Skip to main content

Contrast MCP server

The Contrast MCP server is a bridge between Contrast vulnerability data from our Interactive Application Security Testing (IAST) technology and an integrated development environment (IDE)-based AI agent. This bridge lets the agent identify vulnerable code and fix it from within the IDE. In addition to the vulnerability data itself, Contrast provides its curated remediation guidance to the AI agent. This ensures the AI agent has all the information it needs to get the fix right the first time.

Legal disclaimer

When using Contrast's MCP server, depending on the information you input, that information will be fed into your LLM. Both the submission of data to the LLM and the output generated by the LLM will be subject to the terms of service of that LLM. Use of Contrast's MCP server is entirely at your own risk.

Contrast MCP server benefits

Using the Contrast MCP server with an AI coding agent lets developers swiftly and precisely remediate vulnerabilities that Contrast detects. While this is one of the main use cases, the flexible nature of the MCP technology means you could ask an AI agent to do just about anything with your Contrast data. For example, you could ask it to:

  • Prioritize and fix vulnerable libraries in applications based on library usage data

  • Rapidly assess the impact of newly reported high-severity vulnerabilities across your applications

  • Quickly identify and remove unused libraries using runtime class usage data

  • Triage active attacks and open security incidents, and trace the issues and observations behind them

  • And more...

Data from the Contrast MCP server

The Contrast MCP server provides an MCP client and, by extension, the LLM, access to Contrast data across several product areas. Examples of the data you can access are:

Vulnerabilities (Assess)

  • Vulnerability type (for example, SQL injection, unsafe deserialization, or command injection)

  • Exact location in the code

  • The HTTP endpoint and HTTP request that triggered the vulnerability detection

  • Data flow through the application

  • User-controlled data that entered the vulnerable sink

  • Detailed instructions on how to fix the vulnerability

With this information, the coding agent that you prompt and guide can quickly and accurately remediate identified vulnerabilities.

Attacks (ADR/Protect)

  • Attack status (for example, exploited, blocked, or probed) and category

  • The rule or attack type that triggered detection (for example, SQL injection, XSS)

  • Source IP, application, and server involved in the attack

  • Protection rules configured for an application, so you can see what is actively defending it

Applications and servers

  • Applications filtered by tag or metadata

  • Session metadata available for an application

  • Server inventory, including agent version, environment, and Protect coverage

Libraries (SCA)

  • Libraries used by an application, with class usage statistics (zero usage means a library is likely not exploitable)

  • Vulnerability counts per library

  • Applications affected by a specific CVE

Coverage

  • Route coverage, showing exercised routes versus discovered routes for an application

Scans (SAST)

  • SAST project details and vulnerability counts

  • Raw SARIF scan results (local MCP server only)

Security issues and incidents

In addition to CVE Shield, the hosted MCP server provides tools for exploring security issues, incidents, and observations from the unified data platform in Northstar. These tools are available only on the hosted MCP server and require Northstar to be enabled for your organization.

Search and filter security issues

Search issues across your organization

search_issues

Get full issue details

See everything known about a specific issue

get_issue

See which incidents an issue belongs to

List incidents linked to an issue

list_issue_incidents

See which incidents an issue belongs to

List incidents linked to an issue

list_issue_incidents

Search and filter incidents

Search incidents across your organization

search_incidents

Get full incident details

See everything known about a specific incident

get_incident

See which issues an incident includes

List issues linked to an incident

list_incident_issues

Get full observation details

See the evidence behind a specific observation

get_observation

See the evidence behind an issue

List observations linked to an issue

list_issue_observations

See the evidence behind an incident

List observations linked to an incident

list_incident_observations

CVE Shield tools

Contrast MCP server tools also cover CVE Shield, the virtual patching layer that blocks exploitation of known CVEs at runtime. These three tools are available on the hosted MCP server only and require the Northstar unified data platform to be enabled for your organization:

Find CVEs across your organization

Filter by CVE ID, severity, CVSS score range, or affected application

search_cves

See which applications a CVE affects

Get the list of issues and corresponding applications impacted by a specific CVE and the status of each resulting issue

list_cve_issues

Get a full impact assessment for a CVE

See which applications are affected, which libraries carry the vulnerability, and whether CVE Shield is actively protecting each application. Coverage gaps are flagged automatically, so if an application has a vulnerable library but no active protection, your agent will tell you.

get_cve_impact

Contrast MCP server installation and use

To install and use the MCP server, go to MCP Server for Contrast Security on GitHub.

Sample prompts for developers

  • Remediate vulnerabilities in code

    • List vulnerabilities for Application Y

    • Give me details about vulnerability X on Application Y

    • Review vulnerability X and fix it

  • Remediate vulnerabilities in third-party libraries

    • Which libraries in Application X have High or Critical vulnerabilities and are also being actively used

    • Which libraries in Application X are not being used?

    • Update library X with a critical vulnerability to the safe version

  • Retrieving applications based on tags

    • Give me the applications that have the backend tag

  • Retrieving applications based on metadata

    • Give me the applications that have dev-team and backend-team applied as metadata

  • Retrieving vulnerabilities based on session metadata

    • Give me the session metadata for Application X

    • Give me the vulnerabilities in the latest session for Application X

    • Give me the vulnerabilities for session metadata Branch Name and feature for Application X

    • Give me the route coverage for the latest session for Application X

    • Give me the route coverage for session metadata Branch Name and feature for Application X

    • Give me the impact assessment for CVE-xxxx-xxxx, including any apps where CVE Shield is not covering a vulnerable library

  • Reviewing attack activity

    • Which vulnerabilities in Application X are being blocked by a Protect or ADR rule?

  • Reviewing scan results

    • Give me the SAST scan results for Application X

    • How many vulnerabilities does the latest scan project for Application X have?

Sample prompts for security teams

  • Give me a breakdown of applications and servers vulnerable to CVE-xxxx-xxxx

  • List the libraries for Application X and tell me what version of commons-collections is being used

  • Which vulnerabilities in Application X are being blocked by an ADR or Protect rule?

  • Which production servers do not have Protect enabled?

  • Show me servers whose agents are out of date

  • Show me attack events from the last 7 days and tell me which were exploited

  • Show me open security issues for Application X

  • Give me the details of incident X and the issues linked to it

  • What observations provide evidence for issue X?

Connect an AI agent to Contrast

The Contrast MCP server gives AI coding agents access to your Contrast security data, including vulnerabilities, libraries, routes, and attack activity. Two connection options are available depending on your deployment.

Hosted MCP server

Contrast runs this for you as a remote endpoint. You connect to it with OAuth, so there is nothing to install or maintain and no API keys to manage. This is the right choice for SaaS customers.

Local MCP server

You run this yourself as a local process. This is the right choice for enterprise on-premises (EOP) deployments or when you need to work with raw SARIF output.

Available tools by server: Most tools are available on both the hosted and local MCP servers. A few are specific to one:

  • Local server only: get_scan_results for raw SARIF scan output

  • Hosted server only: Sign-in identity lookup and the full set of issue, incident, observation, and CVE Shield tools (including the CVE Shield tools described above). These require Northstar to be enabled for your organization.

For the complete, current list of tools on each server, see the mcp-contrast README.

Review the mcp-contrast repository for installation instructions with an overview of both options, hosted setup guides by client, and the local server reference.