Symbiotic MCP Server
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Symbiotic MCP Serverscan the src/index.js file for vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Symbiotic MCP Server
A Model Context Protocol (MCP) server for security analysis using Symbiotic CLI
Description
This server exposes security analysis tools via the MCP protocol for any MCP-compatible client. It allows scanning code and infrastructure files without affecting your workspace.
Available Tools
code_scan_files- Static code analysisinfra_scan_files- Infrastructure security scanningsecurity_scan_files- Comprehensive security scan (code + infrastructure)get_supported_languages- List of supported programming languages
Related MCP server: Security-Use MCP Server
Cursor Integration
Setting up the Security Review Command
Create a
.cursordirectory in your project root if it doesn't existCreate or update
.cursor/commands/security-review.mdwith the contents of security-review.md
Using the Command
Open the chat panel in Cursor (Cmd+L or Ctrl+L)
Type
/security-reviewfollowed by optional file paths or glob patternsThe command will perform a comprehensive security analysis, including:
Scanning selected files or the entire workspace
Analyzing for security vulnerabilities
Triaging findings and filtering false positives
Providing a detailed report with severity levels and remediation suggestions
Offering to apply automatic fixes for identified issues
Installation
Install symbiotic-cli
https://github.com/SymbioticSec/cli/releasesGet API token
Create an account on Symbiotic Security and retrieve your API token.
Build and start
Clone this repository and install dependencies:
npm install
npm run buildMCP Configuration
In VSCode, open MCP: Open User Configuration and add in servers:
{
"servers": {
"symbiotic-security": {
"command": "node",
"args": ["path/to/build/index.js"],
"env": {
"SYMBIOTIC_API_TOKEN": "your_token_here",
}
},
}Configuration for other MCP clients may vary but generally follows the same structure.
{
"mcpServers": {
"symbiotic-security": {
"command": "node",
"args": ["path/to/build/index.js"],
"env": {
"SYMBIOTIC_API_TOKEN": "your_token_here"
}
}
}
}Important environment variables:
SYMBIOTIC_API_TOKEN(required) - Your Symbiotic API token
Note: Configuration file name and location may vary depending on your MCP client.
Transport Modes
STDIO (default) - Standard communication for MCP
SSE - Server-Sent Events over HTTP
Streamable HTTP - HTTP with
/mcpendpoint
# STDIO (default)
node build/index.js
# HTTP server on port 9593
SERVER_PORT=9593 node build/index.jsAuthentication
The server requires a valid Symbiotic Security API token. Configuration is done via MCP environment variables.
Minimal required configuration:
"env": {
"SYMBIOTIC_API_TOKEN": "your_token_here"
}How It Works
Receives code files via MCP
Creates temporary files
Executes
symbiotic-cliAutomatic cleanup of temporary files
Returns formatted results
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/SymbioticSec/mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server