Back to Browse

Security Mcp Marketplace MCP Server

Developer ToolsLow Risk9.9MCP RegistryRemote
Free

Server data from the Official MCP Registry

The DLP MCP provides the compliance violation in the one drive, google drive documents.

About

The DLP MCP provides the compliance violation in the one drive, google drive documents.

Remote endpoints: streamable-http: https://{api_host}/api/dlp/mcp/{tenant_id}

Security Report

9.9
Low Risk9.9Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

Endpoint verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-cx-anand-nandeshwar-dlp-mcp": {
      "url": "https://{api_host}/api/dlp/mcp/{tenant_id}"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

DLP MCP Server

License

A production-ready Model Context Protocol (MCP) server that connects AI coding assistants to DLP One — enabling real-time security scanning, vulnerability management, and AI-generated remediation directly inside your IDE or AI agent.

Table of Contents

Overview

The DLP Security MCP server bridges your AI assistant (Claude, Cursor, Copilot, etc.) with DLP One's enterprise application security platform. It exposes security workflows as natural-language-accessible MCP tools, allowing developers to scan code, investigate findings, and receive context-aware fixes without leaving their development environment.

Supported scan engines:

  • SAST — Static Application Security Testing (30+ languages)
  • SCA — Software Composition Analysis (open-source dependencies)
  • KICS — Infrastructure as Code security (Terraform, CloudFormation, Kubernetes, Dockerfile)
  • Secret Detection — Hardcoded credentials, API keys, tokens

Supported transport protocols

Multi-protocol support to facilitate secure and efficient communication between clients and the server:

  • stdio: Standard input/output for CLI or embedded agents
  • sse (Server-Sent Events): For real-time streaming to web-based clients
  • httpstreamableHttp: HTTP-compatible protocol for stream-based messaging

Features

CategoryCapabilities
ScanningPlan, trigger, and monitor multi-engine security scans (CLI or API mode)
FindingsList, filter, and inspect vulnerabilities with severity and state tracking
RemediationAI-generated fixes for code vulnerabilities, insecure packages, and container images
Project ManagementCreate, configure, and search DLP One projects
Application ManagementGroup projects into applications and get org-wide security metrics
AnalyticsTenant-wide vulnerability summaries, risk scores, and time-windowed trends
Supply ChainDetect malicious npm/Maven/PyPI/Go/NuGet packages via Dustico integration
Enterprise AuthJWT (JWKS-verified), OAuth2 token exchange, Redis session caching
ObservabilityStructured logging (zerolog), OpenTelemetry tracing

Authentication

The server uses API Key and OAuth2 authentication.

API Key Authentication

  1. Clients authenticate to DLP One and get an API key.
  2. This API key will be used during MCP client configuration, include the API Key in the Authorization header as mentioned in the MCP Client Configuration section.

OAuth2 Authentication

DLP MCP supports Dynamic Client Registration (DCR) flow allows an AI client (such as Cursor or Claude Desktop) to connect securely.

  1. User only needs to configure the MCP client as mentioned in the MCP Client Configuration section.
  2. When the client attempts to connect to the MCP server, it will be redirected to DLP One login page for authentication.
  3. Once authentication is successful with valid DLP credentials, the MCP client can use the tools provided by the MCP server.

Note: You required valid DLP credentials to get the API Key or connect to the MCP server.

Refer Authentication for detailed authentication instructions and troubleshooting.

MCP Client Configuration

Prerequisites

  • A DLP One tenant
  • DLP API Host
  • API Key (with required access if using API key authentication)

JSON Configuration

Below are examples to add the server to your MCP client configuration. See the examples/ folder for ready-to-use client config files.

Cursor IDE

API Key Authentication:

{
  "mcpServers": {
    "DLP": {
      "url": "https://{api_host}/api/security-mcp/mcp/{tenant}",
      "headers": {
        "cx-origin": "Curosr",
        "Authorization": "API_KEY"
      }
    }
  }
}

OAuth2 Authentication

{
  "mcpServers": {
    "DLP": {
      "url": "https://{api_host}/api/security-mcp/mcp/{tenant}"
    }
  }
}
Claude Desktop / Claude Code

API Key Authentication:

{
  "mcpServers": {
    "DLP": {
      "type": "http",
      "url": "https://{api_host}/api/security-mcp/mcp/{tenant}",
      "headers": {
        "Authorization": "<API_KEY>"
      }
    }
  }
}

Available Tools

Refer usage for detail information.

Scanning

ToolDescription
planScanRecommend scan engines based on the project
triggerScanStart a scan (CLI for local code, API for repository URL)
getScanDetailsGet scan status, progress, and severity summary
getLatestScansRetrieve recent scans for a project
listScansList scans with status, date, and branch filters
listFindingsList vulnerabilities from a scan with severity filtering
getFindingDetailsGet detailed information for a specific finding

Project management

ToolDescription
resolveProjectLook up a project by name
createProjectCreate a new DLP One project
listProjectsBrowse or search all projects
getProjectConfigGet full project configuration

Application management

ToolDescription
listApplicationsBrowse or search applications
createApplicationCreate a new application
getApplicationDetailsGet application details by ID
associateProjectLink projects to an application

Analytics & risk

ToolDescription
listProjectsOverviewHigh-level project security status
getProjectsOverviewAggregateOrganization-wide project metrics
getApplicationsOverviewAggregateOrganization-wide application metrics
getTenantVulnerabilitiesSummaryTime-windowed vulnerability analytics
getRiskSummaryOverall risk assessment
listRiskResultsRisk findings with filtering
updateRiskResultStatusUpdate finding status (CONFIRMED, URGENT, NOT_EXPLOITABLE, …)

Remediation

ToolDescription
codeRemediationAI-generated fixes for SAST findings, secrets, and IaC misconfigurations
packageRemediationSafe upgrade paths for vulnerable open-source packages
imageRemediationSecure base image alternatives for vulnerable container images

License

Apache 2.0 — see LICENSE for details.

Contributing

See CONTRIBUTING.md for development setup, module architecture, and contribution guidelines.

Website: DLP.

© 2026 DLP Ltd. All Rights Reserved.

Reviews

No reviews yet

Be the first to review this server!