Risk Assessment** | Cross-domain risk: VMs, cloud (AWS/Azure/GCP), web apps, certificates |
| **Compliance** | PCI, HIPAA, CIS, NIST, SOC2 posture checking |
| **Remediation** | Patch priorities, deployment status, mitigation coverage |
| **Security Overview** | Daily/weekly/monthly security briefing |
| **Reports** | Generate, list, download Qualys reports |

## Packages

| Package | Description |
|---|---|
| [`qualys-mcp-server`](packages/qualys-mcp-server/) | Standalone MCP server (npm, CLI) |
| [`qualys-mcp-vscode-extension`](packages/qualys-mcp-vscode-extension/) | VS Code extension with auto-registration |

## Quick Start

### Option 1: VS Code Extension

1. Install extension from visual studio marketplace
2. Configure settings: `Cmd+,` → search "Qualys MCP"
3. Set username, password, and POD
4. The server appears automatically in the MCP Servers panel

### Option 2: Standalone (Claude Desktop, Cursor)

```bash
npx qualys-mcp-server
```

Or add to your MCP config:

```json
{
  "mcpServers": {
    "qualys": {
      "command": "npx",
      "args": ["-y", "qualys-mcp-server"],
      "env": {
        "QUALYS_MCP_USERNAME": "your-username",
        "QUALYS_MCP_PASSWORD": "your-password",
        "QUALYS_MCP_POD": "US1"
      }
    }
  }
}
```

## Tools

| Tool | Description |
|---|---|
| `qualys_investigate` | Deep-dive CVE, host, IP, or threat actor |
| `qualys_assess_risk` | Cross-domain risk assessment |
| `qualys_check_compliance` | Compliance posture for PCI/HIPAA/CIS/NIST/SOC2 |
| `qualys_plan_remediation` | Patch priorities and mitigation planning |
| `qualys_security_overview` | Security briefing (daily/weekly/monthly) |
| `qualys_reports` | Report management (list/generate/download/status) |
| `qualys_cache_status` | View and clear API response cache |

## Development

```bash
pnpm install
pnpm run ci       # typecheck + lint + format + test:coverage
pnpm run build    # Build all packages
pnpm run package  # Build VSIX
```

## License

MIT

Maintenance

ActivityInactive
ResponsivenessNo issues