com.offensive360/o360-mcp
Run Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes
Open source Open in the app JSON README (API)
About
Run Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes
Details
- Kind
- MCP servers
- Topic
- No topic detected
- Publisher
- com.offensive360
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 1.0.2
- Last push
- 2026-08-02T13:26:05Z
- Repository state
- ativo
- Language
- JavaScript
- License
- MIT
- Added
- 2026-08-29 03:01:17
- Updated
- 2026-08-29 03:01:17
- Origin id
com.offensive360/o360-mcp
README
# Offensive360 MCP Server
Run [Offensive360](https://offensive360.com) SAST scans from inside your AI assistant.
This [Model Context Protocol](https://modelcontextprotocol.io) server gives Claude Code,
Claude Desktop, Cursor, and any other MCP client two tools:
| Tool | What it does |
|---|---|
| `o360_scan_path` | Zips a local directory, runs a full SAST scan (60+ languages, taint/data-flow analysis), returns findings with file/line, severity, and fixes |
| `o360_scan_status` | Queue position of a running scan |
Ask your assistant things like *"scan this project with Offensive360 and fix the criticals"* —
it scans, reads the findings, and starts patching.
## Setup
You need an Offensive360 **External scan token**:
- **Open-source / public repos:** free — request one at
[offensive360.com/free-for-open-source](https://offensive360.com/free-for-open-source/)
- **Commercial:** any admin of your instance can create one under **Settings → Tokens**
### Claude Code
```bash
claude mcp add offensive360 \
-e O360_URL=https://sast.offensive360.com \
-e O360_TOKEN=<your-token> \
-- npx -y o360-mcp
```
### Claude Desktop / Cursor (JSON)
```json
{
"mcpServers": {
"offensive360": {
"command": "npx",
"args": ["-y", "o360-mcp"],
"env": {
"O360_URL": "https://sast.offensive360.com",
"O360_TOKEN": "<your-token>"
}
}
}
}
```
`O360_URL` can point at your own on-premise or air-gapped instance — the server
talks only to the instance you configure.
## Notes
- Scans are synchronous; typical duration is 1–5 minutes depending on codebase size.
The default client timeout is 900s (`timeout_seconds` parameter to override).
- Common junk directories (`node_modules`, `.git`, `dist`, …) are excluded from the
upload automatically; add more via the `exclude` parameter.
- Findings are also visible in your Offensive360 dashboard with full data-flow traces.
- Requires Node 18+.
## About Offensive360
One platform for SAST, DAST, MAST, SCA, malware & binary analysis, and license
compliance — flat pricing, cloud or fully air-gapped on-premise.
[offensive360.com](https://offensive360.com) · [Book a demo](https://offensive360.com/demo/)