Offensive360 MCP Server
Run Offensive360 SAST scans from inside your AI assistant. This Model Context Protocol server gives Claude Code, Claude Desktop, Cursor, and any other MCP client two tools:
| Tool | What it does |
|---|---|
o360_scan_path | Zips a local directory, runs a full SAST scan (60+ languages, taint/data-flow analysis), returns findings with file/line, severity, and fixes |
o360_scan_status | Queue position of a running scan |
Ask your assistant things like "scan this project with Offensive360 and fix the criticals" — it scans, reads the findings, and starts patching.
Setup
You need an Offensive360 External scan token:
- Open-source / public repos: free — request one at offensive360.com/free-for-open-source
- Commercial: any admin of your instance can create one under Settings → Tokens
Claude Code
claude mcp add offensive360 \
-e O360_URL=https://sast.offensive360.com \
-e O360_TOKEN=<your-token> \
-- npx -y o360-mcp
Claude Desktop / Cursor (JSON)
{
"mcpServers": {
"offensive360": {
"command": "npx",
"args": ["-y", "o360-mcp"],
"env": {
"O360_URL": "https://sast.offensive360.com",
"O360_TOKEN": "<your-token>"
}
}
}
}
O360_URL can point at your own on-premise or air-gapped instance — the server
talks only to the instance you configure.
Notes
- Scans are synchronous; typical duration is 1–5 minutes depending on codebase size.
The default client timeout is 900s (
timeout_secondsparameter to override). - Common junk directories (
node_modules,.git,dist, …) are excluded from the upload automatically; add more via theexcludeparameter. - Findings are also visible in your Offensive360 dashboard with full data-flow traces.
- Requires Node 18+.
About Offensive360
One platform for SAST, DAST, MAST, SCA, malware & binary analysis, and license compliance — flat pricing, cloud or fully air-gapped on-premise. offensive360.com · Book a demo