From 143007b05359490ca466aa957763f63a24739a7e Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar Date: Fri, 3 Jul 2026 01:52:50 +0530 Subject: [PATCH 01/10] - Added files required for cursor marketplace Signed-off-by: Anand Nandeshwar --- .cursor-plugin/plugin.json | 10 ++++++++++ README.md | 9 ++++----- assets/logo.png | Bin 0 -> 2214 bytes mcp/mcp.json => mcp.json | 5 +---- 4 files changed, 15 insertions(+), 9 deletions(-) create mode 100644 .cursor-plugin/plugin.json create mode 100644 assets/logo.png rename mcp/mcp.json => mcp.json (50%) diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json new file mode 100644 index 0000000..35b4057 --- /dev/null +++ b/.cursor-plugin/plugin.json @@ -0,0 +1,10 @@ +{ + "name": "security-mcp", + "displayName": "Checkmarx", + "version": "1.0.0", + "author": { "name": "Checkmarx" }, + "description": "Official Checkmarx MCP server.", + "keywords": ["mcp", "checkmarx", "security", "vulnerability-remediation", "realtime-scan", "sast", "iac", "sca"], + "license": "Apache-2.0", + "logo": "assets/logo.png" +} \ No newline at end of file diff --git a/README.md b/README.md index aede40f..3627bc7 100644 --- a/README.md +++ b/README.md @@ -16,8 +16,7 @@ - [MCP Client Configuration](#mcp-client-configuration) - [Prerequisites](#prerequisites) - [JSON Configuration](#json-configuration) - - [Windsurf IDE](#windsurf-ide) - - [IntelliJ IDEA - GitHub Copilot](#intellij-idea---github-copilot) + - [Cursor IDE](#cursor-ide) - [Claude Desktop / Claude Code](#claude-desktop--claude-code) - [Available Tools](#available-tools) - [Scanning](#scanning) @@ -70,7 +69,7 @@ The server uses **API Key** and **OAuth2** authentication. 1. Clients authenticate to Checkmarx One and get an API key. 2. This API key will be used during MCP client configuration, include the API Key in the `Authorization` header as mentioned in the [MCP Client Configuration](#mcp-client-configuration) section. -### OAuth2 Authentication +### OAuth2 Authentication (Recommended) Checkmarx MCP supports Dynamic Client Registration (DCR) flow allows an AI client (such as Cursor or Claude Desktop) to connect securely. 1. User only needs to configure the MCP client as mentioned in the [MCP Client Configuration](#mcp-client-configuration) section. 2. When the client attempts to connect to the MCP server, it will be redirected to Checkmarx One login page for authentication. @@ -91,7 +90,7 @@ Refer [Authentication](/docs/authentication.md) for detailed authentication inst ### JSON Configuration Below are examples to add the server to your MCP client configuration. See the [examples/](examples) folder for ready-to-use client config files. -#### Windsurf IDE +#### Cursor IDE **API Key Authentication:** @@ -101,7 +100,7 @@ Below are examples to add the server to your MCP client configuration. See the [ "Checkmarx": { "serverUrl": "https://{api_host}/api/security-mcp/mcp/{tenant}", "headers": { - "cx-origin": "Windsurf", + "cx-origin": "Cursor", "Authorization": "API_KEY" } } diff --git a/assets/logo.png b/assets/logo.png new file mode 100644 index 0000000000000000000000000000000000000000..9668e98f5077a0cc38a08d3d17b9e5a52d022b43 GIT binary patch literal 2214 zcmV;X2wC@uP)HSfc%cPCT;>9M4EpjTsq! z!ru2kSqLB)D&(qEBoz!$oFMtVxE+Lq@cb2737?fB2!Q%$T0EC8R5oX4dxLj-IiZ(W zfJVp{#_iqnqggiF##ud<7iZg@OA^XTBs@*b_h~*xx;QgC;fpeWpj;S!m(y_ac=O`L ze!|ul`VHZu3fY?Ei}m3G-D86%_;6cqxp85dW8hZHc$<$B>z~TiRT;QIB!=O)*bo2h zO#AwcBozog{5wdUvTf^7=4l8qr7A~TaYBG9!^g`w4TWI(wB_3J6R_r+?jP7&YkGeD zVDmIUf_!B@(`1<-aoRHN(IWuiVPi2Jf`k{R&ec`d@VVhi82)w3j`#o3vFR0xLr_DF z0|_rSnoT51lD;TYvw!bc?