Spotter-SAST
Related Servers
Alternatives to Spotter-SAST
No user-submitted related servers found.
Related Servers
- AlicenseBqualityDmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.6MIT
- AlicenseNot gradedqualityBmaintenanceStandalone MCP server that provides security scanning, project mapping, and vulnerability fix generation to AI coding assistants.27 npm2MIT
- AlicenseAqualityDmaintenanceMCP server that scans Salesforce Agentforce metadata for security vulnerabilities using 61+ SAST rules, integrating into AI coding workflows to guard against OWASP LLM top 10 risks.1618 npmCryptographic Autonomy 1.0 (Combined Work Exception)
- FlicenseNot gradedqualityDmaintenanceMCP server for automated architectural mapping, security vulnerability detection, ML asset tracking, and code metrics in local repositories.-
- AlicenseNot gradedqualityCmaintenanceMCP server that provides AI coding assistants with access to call graphs, data flows, and security analysis for multi-file vulnerability detection.139Apache 2.0
- AlicenseAqualityDmaintenanceUnified MCP server integrating NIST and OWASP security frameworks with live vulnerability data, enabling security searches, compliance mapping, threat modeling, and checklist generation.4114MIT
TDQS
Scored across 23 tools
Several tools overlap or are redundant, especially legacy tools (auto_fix_file, generate_sast_report, scan_directory, scan_file) that are explicitly superseded. The compliance tools are numerous and have subtle distinctions, while the echo tool is unrelated to the domain. Agents may struggle to select the correct tool.
Tool names predominantly follow a verb_noun convention using snake_case, e.g., ai_enhanced_auto_fix, collect_compliance_evidence. A few names start with a noun (compliance_analytics_dashboard) breaking the pattern slightly, but overall consistency is high.
23 tools is high for a security scanner, especially with 4 legacy tools that could be removed. The domain (SAST + compliance) is broad, but the count feels slightly bloated. The echo tool seems unnecessary.
The tool set covers scanning, vulnerability info, reporting, compliance management, remediation, and monitoring. Minor gaps: no direct tool for user/team management, and legacy tools might cause confusion. Overall, core workflows are well-covered.