Contrast Security

Contrast Security

Brings Contrast's vulnerability and SCA data into your coding agent to quickly remediate vulnerabilities.

11
Stars
5
Forks
15
Releases

Overview

The Contrast MCP Server connects Contrast Security data to an AI coding agent, enabling automatic remediation of vulnerabilities, updates to insecure third-party libraries, and on-demand analysis of security coverage. It leverages vulnerability data from Contrast Assess and Contrast SCA insights to identify at-risk libraries and guide remediation through natural language prompts. Users can request remediation directly from vulnerability reports, query which libraries are vulnerable or unused, and instruct the agent to update to safe versions. The server surfaces security metadata such as route coverage, ADR/Protect findings, and other security configurations to the AI assistant for informed decision making. It supports deployment via Docker or a Java JAR, and provides proxy configuration and SSL trust settings. Integration paths are available for popular IDEs and AI assistants (e.g., VS Code Copilot, IntelliJ Copilot). The README also offers sample prompts for developers and security professionals, installation guides, and data privacy considerations, highlighting the importance of protecting sensitive vulnerability data when using AI services.

Details

Owner
Contrast-Security-OSS
Language
Java
License
Apache License 2.0
Updated
2025-12-07

Features

Remediate vulnerabilities from Contrast Assess data

Remediate vulnerabilities directly based on Contrast Assess findings via natural language prompts to the AI agent.

Insecure library remediation with Contrast SCA insights

Identify and update vulnerable or unused libraries using Contrast SCA data.

On-demand security metadata review

Review route coverage, ADR/Protect findings, and other security metadata for applications on demand.

AI-assisted integration

Seamless integration with AI coding assistants (e.g., VS Code Copilot, IntelliJ Copilot) to drive remediation through prompts.

Flexible deployment options

Deploy via Docker or Java JAR, with proxy and TLS trust configuration options.

Preconfigured installation paths for popular IDEs

One-click VS Code installation and IntelliJ configuration guide to enable Copilot workflows.

Audience

DevelopersRemediate vulnerabilities and manage libraries via natural language prompts in code projects.
Security ProfessionalsAnalyze vulnerabilities, route coverage, ADR/Protect findings, and security metadata via prompts.

Tags

vulnerability remediationSCAContrast SecurityAI coding assistant integrationroute coverageADR/Protect findingssecurity metadatadata privacyDockerJava JAR deployment