Why this server?
Enterprise-grade SAST server with multi-tool integration, compliance verification, AI-powered remediation, and multi-tenant management, directly aligning with Checkmarx's SAST capabilities.
AlicenseCqualityDmaintenanceEnterprise-grade MCP server for static application security testing with multi-tool integration, compliance verification, AI-powered remediation, and multi-tenant management.2310MITWhy this server?
Integrates Checkov, Semgrep, Bandit, and ASH for comprehensive code security analysis, offering a multi-tool approach akin to Checkmarx's SAST + SCA capabilities.

MCP Security Scannerofficial
AlicenseAqualityDmaintenanceIntegrates Checkov, Semgrep, Bandit, and ASH to provide comprehensive code security analysis for AI coding assistants.1515MIT No AttributionWhy this server?
Security scanning MCP server with Semgrep integration, SARIF parsing, baseline diffing, and automated finding triage, similar to Checkmarx's static analysis workflow.
Alicense-qualityDmaintenanceSecurity scanning MCP server. Semgrep integration, SARIF parsing, baseline diffing, framework-aware ruleset selection, and automated finding triage.121MITWhy this server?
Boosts security in the dev lifecycle via SAST, SCA, Secrets & IaC scanning, directly overlapping with Checkmarx's core SAST and SCA offerings.
Why this server?
Provides real-time security scanning superpowers including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment, mirroring Checkmarx's comprehensive security testing.

Cybrium MCP Serverofficial
Alicense-qualityBmaintenanceProvides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.159Apache 2.0Why this server?
Enables interaction with Veracode for SAST scans, SCA vulnerabilities, and CVE retrieval, similar to Checkmarx's platform for security testing and management.
Flicense-qualityDmaintenanceEnables interaction with the Veracode platform to perform security tasks like running SAST scans, checking SCA vulnerabilities, and retrieving CVE information. It allows AI assistants to manage scan workflows, from zipping source code to analyzing scan results through natural language.Why this server?
Performs runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance, resembling Checkmarx's multi-faceted security scanning approach.
AlicenseAqualityAmaintenanceSecurity scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.55215MITWhy this server?
Enables security scanning of codebases through integrated secret detection, SCA, SAST, and DAST vulnerabilities with AI-powered remediation, covering similar ground as Checkmarx.
Alicense-qualityBmaintenanceEnables security scanning of codebases through integrated tools for secret detection, SCA, SAST, and DAST vulnerabilities, with AI-powered remediation suggestions based on findings.MIT