AppSecNews MCP server
Connect Claude, ChatGPT, Cursor, VS Code or any MCP client to the AppSecNews catalog of application security tools, comparisons and news. Read only, no account, every answer links its source page.
Server URL
https://appsecnews.com/mcp
Streamable HTTP. Protocol revisions 2026-07-28 and 2025-11-25. No sign in.
Connect
Claude (claude.ai and the desktop app): add a custom connector and paste the server URL. ChatGPT: where your plan lets you add an MCP server or connector, paste the same URL. Both call the server from their own infrastructure, so nothing runs on your machine.
Claude Code
claude mcp add --transport http appsecnews https://appsecnews.com/mcp
Cursor (~/.cursor/mcp.json)
{
"mcpServers": {
"appsecnews": {
"url": "https://appsecnews.com/mcp"
}
}
}
VS Code (.vscode/mcp.json)
{
"servers": {
"appsecnews": {
"type": "http",
"url": "https://appsecnews.com/mcp"
}
}
}
Any client that takes a JSON config
{
"mcpServers": {
"appsecnews": {
"type": "streamable-http",
"url": "https://appsecnews.com/mcp"
}
}
}
Tools
All read only. Every item in every answer has url, title and last_updated, and every answer carries the line "Source: AppSecNews (https://appsecnews.com)". Please link the url when you use an answer.
- search_tools
- Find application security tools in the AppSecNews catalog by text, category, deployment, license and language. Results are ranked like the site search. query, category, deployment, license, languages, limit, cursor
- get_tool
- The full AppSecNews profile of one tool: summary, best for, license, deployment, languages, integrations and the profile text in Markdown. slug
- compare_tools
- Side by side facts for 2 to 5 tools from their structured records, with the values they all share. No scores or ratings. slugs
- list_categories
- The thirteen AppSec tool categories with what sets each apart and how many tools each has.
- shortlist_tools
- Deterministic filter and rank from stated requirements; no model inside. Category, license and deployment filter; languages, CI platforms and must have features score. The result explains the arithmetic. category, languages, ci_platforms, deployment, license, must_have_features, limit
- latest_news
- Recent AppSecNews news items, newest first, each with its sources on the page. since, tag, tool_slug, limit, cursor
- search_articles
- Search AppSecNews news, blog posts, guides, comparisons and roundups, newest first. query, type, category, limit, cursor
- get_article
- One AppSecNews article or news item: summary, key takeaways, body in Markdown (long bodies are cut with a read more URL), sources, FAQ and related tools. slug
Resources and prompts
- appsecnews://tools/{slug}: The AppSecNews profile of one tool, in Markdown, with its canonical URL.
- appsecnews://articles/{slug}: One published AppSecNews article, guide, comparison or news item, in Markdown, with its sources.
- appsecnews://categories/{slug}: One of the thirteen categories with every published tool in it, in Markdown.
- evaluate_appsec_tools: Guides the assistant through shortlisting and comparing application security tools for a stated stack, citing AppSecNews pages.
- weekly_appsec_briefing: Summarises the last seven days of AppSecNews news with links to each item.
Limits and privacy
- 120 requests a minute per address, and 60 per address and client. Past that the server answers 429 with a Retry-After header and a JSON-RPC error that says so.
- Only published content. No drafts, no user data.
- Each call is logged with the tool name, the client's self reported name, the search text if any, the result count and the time taken. No address and no other arguments are stored.
- Text from vendors is labelled vendor_provided, and markup, hidden characters and instructions aimed at models are removed from everything the server returns.