73
/ 100
17 days ago
glama

rijul170/qualys-mcp

A Model Context Protocol server for full Qualys portal management — expose VMDR, Policy Compliance, WAS, Cloud Agent, Container Security, TotalCloud, Patch Management, CSAM/GAV, EASM and administration to any MCP‑capable client.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: QUALYS_PASSWORD, QUALYS_MCP_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configQUALYS_PLATFORMexport ='US2' # or set QUALYS_API_URL / QUALYS_GATEWAY_URL
configQUALYS_API_URLexport QUALYS_PLATFORM='US2' # or set / QUALYS_GATEWAY_URL
configQUALYS_GATEWAY_URLexport QUALYS_PLATFORM='US2' # or set QUALYS_API_URL /
configQUALYS_USERNAMEexport ='api-user'
🔐 secretQUALYS_PASSWORDexport ='api-pass'
configQUALYS_REQUESTED_WITH
configQUALYS_CONSOLE_LABELNames the console in logs and the server name
configQUALYS_TIMEOUT
configQUALYS_MAX_RETRIES
configQUALYS_MCP_TRANSPORT
configQUALYS_MCP_MODULESComma‑separated allowlist to scope a console to its licensed modules
configQUALYS_MCP_HOST
configQUALYS_MCP_PORT
🔐 secretQUALYS_MCP_API_KEYOptional shared secret for the HTTP transport
configQUALYS_MCP_STATELESS_HTTP
configQUALYS_ENABLE_DESTRUCTIVEunless the console runs with =true.
configQUALYS_DEBUG
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/rijul170-qualys-mcp-g7hgrr)](https://m8ven.ai/mcp/rijul170-qualys-mcp-g7hgrr)
commit: edee0e1766a235b89d401a097a8c0b005aa257fe
code hash: b0cd5650628881807d63008b4c3cb174d89c9e25a47144b5fab42dd8ee6cd8cc
verified: 7/14/2026, 8:35:29 AM
view raw JSON →