DefectDojo MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DEFECTDOJO_API_BASE | Yes | The base URL of your DefectDojo instance (e.g., https://your-defectdojo-instance.com) | |
| DEFECTDOJO_API_TOKEN | Yes | Your DefectDojo API token for authentication |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_findingsC | Get findings with filtering options and pagination support |
| search_findingsC | Search for findings using a text query with pagination support |
| update_finding_statusB | Update the status of a finding (Active, Verified, False Positive, Mitigated, Inactive) |
| add_finding_noteC | Add a note to a finding |
| create_findingD | Create a new finding |
| list_productsC | List all products with optional filtering and pagination support |
| list_engagementsC | List engagements with optional filtering and pagination support |
| get_engagementB | Get a specific engagement by ID |
| create_engagementD | Create a new engagement |
| update_engagementC | Update an existing engagement |
| close_engagementC | Close an engagement |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 11 tools
Each tool has a clearly distinct purpose targeting specific resources and actions, such as create_engagement vs. update_engagement, and get_findings vs. search_findings, with no overlapping or ambiguous functions.
All tool names follow a consistent verb_noun pattern using snake_case, such as create_engagement, list_products, and update_finding_status, with no deviations in style or convention.
With 11 tools, the server is well-scoped for defect management, covering key operations like engagements, findings, and products without being overly sparse or bloated.
The tool set provides strong CRUD/lifecycle coverage for engagements and findings, including create, get, update, and list operations, though minor gaps like product creation or deletion might require workarounds.