|wqAN|~ptIW6X?HEdjpBFT&0TVAg>zx50HX*eFLRXn#= zh(%0h6O0hen2m4%(c?Z>HyZOiAQeBOGn`h6Qf9MpNh*k+?Ra@ZqqTTH8yDrHGO=2k zxfsSov_zlj@^=_*z8j6O#%XX7A%BIg`edYdZaN#6AOi!nrsoS<93@9#v{7sSwQDi5 z>_uW;G*rrrljY=EJoR<1Kzk<)AK`G(rP{L6SXp)s8#h3>`>I=4<#xKN3^3X>K#=nJ zD~;LN9evg1FcVOK@s}nZDVGZ#n+C(r)a)yc56@lA#`ED;OQkVuq1k=r9E|RFemD=# zTmWyeA3VeZ5`LukDb{V~0)bE?Td}O!ey}7+_IropJ+1!egA~W*cK)ue>-C?|s$@2)+gatDD?74;Y@ zkw7niVB=Cp42Kc#z)aN}ujpfU6|;S*Lx_^-Gbj$}yW^>=AC*HEKnH+u0FoZF>%%$G z@4gRf{=qy1LDbTWY$-23y3<)*O^ss);=s1o>HBKFP42Yb=PyWk3F-*Z<4-WnM-T+W$g-9S&`Hv6m*EUk`(#*+&>sNd zV~aHV_Ue>H8(}8i_kMHj*lqm+oOJgOH4YFSH+O1vm0Fqs)$yQfa)YVx1)TH@TcQqy z2LTAVs)*&<@}rUBd3u;hol3bWH17-qFcs=FDj5MqF>l-k98DAT>Cb|BKfU8u&@I3)@`{7%2 z=Xisb`!Ia)MC6vuu;xjMzzwFN0$B4joc`9%Q>_K72-5F^;fs0d__@*Bx5MfKtzzw3 zSn^k0Z@${$JW&J758;mIe0^>Eh9Zh02^hXsvF2HXgF;<2fs`K~2SaSI?EHPBb|u;Jmp&sgwP*PC0qoQ5hUPJ7>p3W^hiI&O3p3d>JA ze=b7wcQ>h>V|@fT3a10O7J5ZGS&tFclV#rE4}E2+AL5ww07{fe4fF6SWvB5(fx(U$gz- o7Y0*NVL#q;4_52n0RRC1|I6k!xo~Rg!2kdN07*qoM6N<$g2_)y^8f$< literal 0 HcmV?d00001 diff --git a/mcp/mcp.json b/mcp.json similarity index 50% rename from mcp/mcp.json rename to mcp.json index ec4a4cf..06e1d05 100644 --- a/mcp/mcp.json +++ b/mcp.json @@ -2,10 +2,7 @@ "mcpServers": { "Checkmarx": { "url": "https:///api/security-mcp/mcp/", - "headers": { - "cx-origin": "", - "Authorization": "" - } } } } + From 928cca6327b7527ff5bf22dd0e17e3acdbdcabb4 Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar Date: Tue, 7 Jul 2026 11:14:54 +0530 Subject: [PATCH 02/10] - Updated readme and plugin.json for cursor marketplace Signed-off-by: Anand Nandeshwar --- .cursor-plugin/plugin.json | 2 +- README.md | 17 +++++++++-------- 2 files changed, 10 insertions(+), 9 deletions(-) diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json index 35b4057..f78d63e 100644 --- a/.cursor-plugin/plugin.json +++ b/.cursor-plugin/plugin.json @@ -4,7 +4,7 @@ "version": "1.0.0", "author": { "name": "Checkmarx" }, "description": "Official Checkmarx MCP server.", - "keywords": ["mcp", "checkmarx", "security", "vulnerability-remediation", "realtime-scan", "sast", "iac", "sca"], + "keywords": ["mcp", "checkmarx", "security", "vulnerability-remediation", "realtime-scan", "sast", "iac", "sca", "secrets-detection", "container"], "license": "Apache-2.0", "logo": "assets/logo.png" } \ No newline at end of file diff --git a/README.md b/README.md index 3627bc7..3ad3880 100644 --- a/README.md +++ b/README.md @@ -64,17 +64,18 @@ Multi-protocol support to facilitate secure and efficient communication between The server uses **API Key** and **OAuth2** authentication. -### API Key Authentication - -1. Clients authenticate to Checkmarx One and get an API key. -2. This API key will be used during MCP client configuration, include the API Key in the `Authorization` header as mentioned in the [MCP Client Configuration](#mcp-client-configuration) section. - ### OAuth2 Authentication (Recommended) Checkmarx MCP supports Dynamic Client Registration (DCR) flow allows an AI client (such as Cursor or Claude Desktop) to connect securely. 1. User only needs to configure the MCP client as mentioned in the [MCP Client Configuration](#mcp-client-configuration) section. 2. When the client attempts to connect to the MCP server, it will be redirected to Checkmarx One login page for authentication. 3. Once authentication is successful with valid Checkmarx credentials, the MCP client can use the tools provided by the MCP server. - + +### API Key Authentication + +1. Clients authenticate to Checkmarx One and get an API key. +2. This API key will be used during MCP client configuration, include the API Key in the `Authorization` header as mentioned in the [MCP Client Configuration](#mcp-client-configuration) section. + + **Note:** You required valid Checkmarx credentials to get the API Key or connect to the MCP server. Refer [Authentication](/docs/authentication.md) for detailed authentication