MCP server for Offensive360 — run SAST scans and read findings from Claude, Cursor, and other AI assistants.
claude mcp add mcp-server -- npx -y o360-mcp{
"mcpServers": {
"mcp-server": {
"command": "npx",
"args": ["-y", "o360-mcp"],
"env": {
"O360_URL": "<o360_url>",
"O360_TOKEN": "<o360_token>"
}
}
}
}O360_URLO360_TOKENMCP Servers overview
# Offensive360 MCP Server
Run [Offensive360](https://offensive360.com) SAST scans from inside your AI assistant.
This [Model Context Protocol](https://modelcontextprotocol.io) server gives Claude Code,
Claude Desktop, Cursor, and any other MCP client two tools:
| Tool | What it does |
|---|---|
| `o360_scan_path` | Zips a local directory, runs a full SAST scan (60+ languages, taint/data-flow analysis), returns findings with file/line, severity, and fixes |
| `o360_scan_status` | Queue position of a running scan |
Ask your assistant things like *"scan this project with Offensive360 and fix the criticals"* —
it scans, reads the findings, and starts patching.
## Setup
You need an Offensive360 **External scan token**:
- **Open-source / public repos:** free — request one at
[offensive360.com/free-for-open-source](https://offensive360.com/free-for-open-source/)
- **Commercial:** any admin of your instance can create one under **Settings → Tokens**
### Claude Code
```bash
claude mcp add offensive360 \
-e O360_URL=https://sast.offensive360.com \
-e O360_TOKEN=<your-token> \
-- npx -y o360-mcp
```
### Claude Desktop / Cursor (JSON)
```json
{
"mcpServers": {
"offensive360": {
"command": "npx",
"args": ["-y", "o360-mcp"],
"env": {
"O360_URL": "https://sast.offensive360.com",
"O360_TOKEN": "<your-token>"
}
}
}
}
```
`O360_URL` can point at your own on-premise or air-gapped instance — the server
talks only to the instance you configure.
## Notes
- Scans are synchronous; typical duration is 1–5 minutes depending on codebase size.
The default client timeout is 900s (`timeout_seconds` parameter to override).
- Common junk directories (`node_modules`, `.git`, `dist`, …) are excluded from the
upload automatically; add more via the `exclude` parameter.
- Findings are also visible in your Offensive360 dashboard with full data-flow traces.
- Requires Node 18+.
## About Offensive360
One platform for SAST, DAST, MAST, SCA, malware & binary analysis, and license
compliance — flat pricing, cloud or fully air-gapped on-premise.
[offensive360.com](https://offensive360.com) · [Book a demo](https://offensive360.com/demo/)
What people ask about mcp-server
What is offensive360/mcp-server?
+
offensive360/mcp-server is mcp servers for the Claude AI ecosystem. MCP server for Offensive360 — run SAST scans and read findings from Claude, Cursor, and other AI assistants. It has 0 GitHub stars and was last updated today.
How do I install mcp-server?
+
You can install mcp-server by cloning the repository (https://github.com/offensive360/mcp-server) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is offensive360/mcp-server safe to use?
+
offensive360/mcp-server has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.
Who maintains offensive360/mcp-server?
+
offensive360/mcp-server is maintained by offensive360. The last recorded GitHub activity is from today, with 0 open issues.
Are there alternatives to mcp-server?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy mcp-server to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/offensive360-mcp-server)<a href="https://claudewave.com/repo/offensive360-mcp-server"><img src="https://claudewave.com/api/badge/offensive360-mcp-server" alt="Featured on ClaudeWave: offensive360/mcp-server" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
The fastest path to AI-powered full stack observability, even for lean teams.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!