Contrast MCP server
The Contrast MCP server is a bridge between Contrast vulnerability data from our Interactive Application Security Testing (IAST) technology and an integrated development environment (IDE)-based AI agent. This bridge lets the agent identify vulnerable code and fix it from within the IDE. In addition to the vulnerability data itself, Contrast provides its curated remediation guidance to the AI agent. This ensures the AI agent has all the information it needs to get the fix right the first time.
Legal disclaimer
When using Contrast's MCP server, depending on the information you input, that information will be fed into your LLM. Both the submission of data to the LLM and the output generated by the LLM will be subject to the terms of service of that LLM. Use of Contrast's MCP server is entirely at your own risk.
Contrast MCP server benefits
Using the Contrast MCP server with an AI coding agent lets developers swiftly and precisely remediate vulnerabilities that Contrast detects. While this is one of the main use cases, the flexible nature of the MCP technology means you could ask an AI agent to do just about anything with your Contrast data. For example, you could ask it to:
Prioritize and fix vulnerable libraries in applications based on library usage data
Rapidly assess the impact of newly reported high-severity vulnerabilities across your applications
Quickly identify and remove unused libraries using runtime class usage data
Triage active attacks and open security incidents, and trace the issues and observations behind them
And more...
Data from the Contrast MCP server
The Contrast MCP server provides an MCP client and, by extension, the LLM, access to Contrast data across several product areas. Examples of the data you can access are:
Vulnerabilities (Assess)
Vulnerability type (for example, SQL injection, unsafe deserialization, or command injection)
Exact location in the code
The HTTP endpoint and HTTP request that triggered the vulnerability detection
Data flow through the application
User-controlled data that entered the vulnerable sink
Detailed instructions on how to fix the vulnerability
With this information, the coding agent that you prompt and guide can quickly and accurately remediate identified vulnerabilities.
Attacks (ADR/Protect)
Attack status (for example, exploited, blocked, or probed) and category
The rule or attack type that triggered detection (for example, SQL injection, XSS)
Source IP, application, and server involved in the attack
Protection rules configured for an application, so you can see what is actively defending it
Applications and servers
Applications filtered by tag or metadata
Session metadata available for an application
Server inventory, including agent version, environment, and Protect coverage
Libraries (SCA)
Libraries used by an application, with class usage statistics (zero usage means a library is likely not exploitable)
Vulnerability counts per library
Applications affected by a specific CVE
Coverage
Route coverage, showing exercised routes versus discovered routes for an application
Scans (SAST)
SAST project details and vulnerability counts
Raw SARIF scan results (local MCP server only)
Security issues and incidents
In addition to CVE Shield, the hosted MCP server provides tools for exploring security issues, incidents, and observations from the unified data platform in Northstar. These tools are available only on the hosted MCP server and require Northstar to be enabled for your organization.
Search and filter security issues | Search issues across your organization |
|
Get full issue details | See everything known about a specific issue |
|
See which incidents an issue belongs to | List incidents linked to an issue |
|
See which incidents an issue belongs to | List incidents linked to an issue |
|
Search and filter incidents | Search incidents across your organization |
|
Get full incident details | See everything known about a specific incident |
|
See which issues an incident includes | List issues linked to an incident |
|
Get full observation details | See the evidence behind a specific observation |
|
See the evidence behind an issue | List observations linked to an issue |
|
See the evidence behind an incident | List observations linked to an incident |
|
CVE Shield tools
Contrast MCP server tools also cover CVE Shield, the virtual patching layer that blocks exploitation of known CVEs at runtime. These three tools are available on the hosted MCP server only and require the Northstar unified data platform to be enabled for your organization:
Find CVEs across your organization | Filter by CVE ID, severity, CVSS score range, or affected application |
|
See which applications a CVE affects | Get the list of issues and corresponding applications impacted by a specific CVE and the status of each resulting issue |
|
Get a full impact assessment for a CVE | See which applications are affected, which libraries carry the vulnerability, and whether CVE Shield is actively protecting each application. Coverage gaps are flagged automatically, so if an application has a vulnerable library but no active protection, your agent will tell you. |
|
Contrast MCP server installation and use
To install and use the MCP server, go to MCP Server for Contrast Security on GitHub.
Sample prompts for developers
Remediate vulnerabilities in code
List vulnerabilities for Application Y
Give me details about vulnerability X on Application Y
Review vulnerability X and fix it
Remediate vulnerabilities in third-party libraries
Which libraries in Application X have High or Critical vulnerabilities and are also being actively used
Which libraries in Application X are not being used?
Update library X with a critical vulnerability to the safe version
Retrieving applications based on tags
Give me the applications that have the
backendtag
Retrieving applications based on metadata
Give me the applications that have
dev-teamandbackend-teamapplied as metadata
Retrieving vulnerabilities based on session metadata
Give me the session metadata for Application X
Give me the vulnerabilities in the latest session for Application X
Give me the vulnerabilities for session metadata
Branch Nameandfeaturefor Application XGive me the route coverage for the latest session for Application X
Give me the route coverage for session metadata
Branch Nameandfeaturefor Application XGive me the impact assessment for CVE-xxxx-xxxx, including any apps where CVE Shield is not covering a vulnerable library
Reviewing attack activity
Which vulnerabilities in Application X are being blocked by a Protect or ADR rule?
Reviewing scan results
Give me the SAST scan results for Application X
How many vulnerabilities does the latest scan project for Application X have?
Sample prompts for security teams
Give me a breakdown of applications and servers vulnerable to CVE-xxxx-xxxx
List the libraries for Application X and tell me what version of commons-collections is being used
Which vulnerabilities in Application X are being blocked by an ADR or Protect rule?
Which production servers do not have Protect enabled?
Show me servers whose agents are out of date
Show me attack events from the last 7 days and tell me which were exploited
Show me open security issues for Application X
Give me the details of incident X and the issues linked to it
What observations provide evidence for issue X?
Connect an AI agent to Contrast
The Contrast MCP server gives AI coding agents access to your Contrast security data, including vulnerabilities, libraries, routes, and attack activity. Two connection options are available depending on your deployment.
Hosted MCP server
Contrast runs this for you as a remote endpoint. You connect to it with OAuth, so there is nothing to install or maintain and no API keys to manage. This is the right choice for SaaS customers.
Local MCP server
You run this yourself as a local process. This is the right choice for enterprise on-premises (EOP) deployments or when you need to work with raw SARIF output.
Available tools by server: Most tools are available on both the hosted and local MCP servers. A few are specific to one:
Local server only:
get_scan_resultsfor raw SARIF scan outputHosted server only: Sign-in identity lookup and the full set of issue, incident, observation, and CVE Shield tools (including the CVE Shield tools described above). These require Northstar to be enabled for your organization.
For the complete, current list of tools on each server, see the mcp-contrast README.
Review the mcp-contrast repository for installation instructions with an overview of both options, hosted setup guides by client, and the local server reference.