instructions and troubleshooting. @@ -98,7 +99,7 @@ Below are examples to add the server to your MCP client configuration. See the [ { "mcpServers": { "Checkmarx": { - "serverUrl": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "Cursor", "Authorization": "API_KEY" @@ -114,7 +115,7 @@ Below are examples to add the server to your MCP client configuration. See the [ { "mcpServers": { "Checkmarx": { - "serverUrl": "https://{api_host}/api/security-mcp/mcp/{tenant}" + "url": "https://{api_host}/api/security-mcp/mcp/{tenant}" } } } From 2977dad83f927a79cb3013cff4c0f4461e980be5 Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar Date: Tue, 7 Jul 2026 12:08:54 +0530 Subject: [PATCH 03/10] - changed placeholder from api_host to cxone_base_url Signed-off-by: Anand Nandeshwar --- README.md | 6 +++--- docs/authentication.md | 6 +++--- docs/troubleshooting.md | 6 +++--- examples/claude-mcp.json | 2 +- examples/copilot-mcp.json | 2 +- examples/cursor-mcp.json | 2 +- examples/kiro-mcp.json | 2 +- examples/windsurf-mcp.json | 2 +- mcp.json | 2 +- server.json | 4 ++-- 10 files changed, 17 insertions(+), 17 deletions(-) diff --git a/README.md b/README.md index 3ad3880..758fa6e 100644 --- a/README.md +++ b/README.md @@ -99,7 +99,7 @@ Below are examples to add the server to your MCP client configuration. See the [ { "mcpServers": { "Checkmarx": { - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "Cursor", "Authorization": "API_KEY" @@ -115,7 +115,7 @@ Below are examples to add the server to your MCP client configuration. See the [ { "mcpServers": { "Checkmarx": { - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}" + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}" } } } @@ -130,7 +130,7 @@ Below are examples to add the server to your MCP client configuration. See the [ "mcpServers": { "Checkmarx": { "type": "http", - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "Authorization": "" } diff --git a/docs/authentication.md b/docs/authentication.md index e2b8bae..0d770f6 100644 --- a/docs/authentication.md +++ b/docs/authentication.md @@ -35,7 +35,7 @@ Pass the API key in the `Authorization` header when configuring your MCP client. ```json { "Checkmarx": { - "serverUrl": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "serverUrl": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "", "Authorization": "API_KEY" @@ -74,13 +74,13 @@ For OAuth2, your MCP client config only needs the server URL: { "mcpServers": { "Checkmarx": { - "serverUrl": "https://{api_host}/api/security-mcp/mcp/{tenant}" + "serverUrl": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}" } } } ``` -Replace `{api_host}` and `{tenant}` with your values. +Replace `{cxone_base_url}` and `{tenant}` with your values. **OAuth2 discovery endpoints exposed by the server:** - `/.well-known/oauth-protected-resource` diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index 22b4768..9b06884 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -20,11 +20,11 @@ Common issues and solutions when using the Checkmarx Security MCP Server. **Symptoms:** Client shows "server not reachable", connection timeout, or no tools listed. **Checks:** -1. Verify the server URL in your config matches the pattern `https://{api_host}/api/security-mcp/mcp/{tenant}`. -2. Confirm your `api_host` value (e.g., `ast.checkmarx.net`) — get this from your Checkmarx administrator. +1. Verify the server URL in your config matches the pattern `https://{cxone_base_url}/api/security-mcp/mcp/{tenant}`. +2. Confirm your `cxone_base_url` value (e.g., `ast.checkmarx.net`) — get this from your Checkmarx administrator. 3. Confirm your `tenant` value (e.g., `cx_eu`, `checkmarx`). 