Offensive360 MCP Server
Officialby offensive360
README.md
# Offensive360 MCP Server
Run [Offensive360](https://offensive360.com) SAST scans from inside your AI assistant.
This [Model Context Protocol](https://modelcontextprotocol.io) server gives Claude Code,
Claude Desktop, Cursor, and any other MCP client two tools:
| Tool | What it does |
|---|---|
| `o360_scan_path` | Zips a local directory, runs a full SAST scan (60+ languages, taint/data-flow analysis), returns findings with file/line, severity, and fixes |
| `o360_scan_status` | Queue position of a running scan |
Ask your assistant things like *"scan this project with Offensive360 and fix the criticals"* —
it scans, reads the findings, and starts patching.
## Setup
You need an Offensive360 **External scan token**:
- **Open-source / public repos:** free — request one at
[offensive360.com/free-for-open-source](https://offensive360.com/free-for-open-source/)
- **Commercial:** any admin of your instance can create one under **Settings → Tokens**
### Claude Code
```bash
claude mcp add offensive360 \
-e O360_URL=https://sast.offensive360.com \
-e O360_TOKEN=<your-token> \
-- npx -y o360-mcp
```
### Claude Desktop / Cursor (JSON)
```json
{
"mcpServers": {
"offensive360": {
"command": "npx",
"args": ["-y", "o360-mcp"],
"env": {
"O360_URL": "https://sast.offensive360.com",
"O360_TOKEN": "<your-token>"
}
}
}
}
```
`O360_URL` can point at your own on-premise or air-gapped instance — the server
talks only to the instance you configure.
## Notes
- Scans are synchronous; typical duration is 1–5 minutes depending on codebase size.
The default client timeout is 900s (`timeout_seconds` parameter to override).
- Common junk directories (`node_modules`, `.git`, `dist`, …) are excluded from the
upload automatically; add more via the `exclude` parameter.
- Findings are also visible in your Offensive360 dashboard with full data-flow traces.
- Requires Node 18+.
## About Offensive360
One platform for SAST, DAST, MAST, SCA, malware & binary analysis, and license
compliance — flat pricing, cloud or fully air-gapped on-premise.
[offensive360.com](https://offensive360.com) · [Book a demo](https://offensive360.com/demo/)
TDQS
A3.9/5.0
Scored across 2 tools
Disambiguation5/5
The two tools have clearly distinct purposes: one initiates a scan and another checks its queue status. There is no overlap or ambiguity in their functions.
Naming Consistency5/5
Both tools follow the same 'o360_scan_' prefix followed by a noun, creating a consistent and predictable naming pattern.
Tool Count3/5
With only two tools, the set feels thin. The scope is narrowly focused on scanning and status, but the count is at the borderline of being too minimal.
Completeness2/5
The set covers initiating a scan and checking status, but lacks operations like retrieving results for finished scans, cancelling scans, or listing past scans. This creates a significant gap for users who need to manage scans over time.
Maintenance
ActivitySlowing
ResponsivenessNo issues