The Context-Switching Crisis
Every DevSecOps engineer knows the “Dashboard Jump.” You are deep in a coding session, perhaps fixing a logic error in Cursor or refining a feature in VS Code. Suddenly, a notification hits your Slack or email about a new vulnerability found in your production environment.
What happens next is predictable and exhausting. You stop coding. You navigate to the HCL AppScan dashboard. You log in. You hunt through application inventories to find the right ID. You click through menus to see if it’s a false positive. You manually trigger a new scan. By the time you get back to your IDE, your “flow” is gone.
This mental tax, the cognitive load of moving between development and security context, is more than just an annoyance. It creates a visibility gap. When security testing feels like a separate, manual chore, it gets done less frequently. This friction is exactly what leads to delayed remediation and unpatched vulnerabilities.
Bridging the Gap with HCL AppScan MCP
The solution isn’t to spend more time in dashboards; it is to bring the dashboard to your editor. The HCL AppScan MCP server changes the relationship between your AI assistant and your security posture.
By connecting HCL AppScan to an AI client like Claude Desktop, Cursor, or Windsurf via Vinkius Edge, you turn your chat interface into a security command center. You no longer need to “go check” the dashboard. Instead, you ask your agent about it.
Through Vinkius, your AI assistant gains access to your AppScan inventory, scan statuses, and vulnerability details through a single, unified connection point. No more managing complex API keys in your local environment or manually exporting CSVs from the cloud console. Your agent becomes an active participant in your security workflow.
Natural Language Auditing in Action
The real power of this integration is how it transforms complex queries into simple conversations. Instead of navigating complex UI trees, you use natural and easy language to audit your applications.
Imagine you are working on a critical API and want to know its current risk level. You don’t need to hunt for the AppID manually; you can simply ask.
Querying Vulnerabilities
You can start by listing all applications in your inventory to find the one you need:
## Prompt: Ask your AI agent (Claude or Cursor)
"List all applications in my AppScan inventory."
Once you have identified the application, you can drill down into specific security issues without ever leaving your IDE. If you suspect a recent change might have introduced a regression, you can query for high-severity findings:
## Prompt: Directly querying for critical issues
"Show me high severity issues for application 'Customer Portal'."
The agent retrieves the data through the list_issues tool, providing an immediate summary of SQL injection, XSS, or other critical vulnerabilities. You get the context you need exactly when you are working on the code that matters.
Automating Remediation Workflows
Discovery is only half the battle. The real value lies in the ability to move from discovery to remediation instantly.
In a traditional workflow, finding a vulnerability is just the beginning of a long manual chain. With the HCL AppScan MCP server, that chain is shortened significantly. If your agent identifies an issue via get_issue, you can immediately command it to verify the fix with a new scan.
Triggering DAST Scans
Let’s say you have just patched a potential cross-site scripting vulnerability. You want to ensure the patch is effective before you even commit the code.
## Prompt: Initiating a new DAST scan via chat
"Start a new DAST scan for appId '12345' with URL 'https://portal.example.com'."
The agent uses the start_dast_scan tool to trigger the process in HCL AppScan on Cloud (ASoC). You can then monitor the progress of this scan by asking about its status. This creates a tight, automated loop: identify, verify, and remediate; all within your development environment.
One thing to note: for scanning internal applications that are not publicly accessible, you must ensure you have an AppScan Presence (local agent) configured. You can use the list_presence tool to check which agents are available before attempting a scan.
Security at the Speed of Development
This approach is the embodiment of “Shift Left” security. Traditionally, shifting left meant giving developers more tools, which often just meant giving them more work. By using an MCP server, you are not adding a new tool to their belt; you are augmenting the tools they already use.
By integrating security into the AI-driven development loop, you achieve several critical goals:
- Reduced Time-to-Remediation: The gap between finding a bug and starting a verification scan shrinks from hours to seconds.
- Increased Visibility: Security becomes a continuous background process rather than a periodic manual audit.
- Lower Cognitive Load: Developers stay in their IDE, maintaining focus and productivity.
The security dashboard is becoming an API, not a destination. Modern DevSecOps requires moving away from manual dashboarding toward AI-driven, automated security auditing.
Setup in Seconds
Connecting your HCL AppScan environment to your AI assistant via Vinkius is designed to be frictionless. You don’t need to write complex integration code or manage sensitive credentials locally.
- Get your Credentials: Log in to your HCL AppScan on Cloud console and retrieve your API Key ID and Secret.
- Configure Vinkius: Use the Vinkius dashboard to set up your connection.
- Connect your Client: Use your personal Connection Token to point your AI client (Cursor, Claude Desktop, etc.) to the Vinkius Edge URL.
The full setup instructions and the ability to subscribe to the HCL AppScan MCP server can be found in the App Catalog.
All your connections are managed through Vinkius Edge, which handles the routing and authentication securely. You get full visibility into every tool execution via the Guardian Control Plane, ensuring you always know exactly what your agents are doing with your security data.
Analyze with AI
Send this article directly to your preferred AI to analyze concepts, extract actionable insights, or seamlessly integrate into your own projects.
Connect AI agents to your entire stack.
Browse ready-to-use MCP servers. Paste one URL to connect live databases, APIs, and business tools instantly.