An MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.LOG_LEVEL— "": "info",MCP_PORT— "": "3000",OSV_DB_PATHOSV_SCANNER_PATH— osv-scannerSECURITY_STRICT_MODE— "": "true"SNYK_API_URLSNYK_TOKENSONARQUBE_TOKENSONARQUBE_URL— (si usas SonarQube)TRIVY_CACHE_DIR— /tmp/trivy-cacheTRIVY_DB_PATHTRIVY_PATHVERACODE_API_IDVERACODE_API_KEYZAP_API_KEYZAP_URL— (si usas OWASP ZAP en modo API; por defecto se usa Docker)[](https://m8ven.ai/mcp/jesusdavidquarksoft-mcp-security-16zsv0)