AppSecNews MCP server

Connect Claude, ChatGPT, Cursor, VS Code or any MCP client to the AppSecNews catalog of application security tools, comparisons and news. Read only, no account, every answer links its source page.

Server URL

https://appsecnews.com/mcp

Streamable HTTP. Protocol revisions 2026-07-28 and 2025-11-25. No sign in.

Connect

Claude (claude.ai and the desktop app): add a custom connector and paste the server URL. ChatGPT: where your plan lets you add an MCP server or connector, paste the same URL. Both call the server from their own infrastructure, so nothing runs on your machine.

Claude Code

claude mcp add --transport http appsecnews https://appsecnews.com/mcp

Cursor (~/.cursor/mcp.json)

{
    "mcpServers": {
        "appsecnews": {
            "url": "https://appsecnews.com/mcp"
        }
    }
}

VS Code (.vscode/mcp.json)

{
    "servers": {
        "appsecnews": {
            "type": "http",
            "url": "https://appsecnews.com/mcp"
        }
    }
}

Any client that takes a JSON config

{
    "mcpServers": {
        "appsecnews": {
            "type": "streamable-http",
            "url": "https://appsecnews.com/mcp"
        }
    }
}

Tools

All read only. Every item in every answer has url, title and last_updated, and every answer carries the line "Source: AppSecNews (https://appsecnews.com)". Please link the url when you use an answer.

search_tools
Find application security tools in the AppSecNews catalog by text, category, deployment, license and language. Results are ranked like the site search. query, category, deployment, license, languages, limit, cursor
get_tool
The full AppSecNews profile of one tool: summary, best for, license, deployment, languages, integrations and the profile text in Markdown. slug
compare_tools
Side by side facts for 2 to 5 tools from their structured records, with the values they all share. No scores or ratings. slugs
list_categories
The thirteen AppSec tool categories with what sets each apart and how many tools each has.
shortlist_tools
Deterministic filter and rank from stated requirements; no model inside. Category, license and deployment filter; languages, CI platforms and must have features score. The result explains the arithmetic. category, languages, ci_platforms, deployment, license, must_have_features, limit
latest_news
Recent AppSecNews news items, newest first, each with its sources on the page. since, tag, tool_slug, limit, cursor
search_articles
Search AppSecNews news, blog posts, guides, comparisons and roundups, newest first. query, type, category, limit, cursor
get_article
One AppSecNews article or news item: summary, key takeaways, body in Markdown (long bodies are cut with a read more URL), sources, FAQ and related tools. slug

Resources and prompts

  • appsecnews://tools/{slug}: The AppSecNews profile of one tool, in Markdown, with its canonical URL.
  • appsecnews://articles/{slug}: One published AppSecNews article, guide, comparison or news item, in Markdown, with its sources.
  • appsecnews://categories/{slug}: One of the thirteen categories with every published tool in it, in Markdown.
  • evaluate_appsec_tools: Guides the assistant through shortlisting and comparing application security tools for a stated stack, citing AppSecNews pages.
  • weekly_appsec_briefing: Summarises the last seven days of AppSecNews news with links to each item.

Limits and privacy

  • 120 requests a minute per address, and 60 per address and client. Past that the server answers 429 with a Retry-After header and a JSON-RPC error that says so.
  • Only published content. No drafts, no user data.
  • Each call is logged with the tool name, the client's self reported name, the search text if any, the result count and the time taken. No address and no other arguments are stored.
  • Text from vendors is labelled vendor_provided, and markup, hidden characters and instructions aimed at models are removed from everything the server returns.