plexicus-mcp
MCP (Model Context Protocol) server for Plexicus, the AI-powered Application Security Posture Management (ASPM) platform. It brings your security findings, scans and AI-generated remediations directly into Claude Code, Cursor, VS Code, Windsurf or any MCP-compatible client — so your coding agent can find, understand and fix vulnerabilities without leaving the IDE.
Unlike the rest of this monorepo, this directory is not a Docker service: it is a standalone Python package published to PyPI that runs on the developer's machine and talks to the Plexicus REST API.
Quick start
- Generate an API token in the Plexicus console: Settings → API Tokens.
- Add the server to your client:
Claude Code
claude mcp add plexicus \
-e PLEXICUS_API_TOKEN=<your-token> \
-e PLEXICUS_API_URL=https://api.app.plexicus.ai \
-- uvx plexicus-mcp
Cursor / VS Code / Windsurf (JSON config)
{
"mcpServers": {
"plexicus": {
"command": "uvx",
"args": ["plexicus-mcp"],
"env": {
"PLEXICUS_API_TOKEN": "<your-token>",
"PLEXICUS_API_URL": "https://api.app.plexicus.ai"
}
}
}
}
No uv? Use pipx run plexicus-mcp or pip install plexicus-mcp + command plexicus-mcp.
Configuration
| Variable | Required | Default | Description |
|---|---|---|---|
PLEXICUS_API_TOKEN |
yes | — | API token from Settings → API Tokens |
PLEXICUS_API_URL |
no | https://api.app.plexicus.ai |
Base URL of your Plexicus API (self-hosted deployments) |
What it exposes
Tools
| Tool | Description |
|---|---|
get_current_repository |
Map the workspace git remote to its Plexicus repository |
list_repositories / get_repository |
Browse registered repositories with severity counts |
list_findings / get_finding |
Query findings (severity, status, CWE, text search, pagination) |
request_scan / get_scan_status |
Launch a scan and follow its progress |
generate_remediation / get_remediation |
Ask the AI remediation engine for a fix and fetch it |
get_security_posture |
Account-wide severity totals and worst repositories |
Prompts — fix_finding, triage_findings, security_review: guided workflows the agent
can follow end-to-end (read finding → generate remediation → apply diff → verify).
Resources — plexicus://repositories and plexicus://repositories/{id}/findings as JSON.
Every tool returns {"markdown": ..., "data": ...}: a human-readable digest plus the raw API
payload for follow-up automation.
Example session
"What critical security issues does this repo have?" — the agent calls
get_current_repository, thenlist_findings(severity="critical")."Fix the SQL injection one" — the agent uses the
fix_findingprompt: reads the finding, requests an AI remediation, applies the diff to your workspace and runs the tests.
Development
cd mcp
pip install -e ".[dev]"
pytest
ruff check .
Releasing
Releases are published to PyPI by the Forgejo workflow .forgejo/workflows/publish-mcp.yml
when a mcp-v* tag is pushed (e.g. mcp-v0.1.0). Bump version in pyproject.toml and
__version__ in src/plexicus_mcp/__init__.py first.
Metadata
Release files for plexicus-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| plexicus_mcp-0.1.0.tar.gz | 12.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| plexicus_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.0 kB
Release files / plexicus_mcp-0.1.0.tar.gz
| Download URL | plexicus_mcp-0.1.0.tar.gz |
|---|---|
| Size | 12.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3d350dcdb6aaa7a6a55a7fd224ebcf74d9abb5bb55ddb9859701d242688539cf
|
|
BLAKE2b-256 checksum How to use checksums |
ebd947bca339aa792a2ee7310d628532ea6e122dd688e0fe9fa54b3893d0e9e2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.11.15
|
Release files / plexicus_mcp-0.1.0-py3-none-any.whl
| Download URL | plexicus_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 12.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
16ecd48f77a7d8ec22d55f0711f85f3bb0a0cedd11784b0fff2cea4cd76c7cf1
|
|
BLAKE2b-256 checksum How to use checksums |
e34f66409d381fa22d30fe5ab808cad5858ffd5a73d90f71300205649efff5b1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.11.15
|