O360 MCP runs on your own machine — the client starts it, so there is no endpoint to ping. 48 installs a week from npm. Last commit 2 Aug 2026.
Run Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes
Today is the operative word: we check O360 MCP every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add o360-mcp -- npx -y o360-mcp
{
"mcpServers": {
"o360-mcp": {
"args": [
"-y",
"o360-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.o360-mcp]
command = "npx"
args = ["-y", "o360-mcp"]
{
"mcpServers": {
"o360-mcp": {
"args": [
"-y",
"o360-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"o360-mcp": {
"args": [
"-y",
"o360-mcp"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
O360_URL (Offensive360 instance base URL), O360_TOKEN (External scan token (free for public repos: https://offensive360.com/free-for-open-source/)).
The author declared them in the registry entry; get the values from the project itself.
Build Apps and run code in 30 languages — sandboxed, with persistent sessions for agent loops.
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Profile Shopify Liquid performance, find slow theme code, and explain fixes in plain language.
Run Python code in a secure sandbox without local setup. Declare inline dependencies and execute s…
Semantic code retrieval engine with hybrid search, context expansion, and 40+ language support.
Vinv runs, tests, and finds issues in your services — with zero code changes.
Local-first memory for AI coding agents. Memory + CodeGraph + Wiki in one SQLite file.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Answers built from our own checks of this server.