4. Check that your network allows outbound HTTPS traffic to the Checkmarx API host. -5. Test basic connectivity: `curl -I https://{api_host}/api/security-mcp/mcp/{tenant}`. +5. Test basic connectivity: `curl -I https://{cxone_base_url}/api/security-mcp/mcp/{tenant}`. **Common mistakes:** - Trailing slash in the URL (remove it). diff --git a/examples/claude-mcp.json b/examples/claude-mcp.json index ef0fb50..528d31b 100644 --- a/examples/claude-mcp.json +++ b/examples/claude-mcp.json @@ -2,7 +2,7 @@ "mcpServers": { "Checkmarx": { "type": "http", - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "Claude", "Authorization": "{api_key}" diff --git a/examples/copilot-mcp.json b/examples/copilot-mcp.json index 7ba3872..1fe8e7e 100644 --- a/examples/copilot-mcp.json +++ b/examples/copilot-mcp.json @@ -1,7 +1,7 @@ { "servers": { "Checkmarx": { - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "requestInit": { "headers": { "cx-origin": "Jetbrains", diff --git a/examples/cursor-mcp.json b/examples/cursor-mcp.json index 89fb346..d3c9296 100644 --- a/examples/cursor-mcp.json +++ b/examples/cursor-mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "Cursor", "Authorization": "{api_key}" diff --git a/examples/kiro-mcp.json b/examples/kiro-mcp.json index b3df312..9e73b2c 100644 --- a/examples/kiro-mcp.json +++ b/examples/kiro-mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "url": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "Kiro", "Authorization": "{api_key}" diff --git a/examples/windsurf-mcp.json b/examples/windsurf-mcp.json index 0dee098..b9527c2 100644 --- a/examples/windsurf-mcp.json +++ b/examples/windsurf-mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "serverUrl": "https://{api_host}/api/security-mcp/mcp/{tenant}", + "serverUrl": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant}", "headers": { "cx-origin": "Windsurf", "Authorization": "{api_key}" diff --git a/mcp.json b/mcp.json index 06e1d05..aaf331f 100644 --- a/mcp.json +++ b/mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "url": "https:///api/security-mcp/mcp/", + "url": "https:///api/security-mcp/mcp/", } } } diff --git a/server.json b/server.json index f01516f..36faa96 100644 --- a/server.json +++ b/server.json @@ -11,9 +11,9 @@ "remotes": [ { "type": "streamable-http", - "url": "https://{api_host}/api/security-mcp/mcp/{tenant_id}", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant_id}", "variables": { - "api_host": { + "cxone_base_url": { "description": "API host provided by your Checkmarx administrator, e.g., ast.checkmarx.net", "isRequired": true }, From 5c4463651108671f3093d0e5c3202b759f9904f1 Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar Date: Tue, 7 Jul 2026 12:33:42 +0530 Subject: [PATCH 04/10] - changed mcp server name to Checkmarx Signed-off-by: Anand Nandeshwar --- .cursor-plugin/plugin.json | 2 +- server.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json index f78d63e..2abefe4 100644 --- a/.cursor-plugin/plugin.json +++ b/.cursor-plugin/plugin.json @@ -1,5 +1,5 @@ { - "name": "security-mcp", + "name": "Checkmarx", "displayName": "Checkmarx", "version": "1.0.0", "author": { "name": "Checkmarx" }, diff --git a/server.json b/server.json index 36faa96..08e4bb3 100644 --- a/server.json +++ b/server.json @@ -1,6 +1,6 @@ { "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json", - "name": "com.checkmarx/security-mcp", + "name": "com.checkmarx/Checkmarx", "description": "Official Checkmarx MCP Server", "repository": { "url": "https://github.com/Checkmarx/cx-agentic-ai", From 128a41b93435ee34b1da9ddb124b930ef1e859d7 Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar Date: Thu, 9 Jul 2026 12:20:15 +0530 Subject: [PATCH 05/10] - changed mcp server name to checkmarx as it requires in lowercase Signed-off-by: Anand Nandeshwar --- .cursor-plugin/plugin.json | 15 +++++++++++++-- server.json | 2 +- 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json index 2abefe4..532834c 100644 --- a/.cursor-plugin/plugin.json +++ b/.cursor-plugin/plugin.json @@ -1,10 +1,21 @@ { - "name": "Checkmarx", + "name": "checkmarx", "displayName": "Checkmarx", "version": "1.0.0", "author": { "name": "Checkmarx" }, "description": "Official Checkmarx MCP server.", - "keywords": ["mcp", "checkmarx", "security", "vulnerability-remediation", "realtime-scan", "sast", "iac", "sca", "secrets-detection", "container"], + "keywords": [ + "mcp", + "checkmarx", + "security", + "vulnerability-remediation", + "realtime-scan", + "sast", + "iac", + "sca", + "secrets-detection", + "container" + ], "license": "Apache-2.0", "logo": "assets/logo.png" } \ No newline at end of file diff --git a/server.json b/server.json index 08e4bb3..1b737bd 100644 --- a/server.json +++ b/server.json @@ -1,6 +1,6 @@ { "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json", - "name": "com.checkmarx/Checkmarx", + "name": "com.checkmarx/checkmarx", "description": "Official Checkmarx MCP Server", "repository": { "url": "https://github.com/Checkmarx/cx-agentic-ai", From 4b57c6d77cb2b0e6e39eafeb568d6571a72a70da Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar Date: Thu, 9 Jul 2026 12:22:57 +0530 Subject: [PATCH 06/10] - changed mcp server name to checkmarx as it requires in lowercase Signed-off-by: Anand Nandeshwar --- mcp.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mcp.json b/mcp.json index aaf331f..614b7c1 100644 --- a/mcp.json +++ b/mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "url": "https:///api/security-mcp/mcp/", + "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant_id}", } } } From 161d2b9ad45181793b51b3add1e66a627807857a Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar <73646287+cx-anand-nandeshwar@users.noreply.github.com> Date: Tue, 21 Jul 2026 01:45:55 +0530 Subject: [PATCH 07/10] - Added cursor plugin with folder structure --- .cursor-plugin/marketplace.json | 19 ++++++++++ .cursor-plugin/plugin.json | 21 ----------- assets/logo.png | Bin 2214 -> 0 bytes mcp.json | 8 ---- .../.cursor-plugin/plugin.json | 35 ++++++++++++++++++ plugins/cx-cursor-plugin/mcp.json | 7 ++++ 6 files changed, 61 insertions(+), 29 deletions(-) create mode 100644 .cursor-plugin/marketplace.json delete mode 100644 .cursor-plugin/plugin.json delete mode 100644 assets/logo.png delete mode 100644 mcp.json create mode 100644 plugins/cx-cursor-plugin/.cursor-plugin/plugin.json create mode 100644 plugins/cx-cursor-plugin/mcp.json diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json new file mode 100644 index 0000000..6bd261f --- /dev/null +++ b/.cursor-plugin/marketplace.json @@ -0,0 +1,19 @@ +{ + "name": "cx-cursor-marketplace", + "owner": { + "name": "Checkmarx" + }, + "metadata": { + "description": "Official Checkmarx MCP Plugin For Cursor IDE", + "version": "1.0.0" + }, + "plugins": [ + { + "name": "checkmarx", + "displayName": "Checkmarx", + "description": "Checkmarx-powered security scanning and fixing inside your coding loop. Checks the code you write and the code AI generates for vulnerabilities and risky dependencies, then returns precise, engine-backed fixes. Best invoked after writing or changing code, before commits, and around security-sensitive logic. Applies fixes inline so you can accept them without leaving your editor.", + "category": "security", + "source": "./plugins/cx-cursor-plugin" + } + ] +} diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json deleted file mode 100644 index 532834c..0000000 --- a/.cursor-plugin/plugin.json +++ /dev/null @@ -1,21 +0,0 @@ -{ - "name": "checkmarx", - "displayName": "Checkmarx", - "version": "1.0.0", - "author": { "name": "Checkmarx" }, - "description": "Official Checkmarx MCP server.", - "keywords": [ - "mcp", - "checkmarx", - "security", - "vulnerability-remediation", - "realtime-scan", - "sast", - "iac", - "sca", - "secrets-detection", - "container" - ], - "license": "Apache-2.0", - "logo": "assets/logo.png" -} \ No newline at end of file diff --git a/assets/logo.png b/assets/logo.png deleted file mode 100644 index 9668e98f5077a0cc38a08d3d17b9e5a52d022b43..