# HCL AppScan MCP for AI Agents AI Agent Connect

> HCL AppScan MCP. Manage security scans and vulnerabilities directly from your AI client. Track application security issues, monitor live DAST scans, and audit your security inventory without switching tabs.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_mYfPAvMiXfAXuaYYaGV3n5T9Sji2RICkXrcN7Ich/ai-agent-connect
- **Tags:** application-security, security-testing, vulnerability-management, code-auditing, threat-detection, devsecops

## Description

The HCL AppScan MCP connects your security testing data to your AI client. It's a different way to handle application security by pulling information directly from your HCL AppScan on Cloud (ASoC) environment. Instead of jumping between different browser tabs and manually exporting results into spreadsheets, you don't have to do the heavy lifting anymore. You can just ask your agent to find the most critical issues. It handles the monitoring of your active scans and checks the status of new tests in real time. If you need to start a new dynamic analysis for a web application, you can do it right from your chat interface. It also lets you see which local agents are available for your internal network scans. You can quickly summarize your current security posture or pull specific details on a single vulnerability to share with your team. By connecting this through Vinkius, you get a central way to keep your security inventory organized without managing separate connections for every tool. You get a clear view of what needs fixing first without the manual overhead of navigating complex dashboards every day. This makes it much easier to stay on top of your security goals while keeping your focus on development. You can move from identifying a vulnerability to understanding its impact in a few seconds, rather than spending an hour digging through logs.

## Tools

### get_account_check
Confirm your connection to HCL AppScan is active and working. This ensures your agent has the right access to pull your data.

### get_app
Fetch specific metadata for a single application in your inventory. This is useful for getting unique IDs or basic app details.

### get_issue
Get the full details of a specific security vulnerability. Use this to see the exact nature of a bug and its severity level.

### get_scan
Check the current status and results of a specific security scan. This helps you monitor real-time progress without leaving your interface.

### get_account_info
Pull the basic details of the authenticated user account. Use this to verify which user profile the agent is currently using.

### list_apps
See every application currently registered in your security inventory. This helps you quickly find the right app to audit or scan.

### list_issues
Pull a list of all vulnerabilities found for a specific application. Use this to identify which security bugs need to be fixed first.

### list_presence
View the local agents available for scanning your internal apps. This shows you which hardware is ready to run your tests.

### list_scans
View a history of all scans performed within your account. Use this to track past results and historical security data.

### start_dast_scan
Kick off a new dynamic analysis scan for a target web application. This lets you start new security tests directly from the chat.

## Prompt Examples

**Prompt:** 
```
What's the status of our security scans for the main website?
```

**Response:** 
```
I've checked the current scan status for your main website. Here is the summary:

| Scan ID | Target | Status | Completion |
| :--- | :--- | :--- | :--- |
| **scan_8821** | `https://portal.example.com` | **In Progress** | 65%
| **scan_7740** | `https://api.example.com` | **Completed** | 100%

Would you like me to pull the full results for the completed scan?
```

**Prompt:** 
```
Are there any high-severity issues on our mobile API?
```

**Response:** 
```
I've pulled the vulnerabilities for the Mobile API. I found **3 high-severity issues** that need attention:

*   **SQL Injection** (Critical) - Found in the `/user/login` endpoint.
*   **Cross-Site Scripting (XSS)** (High) - Found in the `/profile/update` field.
*   **Insecure Direct Object Reference** (High) - Affects the `/messages` endpoint.

I can pull the full details for any of these if you'd like.
```

**Prompt:** 
```
Can you start a scan for the new staging URL?
```

**Response:** 
```
I've successfully started a new DAST scan for the staging environment.

*   **Target URL:** `https://staging.example.com`
*   **Scan ID:** `scan_99210`
*   **Status:** Initializing

I'll monitor the progress for you. Just ask me for an update anytime.
```

## Capabilities

### Check account connection
Verify that your connection to HCL AppScan is active and authorized.

### Summarize security issues
Pull lists of vulnerabilities for specific applications to see what needs fixing.

### Start dynamic analysis scans
Kick off new DAST scans for web applications directly from your chat.

### Monitor scan progress
Check the real-time status of active security tests and completed scans.

### Audit application inventory
List and search all applications currently in your security inventory.

### Identify local scanning agents
See which local presences are available for scanning your internal systems.

## Use Cases

### Summarizing high-risk bugs
A security engineer asks their agent to find all high-severity issues for the 'Payment Gateway'. The agent uses list_issues to pull the data and presents a prioritized to-do list.

### Triggering scans during deployment
A DevSecOps engineer wants to run a test on a new staging URL. They ask the agent to start a DAST scan, which triggers start_dast_scan automatically.

### Audit proof for compliance
A compliance officer asks for a list of all scans performed in the last month. The agent uses list_scans to provide a historical report for the audit.

### Deep dive into a specific bug
A developer wants to know why a specific SQL injection was flagged. The agent uses get_issue to pull the exact details and reproduction steps for that vulnerability.

## Benefits

- Stop dashboard hopping by using list_apps to see your entire security inventory in one place.
- Identify critical risks faster with list_issues to see exactly what needs immediate attention.
- Automate scan initiation using start_dast_scan to keep your security testing consistent across deployments.
- Get real-time updates on testing progress with get_scan to avoid waiting on blind results.
- Audit your security posture quickly by pulling account and application data with get_account_info and get_app.
- Manage internal scanning hardware more easily by using list_presence to see active local agents.

## How It Works

The bottom line is you get a direct line from your chat interface to your security testing data.

1. Connect your HCL AppScan account credentials to the Connector via Vinkius.
2. Ask your AI client to list your applications or check for high-severity issues.
3. Receive a formatted summary of your security posture and active scan statuses.

## Frequently Asked Questions

**Does HCL AppScan MCP help with DAST scans?**
Yes, this Connector allows your AI client to start new dynamic analysis (DAST) scans and monitor their progress in real-time.

**Can I see all my applications in one list with HCL AppScan MCP?**
Yes, you can ask your agent to list every application currently registered in your security inventory for a quick overview.

**How do I find specific bugs using HCL AppScan MCP?**
You can ask your agent to list issues for a specific application. It will pull the vulnerabilities and summarize them for you.

**Does HCL AppScan MCP work with HCL AppScan on Cloud?**
Yes, it is specifically designed to connect with HCL AppScan on Cloud (ASoC) to manage your security posture.

**Can I start scans automatically with HCL AppScan MCP?**
Yes, your AI client can trigger new DAST scans directly through your chat interface whenever you need them.

**How do I know if my account is connected to HCL AppScan MCP?**
You can simply ask your agent to check your account connection status. It will verify that your connection is active and authorized.

**How do I get my AppScan API Key ID and Secret?**
Log in to the AppScan on Cloud console, go to your **User Profile** (top right), and select **API Keys**. You can generate a new Key ID and Key Secret there.

**Does this server support the EU region?**
Yes, you can configure the `APPSCAN_REGION` environment variable to `eu` to connect to the European data center (`eu.cloud.appscan.com`).

**Can I start a scan for an internal application?**
Yes, provided you have an AppScan Presence (local agent) configured. You can use the `list_presence` tool to check their availability before starting a scan.