Vinkius
Checkmarx

Checkmarx MCP. Diagnose Flaws and Pinpoint the Perfect Fix Spot.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Checkmarx MCP on Cursor AI Code Editor MCP Client Checkmarx MCP on Claude Desktop App MCP Integration Checkmarx MCP on OpenAI Agents SDK MCP Compatible Checkmarx MCP on Visual Studio Code MCP Extension Client Checkmarx MCP on GitHub Copilot AI Agent MCP Integration Checkmarx MCP on Google Gemini AI MCP Integration Checkmarx MCP on Lovable AI Development MCP Client Checkmarx MCP on Mistral AI Agents MCP Compatible Checkmarx MCP on Amazon AWS Bedrock MCP Support

Just plug in your AI agents and start using Vinkius.

Checkmarx One MCP automates Application Security testing for deep code analysis. Trigger full SAST/SCA scans across any project container, pull vulnerability data down to the exact line of code, and identify optimal patch locations without leaving your chat window.

What your AI agents can do

Cancel scan

Stops an actively running Checkmarx scan when new code commits overlap or resource usage is unnecessary.

Get kics results

Retrieves specialized findings focused only on misconfigurations in Infrastructure as Code (Terraform, Dockerfiles, Kubernetes YAML).

Get project

Fetches specific metadata details for a designated Checkmarx project.

+ 7 more capabilities included
Run Targeted Scans

Trigger SAST/SCA security checks on specific code branches to test for vulnerabilities.

Inventory Codebases

List all applications and projects within your environment, getting a full map of your codebase containers.

Triage Vulnerability Data

Pull structured vulnerability findings, including severity and the exact line number where a flaw exists.

Determine Best Fix Location (BFL)

Calculate the precise optimal spot in your code to apply a patch that resolves a specific security flaw entirely.

Check Infrastructure Code

Get specialized metrics on misconfigurations found in Terraform, Dockerfiles, or Kubernetes YAML files (KICS).

Supported MCP Clients

OAuth 2.0 Compatible
Vinkius runs on Claude Claude
Vinkius runs on ChatGPT ChatGPT
Vinkius runs on Cursor Cursor
Vinkius runs on Gemini Gemini
Vinkius runs on VS Code VS Code
Vinkius runs on JetBrains JetBrains
Vinkius runs on Vercel Vercel
Vinkius runs on Zendesk Zendesk
+ other MCP clients
Free for Subscribers

Waiting for input…

AI Agent

Checkmarx: 10 Tools for Security Management

Manage your entire AppSec workflow with these tools, covering everything from listing applications to finding the perfect patch location.

Make your AI actually useful.

Add this MCP to Claude, Cursor, or Windsurf and your AI stops guessing. It gets real tools to look things up, take action, and handle the stuff you keep doing by hand.

Start using Checkmarx on Vinkius
cancel019d756e

cancel scan

Stops an actively running Checkmarx scan when new code commits overlap or resource usage is unnecessary.

get019d756e

get kics results

Retrieves specialized findings focused only on misconfigurations in Infrastructure as Code (Terraform, Dockerfiles, Kubernetes YAML).

get019d756e

get project

Fetches specific metadata details for a designated Checkmarx project.

get019d756e

get scan details

Checks the precise status and configuration of an existing scan, including which engines ran and when they failed.

get019d756e

get scan results

Downloads structured SAST/security vulnerability findings for a completed scan ID, noting severity and code line number.

list019d756e

list applications

Lists all high-level applications that act as containers for multiple microservices within Checkmarx One.

list019d756e

list bfl

Determines the Best Fix Location (BFL) by providing a specific scan ID and rule identifier string.

list019d756e

list projects

Provides a list of all individual codebases managed within Checkmarx One, including their metadata.

list019d756e

list scans

Retrieves historical and current scan records for a project, showing the ID, status, branch, and time stamps.

run019d756e

run scan

Triggers a new Checkmarx One code scan, useful in CI/CD pipelines to test security quality on pull requests.

Choose How to Get Started

Build a custom MCP for your own tools, or connect a ready-made integration from our catalog.

Build Your Own

Turn any API into an MCP. Import a spec, define Agent Skills, or deploy with MCPFusion.

  • Import from OpenAPI, Swagger, or YAML specs
  • Create Agent Skills with progressive disclosure
  • Deploy to edge with MCPFusion framework
  • Built in DLP, auth, and compliance on every call
  • Real time usage dashboard and cost metering
  • Publish to catalog or keep private
Start building

Make Your AI Do More

Start with Checkmarx, then connect any of our 4,800+ other servers whenever your AI needs more. One click, no limits.

  • Use this MCP plus 4,800+ others, all in one place
  • Add new capabilities to your AI anytime you want
  • Every connection is secured and compliant automatically
  • Track usage and costs across all your servers
  • Works with Claude, ChatGPT, Cursor, and more
  • New servers added to the catalog every week
Checkmarx MCP server cover

Independent Platform Disclaimer: Vinkius is an independent platform and is not affiliated with, endorsed by, sponsored by, verified by, or otherwise authorized by Checkmarx. All third-party trademarks, logos, and brand names are the property of their respective owners. Their use on this website is strictly for informational purposes to identify service compatibility and interoperability.

