Skip to main content
Glama
offensive360

Offensive360 MCP Server

Official
by offensive360
README.md
# Offensive360 MCP Server

Run [Offensive360](https://offensive360.com) SAST scans from inside your AI assistant.
This [Model Context Protocol](https://modelcontextprotocol.io) server gives Claude Code,
Claude Desktop, Cursor, and any other MCP client two tools:

| Tool | What it does |
|---|---|
| `o360_scan_path` | Zips a local directory, runs a full SAST scan (60+ languages, taint/data-flow analysis), returns findings with file/line, severity, and fixes |
| `o360_scan_status` | Queue position of a running scan |

Ask your assistant things like *"scan this project with Offensive360 and fix the criticals"* —
it scans, reads the findings, and starts patching.

## Setup

You need an Offensive360 **External scan token**:

- **Open-source / public repos:** free — request one at
  [offensive360.com/free-for-open-source](https://offensive360.com/free-for-open-source/)
- **Commercial:** any admin of your instance can create one under **Settings → Tokens**

### Claude Code

```bash
claude mcp add offensive360 \
  -e O360_URL=https://sast.offensive360.com \
  -e O360_TOKEN=<your-token> \
  -- npx -y o360-mcp
```

### Claude Desktop / Cursor (JSON)

```json
{
  "mcpServers": {
    "offensive360": {
      "command": "npx",
      "args": ["-y", "o360-mcp"],
      "env": {
        "O360_URL": "https://sast.offensive360.com",
        "O360_TOKEN": "<your-token>"
      }
    }
  }
}
```

`O360_URL` can point at your own on-premise or air-gapped instance — the server
talks only to the instance you configure.

## Notes

- Scans are synchronous; typical duration is 1–5 minutes depending on codebase size.
  The default client timeout is 900s (`timeout_seconds` parameter to override).
- Common junk directories (`node_modules`, `.git`, `dist`, …) are excluded from the
  upload automatically; add more via the `exclude` parameter.
- Findings are also visible in your Offensive360 dashboard with full data-flow traces.
- Requires Node 18+.

## About Offensive360

One platform for SAST, DAST, MAST, SCA, malware & binary analysis, and license
compliance — flat pricing, cloud or fully air-gapped on-premise.
[offensive360.com](https://offensive360.com) · [Book a demo](https://offensive360.com/demo/)

TDQS

A3.9/5.0

Scored across 2 tools

Disambiguation5/5

The two tools have clearly distinct purposes: one initiates a scan and another checks its queue status. There is no overlap or ambiguity in their functions.

Naming Consistency5/5

Both tools follow the same 'o360_scan_' prefix followed by a noun, creating a consistent and predictable naming pattern.

Tool Count3/5

With only two tools, the set feels thin. The scope is narrowly focused on scanning and status, but the count is at the borderline of being too minimal.

Completeness2/5

The set covers initiating a scan and checking status, but lacks operations like retrieving results for finished scans, cancelling scans, or listing past scans. This creates a significant gap for users who need to manage scans over time.

Maintenance

ActivitySlowing
ResponsivenessNo issues