Install
mcp_config.json
{
"mcpServers": {
"com-checkmarx-checkmarx": {
"url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant_id}",
"type": "streamable-http"
}
}
}Documentation
Checkmarx Agentic AI Checkmarx application security, built for AI coding agents.
Report Bug
·
Request Feature
Table of Contents
Overview
Checkmarx Security MCP
Developer Assist Plugins
Checkmarx One CLI
Documentation
Contributing
License
Feedback
Contact
Overview
AI coding assistants generate code quickly, but that code can carry the same security risks as code written by hand. This repository connects Checkmarx One — Checkmarx's application security platform — to those assistants, so generated code is scanned for vulnerabilities as it's written, not after the fact.
This repository ships two complementary ways to bring Checkmarx One into an AI-assisted workflow. Use them together or separately — they solve different halves of the problem.
- Checkmarx Security MCP — a hosted MCP server any MCP-capable assistant can call to scan, inspect findings, and apply AI remediation on demand.
- Developer Assist plugins — fail-closed gates that scan scannable file writes before they land on disk, for Claude Code, Cursor, GitHub Copilot CLI, Codex CLI, and Gemini CLI.
| Piece | What it does | When to use it |
|---|---|---|
| Checkmarx Security MCP | Tools the assistant can call — scan a project, inspect findings, apply AI remediation | You want on-demand scanning and fix-it workflows in any MCP client |
| Developer Assist plugins | A fail-closed gate — scannable file writes are scanned before they land on disk | You want the check to be automatic and non-optional |
The plugins wrap the Checkmarx One CLI (ast-cli) (cx) for install, authentication, and native hook scanning, and they start the same MCP server for remediation.
Checkmarx Security MCP
A hosted MCP server that connects any MCP-capable AI client — Claude, Cursor, Copilot, Windsurf, Kiro — to Checkmarx One. It exposes scanning, findings, project management, and AI-generated remediation as tools your assistant can call in conversation.
Configure it once (see examples/ for per-client config) and ask.
Details → README-MCP.md
Cursor: MCP-only install
plugins/cx-cursor-plugin is a lightweight Cursor marketplace plugin that registers the Checkmarx MCP server only — no hook chain, no file-write gate, just the MCP tools. Use it when you want Checkmarx MCP tools in Cursor without adopting the Developer Assist gate.
Details → plugins/cx-cursor-plugin/README.md
Developer Assist Plugins
Each plugin provides the same fail-closed security gate, wired in as a native hook for its client. Before the agent writes or edits a scannable file, the Checkmarx cx CLI scans the proposed content — real vulnerabilities are blocked rather than silently allowed, as is the case where the scanner itself can't be trusted to run. Shell commands are never gated. Findings are remediated through the bundled Checkmarx MCP server. Marketplace install and guided cx setup follow the same pattern across clients; only the client integration differs.
| Plugin | Client | Details |
|---|---|---|
cx-devassist | Claude Code | plugins/cx-devassist/README.md |
cursor-devassist | Cursor | plugins/cursor-devassist/README.md |
copilot-devassist | GitHub Copilot CLI | plugins/copilot-devassist/README.md |
codex-devassist | Codex CLI | plugins/codex-devassist/README.md |
| Root extension | Gemini CLI | docs/gemini-cli-devassist.md |
Checkmarx One CLI
The plugins install and drive the Checkmarx One CLI (cx) from Checkmarx/ast-cli. That CLI wraps Checkmarx One APIs for scans, authentication, and the native agent-hook scanners (ASCA, KICS, SCA).
Releases and platform downloads: ast-cli releases.
Documentation: Checkmarx One CLI tool.
Documentation
- README-MCP.md — MCP server overview, auth, and client config
- docs/usage.md — MCP tool catalog and example workflows
- docs/authentication.md — API key and OAuth2 setup
- docs/troubleshooting.md — connection, auth, and scan issues
- docs/gemini-cli-devassist.md — Gemini CLI extension install, hooks, and skills
- CONTRIBUTING.md — how to contribute
Contributing
We appreciate feedback and contributions. Before you get started, please see:
- Checkmarx contribution guidelines
- Code of Conduct
- SECURITY.md — report a vulnerability
License
Distributed under the Apache 2.0 license. It governs everything in this repository, including the MCP server and all plugins.
Feedback
We'd love to hear your feedback! If you come across a bug or have a feature request, please let us know by submitting an issue in GitHub Issues.
Contact
Checkmarx One Integrations Team
Project Link: https://github.com/Checkmarx/cx-agentic-ai.
Website: Checkmarx.
© 2026 Checkmarx Ltd. All Rights Reserved.
Sourced from the repository README.
More in AI & Agents
- PonytailMakes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.109,599
- AgentsMulti-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, and Google Antigravity39,079
- Frontend SlidesCreate beautiful slides on the web using a coding agent's frontend skills28,060
- Agent Skills Search ServerSearch and discover Agent Skills from the skills.sh registry. Powered by HAPI MCP server.25,980
- Agency Agents Zh🎭 267 个即插即用的 AI 专家角色 — 支持 Hermes Agent/Claude Code/Cursor/Copilot 等 18 种工具,覆盖工程/设计/营销/金融等 20 个部门。含 52 个中国市场原创智能体(小红书/抖音/微信/飞书/钉钉等)。搭配编排器 agency-orchestrator,一句话即可让多位专家按 DAG 自动协作。19,868
- Watermarks RemoverStrip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD17,822