MCP低风险未认领

SAST MCP Server

11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations

Skyrxinskyrxin/sast-mcp-server★ 3更新于 2026年6月24日

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.Skyrxin/sast-mcp-server",
  "description": "11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations",
  "title": "SAST MCP Server",
  "repository": {
    "url": "https://github.com/Skyrxin/sast-mcp-server",
    "source": "github"
  },
  "version": "0.8.3",
  "websiteUrl": "https://github.com/Skyrxin/sast-mcp-server#readme",
  "packages": [
    {
      "registryType": "pypi",
      "registryBaseUrl": "https://pypi.org",
      "identifier": "sast-mcp-server",
      "version": "0.8.3",
      "runtimeHint": "uvx",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Per-scan timeout in seconds (default: 300).",
          "default": "300",
          "name": "SAST_MCP_TIMEOUT"
        },
        {
          "description": "Logging level: DEBUG, INFO, WARNING, ERROR (default: INFO).",
          "default": "INFO",
          "name": "SAST_MCP_LOG_LEVEL"
        },
        {
          "description": "Optional static API key to require auth (legacy mode; HTTP transports).",
          "isSecret": true,
          "name": "SAST_MCP_API_KEY"
        },
        {
          "description": "Optional HMAC secret to require JWT auth with scopes (HTTP transports).",
          "isSecret": true,
          "name": "SAST_MCP_JWT_SECRET"
        }
      ]
    }
  ]
}

权限

声明检测
运行代码—python
安装—pypi:sast-mcp-server@0.8.3
安装时运行脚本—无
网络无无
需要的凭据SAST_MCP_API_KEYSAST_MCP_JWT_SECRETSAST_MCP_API_KEYSAST_MCP_JWT_SECRET
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

版本

  1. #10.8.3最新2026年10月7日