Skip to main content
Glama
raviraj-ntp

armorcode-mcp

by raviraj-ntp
README.md
# ArmorCode MCP

Local MCP server for **ArmorCode** — finding triage, scans, exceptions, risk scores, and release gate checks.

---

## Quick start

```json
{
  "mcpServers": {
    "armorcode": {
      "command": "npx",
      "args": ["-y", "@raviraj87/armorcode-mcp"],
      "env": {
        "ARMORCODE_URL": "https://your-tenant.armorcode.com",
        "ARMORCODE_API_TOKEN": "your-api-token"
      }
    }
  }
}
```

`ARMORCODE_WRITE_ENABLED` is **optional** — omit it for safe defaults (write tools preview only).

---

## Environment variables

| Variable | Required | Description |
|----------|----------|-------------|
| `ARMORCODE_URL` | Yes | Tenant base URL |
| `ARMORCODE_API_TOKEN` | Yes | API token from Manage → Integrations → API |
| `ARMORCODE_WRITE_ENABLED` | No | Set `true` to apply writes with `dryRun: false` |

---

## Tools (v1.0)

### Findings
| Tool | Purpose |
|------|---------|
| `armorcode_search_findings` | Search/filter findings |
| `armorcode_get_finding` | Full finding detail |
| `armorcode_get_finding_events` | Audit trail |
| `armorcode_get_findings_stats` | Counts by severity/status |
| `armorcode_get_severity_stats` | Severity breakdown |

### Status & comments (write, dry-run default)
| Tool | Purpose |
|------|---------|
| `armorcode_confirm_finding` | OPEN → CONFIRMED |
| `armorcode_control_finding` | → CONTROLLED |
| `armorcode_block_finding` | Block via accept-risk |
| `armorcode_accept_risk` | Accept risk |
| `armorcode_mark_false_positive` | False positive |
| `armorcode_reopen_finding` | Reopen |
| `armorcode_triage_finding` | → TRIAGE |
| `armorcode_mitigate_finding` | → MITIGATED |
| `armorcode_suppress_finding` | Suppress |
| `armorcode_add_comment` | Add note |
| `armorcode_add_exploitability_comment` | Structured exploitability |
| `armorcode_update_finding_severity` | Change severity |

### Products & risk
| Tool | Purpose |
|------|---------|
| `armorcode_list_products` | List products/groups |
| `armorcode_list_subproducts` | List subproducts |
| `armorcode_get_product_risk_score` | Product risk |
| `armorcode_get_subproduct_risk_score` | Subproduct risk |
| `armorcode_get_all_product_risk_scores` | All products |

### Scans & exceptions
| Tool | Purpose |
|------|---------|
| `armorcode_list_scans` | List scans |
| `armorcode_get_scan` | Scan details |
| `armorcode_execute_scan` | Trigger scan |
| `armorcode_trigger_scan_pull` | PULL tool scheduler (Black Duck, etc.) |
| `armorcode_list_scan_schedulers` | List schedulers |
| `armorcode_delete_scan_scheduler` | Clean up scheduler |
| `armorcode_list_exceptions` | Open exceptions |
| `armorcode_get_exception` | Exception detail |
| `armorcode_create_exception` | Create risk register entry |
| `armorcode_release_gate_status` | Jenkins release gate check |

### Escape hatch
| Tool | Purpose |
|------|---------|
| `armorcode_health` | Connectivity check |
| `armorcode_api` | Any GET/POST/PUT/DELETE path |

---

## Dev

```bash
cd armorcode-mcp
npm install
npm run build
ARMORCODE_URL=... ARMORCODE_API_TOKEN=... npm run test:readonly
```

## License

MIT — Copyright © 2026 Ravi Raj

TDQS

C2.5/5.0

Scored across 37 tools

Disambiguation4/5

Most tools have clearly distinct purposes, especially for findings where each action (accept, confirm, mitigate, etc.) targets a specific status. However, the sheer number of finding-related tools (15+) could cause some confusion, particularly between armorcode_accept_risk and armorcode_block_finding, though descriptions clarify.

Naming Consistency5/5

All tools follow the consistent pattern of 'armorcode_verb_noun' with underscores, using predictable verbs like get, list, add, create, delete, search, etc. The naming is uniform and easy to understand across the entire set.

Tool Count2/5

With 37 tools, the count is well above typical well-scoped MCP servers (3-15) and exceeds the 25+ threshold for 'too many'. While the ArmorCode domain may have many operations, the tool surface feels overly granular, with many separate tools that could be parameterized.

Completeness4/5

The tool set covers the core ArmorCode workflows: findings (CRUD-like status changes, tagging, comments), scans, products, exceptions, and risk scores. Missing operations like deleting findings or updating products are minor gaps that do not severely hinder common use cases, especially with the armorcode_api escape hatch.

Maintenance

ActivityStale
ResponsivenessNo issues