Back to Browse

O360 MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Run Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes

About

Run Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes

Security Report

5.2
Moderate5.2Moderate Risk

Well-structured MCP server with proper authentication via token-based access and reasonable security practices. Token is correctly required and not hardcoded. Code quality is solid with appropriate input validation and error handling. Minor concerns around broad error messages and lack of explicit request timeout defaults do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

3 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Offensive360 instance base URLOptional

Environment variable: O360_URL

External scan token (free for public repos: https://offensive360.com/free-for-open-source/)Required

Environment variable: O360_TOKEN

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "com-offensive360-o360-mcp": {
      "env": {
        "O360_URL": "your-o360-url-here",
        "O360_TOKEN": "your-o360-token-here"
      },
      "args": [
        "-y",
        "o360-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Offensive360 MCP Server

Run Offensive360 SAST scans from inside your AI assistant. This Model Context Protocol server gives Claude Code, Claude Desktop, Cursor, and any other MCP client two tools:

ToolWhat it does
o360_scan_pathZips a local directory, runs a full SAST scan (60+ languages, taint/data-flow analysis), returns findings with file/line, severity, and fixes
o360_scan_statusQueue position of a running scan

Ask your assistant things like "scan this project with Offensive360 and fix the criticals" — it scans, reads the findings, and starts patching.

Setup

You need an Offensive360 External scan token:

Claude Code

claude mcp add offensive360 \
  -e O360_URL=https://sast.offensive360.com \
  -e O360_TOKEN=<your-token> \
  -- npx -y o360-mcp

Claude Desktop / Cursor (JSON)

{
  "mcpServers": {
    "offensive360": {
      "command": "npx",
      "args": ["-y", "o360-mcp"],
      "env": {
        "O360_URL": "https://sast.offensive360.com",
        "O360_TOKEN": "<your-token>"
      }
    }
  }
}

O360_URL can point at your own on-premise or air-gapped instance — the server talks only to the instance you configure.

Notes

  • Scans are synchronous; typical duration is 1–5 minutes depending on codebase size. The default client timeout is 900s (timeout_seconds parameter to override).
  • Common junk directories (node_modules, .git, dist, …) are excluded from the upload automatically; add more via the exclude parameter.
  • Findings are also visible in your Offensive360 dashboard with full data-flow traces.
  • Requires Node 18+.

About Offensive360

One platform for SAST, DAST, MAST, SCA, malware & binary analysis, and license compliance — flat pricing, cloud or fully air-gapped on-premise. offensive360.com · Book a demo

Reviews

No reviews yet

Be the first to review this server!