Install
$ agentstack add mcp-symbioticsec-mcp ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v1.0.0-beta1 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v1.0.0-beta1. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Symbiotic MCP Server
A Model Context Protocol (MCP) server for security analysis using Symbiotic CLI
Description
This server exposes security analysis tools via the MCP protocol for any MCP-compatible client. It allows scanning code and infrastructure files without affecting your workspace.
Available Tools
code_scan_files- Static code analysisinfra_scan_files- Infrastructure security scanningsecurity_scan_files- Comprehensive security scan (code + infrastructure)get_supported_languages- List of supported programming languages
Cursor Integration
Setting up the Security Review Command
- Create a
.cursordirectory in your project root if it doesn't exist - Create or update
.cursor/commands/security-review.mdwith the contents of [security-review.md](security-review.md)
Using the Command
- Open the chat panel in Cursor (Cmd+L or Ctrl+L)
- Type
/security-reviewfollowed by optional file paths or glob patterns - The command will perform a comprehensive security analysis, including:
- Scanning selected files or the entire workspace
- Analyzing for security vulnerabilities
- Triaging findings and filtering false positives
- Providing a detailed report with severity levels and remediation suggestions
- Offering to apply automatic fixes for identified issues
Installation
- Install symbiotic-cli
https://github.com/SymbioticSec/cli/releases
- Get API token
Create an account on Symbiotic Security and retrieve your API token.
- Build and start
Clone this repository and install dependencies:
npm install
npm run build
MCP Configuration
In VSCode, open MCP: Open User Configuration and add in servers:
{
"servers": {
"symbiotic-security": {
"command": "node",
"args": ["path/to/build/index.js"],
"env": {
"SYMBIOTIC_API_TOKEN": "your_token_here",
}
},
}
Configuration for other MCP clients may vary but generally follows the same structure.
{
"mcpServers": {
"symbiotic-security": {
"command": "node",
"args": ["path/to/build/index.js"],
"env": {
"SYMBIOTIC_API_TOKEN": "your_token_here"
}
}
}
}
Important environment variables:
SYMBIOTIC_API_TOKEN(required) - Your Symbiotic API token
Note: Configuration file name and location may vary depending on your MCP client.
Transport Modes
- STDIO (default) - Standard communication for MCP
- SSE - Server-Sent Events over HTTP
- Streamable HTTP - HTTP with
/mcpendpoint
# STDIO (default)
node build/index.js
# HTTP server on port 9593
SERVER_PORT=9593 node build/index.js
Authentication
The server requires a valid Symbiotic Security API token. Configuration is done via MCP environment variables.
Minimal required configuration:
"env": {
"SYMBIOTIC_API_TOKEN": "your_token_here"
}
How It Works
- Receives code files via MCP
- Creates temporary files
- Executes
symbiotic-cli - Automatic cleanup of temporary files
- Returns formatted results
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: SymbioticSec
- Source: SymbioticSec/mcp
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v1.0.0-beta1 Imported from the upstream source.