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 2214 zcmV;X2wC@uP)HSfc%cPCT;>9M4EpjTsq! z!ru2kSqLB)D&(qEBoz!$oFMtVxE+Lq@cb2737?fB2!Q%$T0EC8R5oX4dxLj-IiZ(W zfJVp{#_iqnqggiF##ud<7iZg@OA^XTBs@*b_h~*xx;QgC;fpeWpj;S!m(y_ac=O`L ze!|ul`VHZu3fY?Ei}m3G-D86%_;6cqxp85dW8hZHc$<$B>z~TiRT;QIB!=O)*bo2h zO#AwcBozog{5wdUvTf^7=4l8qr7A~TaYBG9!^g`w4TWI(wB_3J6R_r+?jP7&YkGeD zVDmIUf_!B@(`1<-aoRHN(IWuiVPi2Jf`k{R&ec`d@VVhi82)w3j`#o3vFR0xLr_DF z0|_rSnoT51lD;TYvw!bc?|wqAN|~ptIW6X?HEdjpBFT&0TVAg>zx50HX*eFLRXn#= zh(%0h6O0hen2m4%(c?Z>HyZOiAQeBOGn`h6Qf9MpNh*k+?Ra@ZqqTTH8yDrHGO=2k zxfsSov_zlj@^=_*z8j6O#%XX7A%BIg`edYdZaN#6AOi!nrsoS<93@9#v{7sSwQDi5 z>_uW;G*rrrljY=EJoR<1Kzk<)AK`G(rP{L6SXp)s8#h3>`>I=4<#xKN3^3X>K#=nJ zD~;LN9evg1FcVOK@s}nZDVGZ#n+C(r)a)yc56@lA#`ED;OQkVuq1k=r9E|RFemD=# zTmWyeA3VeZ5`LukDb{V~0)bE?Td}O!ey}7+_IropJ+1!egA~W*cK)ue>-C?|s$@2)+gatDD?74;Y@ zkw7niVB=Cp42Kc#z)aN}ujpfU6|;S*Lx_^-Gbj$}yW^>=AC*HEKnH+u0FoZF>%%$G z@4gRf{=qy1LDbTWY$-23y3<)*O^ss);=s1o>HBKFP42Yb=PyWk3F-*Z<4-WnM-T+W$g-9S&`Hv6m*EUk`(#*+&>sNd zV~aHV_Ue>H8(}8i_kMHj*lqm+oOJgOH4YFSH+O1vm0Fqs)$yQfa)YVx1)TH@TcQqy z2LTAVs)*&<@}rUBd3u;hol3bWH17-qFcs=FDj5MqF>l-k98DAT>Cb|BKfU8u&@I3)@`{7%2 z=Xisb`!Ia)MC6vuu;xjMzzwFN0$B4joc`9%Q>_K72-5F^;fs0d__@*Bx5MfKtzzw3 zSn^k0Z@${$JW&J758;mIe0^>Eh9Zh02^hXsvF2HXgF;<2fs`K~2SaSI?EHPBb|u;Jmp&sgwP*PC0qoQ5hUPJ7>p3W^hiI&O3p3d>JA ze=b7wcQ>h>V|@fT3a10O7J5ZGS&tFclV#rE4}E2+AL5ww07{fe4fF6SWvB5(fx(U$gz- o7Y0*NVL#q;4_52n0RRC1|I6k!xo~Rg!2kdN07*qoM6N<$g2_)y^8f$< diff --git a/mcp.json b/mcp.json deleted file mode 100644 index 614b7c1..0000000 --- a/mcp.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "mcpServers": { - "Checkmarx": { - "url": "https://{cxone_base_url}/api/security-mcp/mcp/{tenant_id}", - } - } -} - diff --git a/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json b/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json new file mode 100644 index 0000000..d73be18 --- /dev/null +++ b/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json @@ -0,0 +1,35 @@ +{ + "name": "checkmarx", + "displayName": "Checkmarx", + "version": "1.0.0", + "description": "Checkmarx-powered security scanning and fixing inside your coding loop. Real-time vulnerability detection with AI-powered remediation.", + "author": { + "name": "Checkmarx", + "email": "support@checkmarx.com", + "url": "https://checkmarx.com" + }, + "homepage": "https://checkmarx.com", + "repository": "https://github.com/checkmarx/cx-agentic-ai", + "license": "Apache-2.0", + "logo": "../assets/logo.png", + "keywords": [ + "mcp", + "checkmarx", + "security", + "vulnerability-remediation", + "realtime-scan", + "sast", + "iac", + "sca", + "secrets-detection" + ], + "mcpServers": { + "Checkmarx": { + "url": "https://ast-master-components.dev.cxast.net/api/security-mcp/mcp/master-sypher" + } + }, + "commands": [], + "rules": [], + "skills": [], + "agents": [] +} \ No newline at end of file diff --git a/plugins/cx-cursor-plugin/mcp.json b/plugins/cx-cursor-plugin/mcp.json new file mode 100644 index 0000000..44417ec --- /dev/null +++ b/plugins/cx-cursor-plugin/mcp.json @@ -0,0 +1,7 @@ +{ + "mcpServers": { + "Checkmarx": { + "url": "https://ast-master-components.dev.cxast.net/api/security-mcp/mcp/master-sypher" + } + } +} \ No newline at end of file From