Adversary MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ADVERSARY_LLM_MODEL | No | LLM model to use | |
| ADVERSARY_LOG_LEVEL | No | Log level for the application | INFO |
| ADVERSARY_LLM_PROVIDER | No | LLM provider (e.g., openai, anthropic) | |
| ADVERSARY_CACHE_SIZE_MB | No | Cache size in megabytes | 200 |
| ADVERSARY_WORKSPACE_ROOT | No | Path to the project workspace root | |
| ADVERSARY_MAX_CONCURRENT_SCANS | No | Maximum number of concurrent scans | 8 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| adv_scan_fileB | Scan a file for security vulnerabilities using Clean Architecture. Automatically uses session-aware analysis when LLM is configured. |
| adv_scan_folderB | Scan a directory for security vulnerabilities using Clean Architecture. Automatically uses session-aware project analysis when LLM is configured. |
| adv_scan_codeB | Scan code content for security vulnerabilities using Clean Architecture. Automatically uses session-aware analysis with project context when available. |
| adv_get_statusB | Get comprehensive server status including session management capabilities, active sessions, and cache statistics |
| adv_get_versionB | Get server version information |
| adv_mark_false_positiveC | Mark a finding as a false positive |
| adv_unmark_false_positiveB | Remove false positive marking from a finding |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 7 tools
Each tool has a clearly distinct purpose with no ambiguity. The three scanning tools (code, file, folder) target different input types, while status/version tools serve administrative functions and false positive tools handle annotation management. There is no functional overlap between tools.
All tools follow a perfect 'adv_verb_noun' pattern with consistent snake_case throughout. The naming convention is highly predictable, making it easy for agents to understand tool purposes from their names alone.
Seven tools is an excellent number for this security scanning domain. The set covers core scanning operations (code/file/folder), administrative functions (status/version), and annotation management (mark/unmark false positives) without being overwhelming or sparse.
The tool surface covers the essential security scanning workflow well, including scanning different input types and managing false positives. A minor gap exists in result retrieval/management tools - there's no way to list, filter, or export findings beyond the scanning operations themselves, but agents can work around this limitation.