Checkmarx Security MCP plugin for Claude Code. Connects Claude to the Checkmarx One platform for SAST, SCA, KICS, container, and secret-detection workflows: list projects and applications, trigger and monitor scans, inspect findings, and retrieve AI-driven remediation for vulnerable packages, images, and source code.
This repository is a Claude Code plugin marketplace published by Checkmarx. It currently hosts one plugin:
| Plugin | Description |
|---|---|
checkmarx-security-mcp | Connects Claude to the Checkmarx One platform via the security-mcp server (SAST / SCA / KICS / secret detection / remediation). |
From the Claude Code CLI:
# Register this repo as a marketplace (one-time)
/plugin marketplace add cx-hitesh-madgulkar/MCP-plugin
# Install a plugin from it
/plugin install checkmarx-security-mcp@MCP-plugin
# Enable
/plugin enable checkmarx-security-mcp
/pluginis only available in the Claude Code CLI. The VS Code extension does not expose this command — use the terminal.
See each plugin's own README for its setup, environment variables, and usage:
MCP-plugin/
├─ .claude-plugin/
│ └─ marketplace.json ← marketplace manifest (lists plugins)
├─ plugins/
│ └─ checkmarx-security-mcp/
│ ├─ .claude-plugin/
│ │ └─ plugin.json ← plugin metadata
│ ├─ .mcp.json ← MCP server config (HTTP + Bearer auth)
│ └─ README.md
└─ README.md ← (this file)
plugins/<your-plugin>/ with .claude-plugin/plugin.json, .mcp.json (if it wraps an MCP server), and README.md.plugins in .claude-plugin/marketplace.json.Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimnpx claudepluginhub cx-hitesh-madgulkar/mcp-plugin --plugin checkmarx-security-mcpHarness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Browser automation and end-to-end testing MCP server by Microsoft. Enables Claude to interact with web pages, take screenshots, fill forms, click elements, and perform automated browser testing workflows.
Reliable automation, in-depth debugging, and performance analysis in Chrome using Chrome DevTools and Puppeteer
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Memory compression system for Claude Code - persist context across sessions