ecc10608ad607f1db09d4e29536290e56967e2ed Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar <73646287+cx-anand-nandeshwar@users.noreply.github.com> Date: Tue, 21 Jul 2026 01:51:11 +0530 Subject: [PATCH 08/10] - Added cursor plugin with folder structure --- .../cx-cursor-plugin/.cursor-plugin/plugin.json | 2 +- plugins/cx-cursor-plugin/assets/logo.png | Bin 0 -> 2214 bytes plugins/cx-cursor-plugin/mcp.json | 2 +- 3 files changed, 2 insertions(+), 2 deletions(-) create mode 100644 plugins/cx-cursor-plugin/assets/logo.png diff --git a/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json b/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json index d73be18..b261b17 100644 --- a/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json +++ b/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json @@ -25,7 +25,7 @@ ], "mcpServers": { "Checkmarx": { - "url": "https://ast-master-components.dev.cxast.net/api/security-mcp/mcp/master-sypher" + "url": "https://${env:CXONE_BASE_URL}/api/security-mcp/mcp/${env:CXONE_TENANT_ID}" } }, "commands": [], diff --git a/plugins/cx-cursor-plugin/assets/logo.png b/plugins/cx-cursor-plugin/assets/logo.png new file mode 100644 index 0000000000000000000000000000000000000000..9668e98f5077a0cc38a08d3d17b9e5a52d022b43 GIT binary patch literal 2214 zcmV;X2wC@uP)HSfc%cPCT;>9M4EpjTsq! z!ru2kSqLB)D&(qEBoz!$oFMtVxE+Lq@cb2737?fB2!Q%$T0EC8R5oX4dxLj-IiZ(W zfJVp{#_iqnqggiF##ud<7iZg@OA^XTBs@*b_h~*xx;QgC;fpeWpj;S!m(y_ac=O`L ze!|ul`VHZu3fY?Ei}m3G-D86%_;6cqxp85dW8hZHc$<$B>z~TiRT;QIB!=O)*bo2h zO#AwcBozog{5wdUvTf^7=4l8qr7A~TaYBG9!^g`w4TWI(wB_3J6R_r+?jP7&YkGeD zVDmIUf_!B@(`1<-aoRHN(IWuiVPi2Jf`k{R&ec`d@VVhi82)w3j`#o3vFR0xLr_DF z0|_rSnoT51lD;TYvw!bc?|wqAN|~ptIW6X?HEdjpBFT&0TVAg>zx50HX*eFLRXn#= zh(%0h6O0hen2m4%(c?Z>HyZOiAQeBOGn`h6Qf9MpNh*k+?Ra@ZqqTTH8yDrHGO=2k zxfsSov_zlj@^=_*z8j6O#%XX7A%BIg`edYdZaN#6AOi!nrsoS<93@9#v{7sSwQDi5 z>_uW;G*rrrljY=EJoR<1Kzk<)AK`G(rP{L6SXp)s8#h3>`>I=4<#xKN3^3X>K#=nJ zD~;LN9evg1FcVOK@s}nZDVGZ#n+C(r)a)yc56@lA#`ED;OQkVuq1k=r9E|RFemD=# zTmWyeA3VeZ5`LukDb{V~0)bE?Td}O!ey}7+_IropJ+1!egA~W*cK)ue>-C?|s$@2)+gatDD?74;Y@ zkw7niVB=Cp42Kc#z)aN}ujpfU6|;S*Lx_^-Gbj$}yW^>=AC*HEKnH+u0FoZF>%%$G z@4gRf{=qy1LDbTWY$-23y3<)*O^ss);=s1o>HBKFP42Yb=PyWk3F-*Z<4-WnM-T+W$g-9S&`Hv6m*EUk`(#*+&>sNd zV~aHV_Ue>H8(}8i_kMHj*lqm+oOJgOH4YFSH+O1vm0Fqs)$yQfa)YVx1)TH@TcQqy z2LTAVs)*&<@}rUBd3u;hol3bWH17-qFcs=FDj5MqF>l-k98DAT>Cb|BKfU8u&@I3)@`{7%2 z=Xisb`!Ia)MC6vuu;xjMzzwFN0$B4joc`9%Q>_K72-5F^;fs0d__@*Bx5MfKtzzw3 zSn^k0Z@${$JW&J758;mIe0^>Eh9Zh02^hXsvF2HXgF;<2fs`K~2SaSI?EHPBb|u;Jmp&sgwP*PC0qoQ5hUPJ7>p3W^hiI&O3p3d>JA ze=b7wcQ>h>V|@fT3a10O7J5ZGS&tFclV#rE4}E2+AL5ww07{fe4fF6SWvB5(fx(U$gz- o7Y0*NVL#q;4_52n0RRC1|I6k!xo~Rg!2kdN07*qoM6N<$g2_)y^8f$< literal 0 HcmV?d00001 diff --git a/plugins/cx-cursor-plugin/mcp.json b/plugins/cx-cursor-plugin/mcp.json index 44417ec..4c191ae 100644 --- a/plugins/cx-cursor-plugin/mcp.json +++ b/plugins/cx-cursor-plugin/mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "url": "https://ast-master-components.dev.cxast.net/api/security-mcp/mcp/master-sypher" + "url": "https://${env:CXONE_BASE_URL}/api/security-mcp/mcp/${env:CXONE_TENANT_ID}" } } } \ No newline at end of file From b9635db7e83e811f208044181e92a935e65f53e4 Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar <73646287+cx-anand-nandeshwar@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:55:08 +0530 Subject: [PATCH 09/10] - Changed mcp configuration setup --- .../.cursor-plugin/plugin.json | 19 +++++++++++++++---- plugins/cx-cursor-plugin/mcp.json | 2 +- 2 files changed, 16 insertions(+), 5 deletions(-) diff --git a/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json b/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json index b261b17..94ec6a2 100644 --- a/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json +++ b/plugins/cx-cursor-plugin/.cursor-plugin/plugin.json @@ -23,10 +23,21 @@ "sca", "secrets-detection" ], - "mcpServers": { - "Checkmarx": { - "url": "https://${env:CXONE_BASE_URL}/api/security-mcp/mcp/${env:CXONE_TENANT_ID}" - } + "variables": { + "type": "object", + "properties": { + "CXONE_BASE_URL": { + "type": "string", + "title": "Checkmarx One API Host", + "description": "Your Checkmarx One API host, e.g. ast.checkmarx.net" + }, + "CXONE_TENANT_ID": { + "type": "string", + "title": "Tenant ID", + "description": "Your Checkmarx tenant identifier" + } + }, + "required": ["CXONE_BASE_URL", "CXONE_TENANT_ID"] }, "commands": [], "rules": [], diff --git a/plugins/cx-cursor-plugin/mcp.json b/plugins/cx-cursor-plugin/mcp.json index 4c191ae..1f51c15 100644 --- a/plugins/cx-cursor-plugin/mcp.json +++ b/plugins/cx-cursor-plugin/mcp.json @@ -1,7 +1,7 @@ { "mcpServers": { "Checkmarx": { - "url": "https://${env:CXONE_BASE_URL}/api/security-mcp/mcp/${env:CXONE_TENANT_ID}" + "url": "https://${CXONE_BASE_URL}/api/security-mcp/mcp/${CXONE_TENANT_ID}" } } } \ No newline at end of file From d3cad2392732f33d2510efbdf3aee2c92df03b03 Mon Sep 17 00:00:00 2001 From: Anand Nandeshwar <73646287+cx-anand-nandeshwar@users.noreply.github.com> Date: Tue, 21 Jul 2026 17:08:00 +0530 Subject: [PATCH 10/10] - added readme file for cursor --- plugins/cx-cursor-plugin/README.md | 51 ++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 plugins/cx-cursor-plugin/README.md diff --git a/plugins/cx-cursor-plugin/README.md b/plugins/cx-cursor-plugin/README.md new file mode 100644 index 0000000..354901e --- /dev/null +++ b/plugins/cx-cursor-plugin/README.md @@ -0,0 +1,51 @@ +# Cursor IDE - Checkmarx MCP Setup Guide + +The Checkmarx plugin registers its MCP server automatically through Cursor's plugin marketplace mechanism — no manual `mcp.json` editing, no environment variables, and no restarting your computer. + +## Setup (1 minute) + +1. Install the **Checkmarx** plugin from the Cursor Marketplace (or add this repo's `.cursor-plugin/marketplace.json` as a custom marketplace source). +2. When Cursor prompts you to configure the plugin, fill in: + - **Checkmarx One API Host** — e.g. `ast.checkmarx.net` + - **Tenant ID** — your Checkmarx tenant identifier + - **API Key** *(optional)* — leave blank to authenticate via browser-based OAuth2 login on first use instead +3. Restart Cursor. + +That's it — Cursor reads the plugin's `mcp.json` and registers the `Checkmarx` MCP server for you using the values you entered. + +## Verify + +Ask Cursor: +``` +What MCP servers are available? +``` +or +``` +List all Checkmarx tools +``` + +If you left the API Key blank, the first tool call will open a browser window for you to log in to Checkmarx One. After that, token refresh is handled automatically. + +## Updating configuration later + +Reopen the plugin's configuration panel in Cursor (Settings → Plugins → Checkmarx → Configure) to change your API host, tenant ID, or API key — no file editing required. + +## Troubleshooting + +**MCP not appearing in Cursor** +- Confirm the plugin shows as installed and configured in Settings → Plugins. +- Confirm Cursor was restarted after installing/configuring the plugin. + +**Connection error** +- Double-check the API host (e.g. `ast.checkmarx.net`, no `https://` prefix) and tenant ID. +- Confirm network access to your Checkmarx One tenant. + +**401 Unauthorized** +- If using OAuth2 (API Key left blank), make sure you completed the browser login prompt. +- If using an API key, verify it hasn't expired and that your Checkmarx user has the required permissions. + +See [docs/authentication.md](../../docs/authentication.md) for full authentication details. + +## Getting help + +Contact: support@checkmarx.com