VINKIUS INFRASTRUCTURE

Cloud Hosted

Managed infra

V8 Isolated

Sandboxed per request

Zero-Trust Proxy

No stored credentials

DLP Enforced

Policy on every call

GDPR Compliant

EU data residency

Token Compression

~60% cost reduction

Your data is protected. See how we built it.

Works with Claude, ChatGPT, Cursor, and more

The Model Context Protocol standardizes how applications expose capabilities to LLMs. Instead of operating in isolation, your AI gains direct access to external platforms, live data, and real-world actions through secure, standardized connections.

This server provides 10 capabilities that interface natively with Claude, ChatGPT, Cursor, and any MCP client. No middleware. No custom integration required.

Navigating Checkmarx's Dashboard Maze

Right now, figuring out a vulnerability requires jumping between the main dashboard, the project view, and the specific scan results tab. You click to see the flaw, then you copy the ID, then you switch tabs to check its severity, and finally, you open another window just to look up the recommended fix.

With this MCP, those manual jumps disappear. The agent handles the context switching for you. You ask it about a vulnerability, and it pulls all the necessary details—the location, the severity, the potential infrastructure overlap—and gives you one clean answer.

Pinpointing Vulnerabilities with `list_bfl`

The hardest part is that once an AppSec report shows a flaw at line 142, the fix might actually be three files away. You waste time guessing which parameter or function needs sanitization.

Using `list_bfl` changes that entirely. Give it the specific scan ID and the rule ID, and it calculates the one optimal spot to put your patch. It's surgical precision for remediation.

What you can do with this MCP connector

This connector lets you take programmatic control over your entire application security posture using Checkmarx One. Instead of clicking through complex cyber dashboards, you talk to your agent about code flaws—and it handles the heavy lifting. You can list all active projects and applications in your codebase containers, then trigger full scans on specific branches or pull existing scan data for immediate review.

The real value comes when you need to connect this security check to other systems; through Vinkius, you can chain the vulnerability findings from this MCP with a ticketing system, automating the process of assigning remediation tasks and tracking status updates across multiple platforms. You get deep visibility into what every agent is doing via Vinkius AI Analytics—nothing happens in the dark when running scans or pulling results.

Built · Hosted · Managed by Vinkius Checkmarx MCP - Automate AppSec Code Scanning Server ID 019d756e-34c4-7303-b2e4-d79b36281968
Vinkius Inspector
Compliance Grade F
Score 3.6/100
Vinkius Inspector Badge — Score 3.6/100

Common Questions About Checkmarx MCP

How do I get vulnerability data using `get_scan_results`? +

You need a completed scan ID and then you call get_scan_results. This pulls the structured findings, including severity and the exact lines of code where the flaw was detected.

I want to check misconfigurations in my Kubernetes YAML. Which tool should I use? +

Use get_kics_results. This tool specifically focuses on Infrastructure as Code findings, isolating issues in K8s YAML, Dockerfiles, and Terraform files.

What's the best way to find the fix for a flaw using `list_bfl`? +

You must provide two things: the scan ID and the specific query (rule) ID string. The agent then calculates the optimal patch location based on those inputs.

How do I know if my scans are still running using `get_scan_details`? +

Call get_scan_details. It returns granular execution details, telling you which scan engines (SAST, SCA, KICS) fired and their individual run times or failure reasons.

Before running a scan, how should I use `get_project` to ensure the correct source code context is selected? +

You must call get_project first. This step gives you the necessary metadata for the specific codebase container and branch. It ensures your subsequent scans run against the intended version of the app.

My scan is running, but I need to stop it early; how does the `cancel_scan` tool prevent wasted resource use? +

The cancel_scan tool immediately drops the scanning context and prevents unnecessary engine resource consumption. It's useful if a developer pushes a new commit that overlaps with an active job.

If I need to review results from last week, what does the `list_scans` tool allow me to retrieve? +

list_scans gives you a historical record of all runs. You get the scan ID, status (Completed, Failed, etc.), and the targeted branch for every project run.

How can I get an overview of all microservices or major code containers using `list_applications`? +

list_applications provides a high-level inventory. It groups multiple individual services together, giving you aggregated risk reporting across your entire product line.

Built & Managed by Vinkius 30s setup 10 tools

We've already built the connector for Checkmarx. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 10 tools are live and waiting. You're up and running in seconds.

Vinkius runs on Claude Claude
Vinkius runs on ChatGPT ChatGPT
Vinkius runs on Cursor Cursor
Vinkius runs on Gemini Gemini
Vinkius runs on Windsurf Windsurf
Vinkius runs on VS Code VS Code
Vinkius runs on JetBrains JetBrains
Vinkius runs on Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.