Why this server?
Enterprise-grade SAST server with multi-tool integration, compliance verification, AI-powered remediation, and multi-tenant management, directly aligning with Checkmarx's SAST capabilities.
AlicenseCqualityDmaintenanceEnterprise-grade MCP server for static application security testing with multi-tool integration, compliance verification, AI-powered remediation, and multi-tenant management.Last updated2310MITWhy this server?
Provides static code analysis using Joern's Code Property Graph for 12+ languages, including security analysis, taint flow detection, and CPGQL queries, similar to Checkmarx's deep code analysis.
Alicense-qualityAmaintenanceProvides static code analysis using Joern's Code Property Graph technology for 12+ programming languages. Enables security analysis, code browsing, taint flow detection, and CPGQL queries through natural language.Last updated127GPL 3.0Why this server?
Integrates Checkov, Semgrep, Bandit, and ASH for comprehensive code security analysis, offering a multi-tool approach akin to Checkmarx's SAST + SCA capabilities.

MCP Security Scannerofficial
Alicense-qualityCmaintenanceIntegrates Checkov, Semgrep, Bandit, and ASH to provide comprehensive code security analysis for AI coding assistants.Last updated14MIT No AttributionWhy this server?
Security scanning MCP server with Semgrep integration, SARIF parsing, baseline diffing, and automated finding triage, similar to Checkmarx's static analysis workflow.
-license-quality-maintenanceSecurity scanning MCP server. Semgrep integration, SARIF parsing, baseline diffing, framework-aware ruleset selection, and automated finding triage.Last updated1Why this server?
Provides security scanning of code snippets and codebases via the Asterisk security API for real-time vulnerability analysis, comparable to Checkmarx's scanning focus.

Asterisk MCP Serverofficial
Alicense-qualityDmaintenanceProvides security scanning of code snippets, codebases, and code changes via the Model Context Protocol, connecting to the Asterisk security API for real-time vulnerability analysis.Last updated34Apache 2.0Why this server?
Boosts security in the dev lifecycle via SAST, SCA, Secrets & IaC scanning, directly overlapping with Checkmarx's core SAST and SCA offerings.
Why this server?
Provides real-time security scanning superpowers including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment, mirroring Checkmarx's comprehensive security testing.

Cybrium MCP Serverofficial
Alicense-qualityAmaintenanceProvides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.Last updated17Apache 2.0Why this server?
Enables interaction with Veracode for SAST scans, SCA vulnerabilities, and CVE retrieval, similar to Checkmarx's platform for security testing and management.
Flicense-qualityDmaintenanceEnables interaction with the Veracode platform to perform security tasks like running SAST scans, checking SCA vulnerabilities, and retrieving CVE information. It allows AI assistants to manage scan workflows, from zipping source code to analyzing scan results through natural language.Last updatedWhy this server?
Performs runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance, resembling Checkmarx's multi-faceted security scanning approach.
AlicenseAqualityAmaintenanceSecurity scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.Last updated552MIT