MCP Server
The VAAST MCP Server exposes read-only access to your local scan data for AI agents via the Model Context Protocol.
What it is
The MCP Server is a stdio-based JSON-RPC server that AI clients (Claude Desktop, Claude Code, Cursor, VS Code) can connect to in order to:
- List your VAAST workspaces
- Read scan findings
- Check current scan status
- List registered scan targets
All data comes from your local VAAST installation. The server never exposes data over the network.
Security Model
The VAAST MCP Server is designed for read-only, local-only access:
| Aspect | Implementation |
|---|---|
| Read-only | No tools for launching scans, modifying data, or deleting resources |
| Local server | Binds to 127.0.0.1 only — never accessible from the network |
| Bearer token auth | Per-session token regenerated each time VAAST starts, stored in ~/.vaast/mcp.json |
| Data sources | list_workspaces, get_findings, get_scan_status read from local SQLite; list_targets fetches from Xtrinel API |
Prerequisites
- VAAST running: The desktop app must be open
- Signed in: Required for
list_targets(fetches from Xtrinel API) - MCP Server started: Go to Integrations → MCP Server and click Start
- Node.js 18+: Required to run the npx command
Installation
Command
Latest version (auto-updates):
npx -y @xtrinel/vaast-mcp
Pinned version (recommended for stability):
npx -y @xtrinel/[email protected]
Package verification
View package on npm:
npm view @xtrinel/vaast-mcp
Verify provenance attestation:
npm view @xtrinel/vaast-mcp --json | jq .dist.attestations
Registry listing: com.xtrinel/vaast (search "vaast")
Client Setup
Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"vaast": {
"command": "npx",
"args": ["-y", "@xtrinel/[email protected]"]
}
}
}
Config file location:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
Restart Claude Desktop after saving.
Official docs: Using MCP with Claude for Desktop
Claude Code
Run in your terminal:
claude mcp add vaast -- npx -y @xtrinel/vaast-mcp
Official docs: Model Context Protocol
Cursor
- Open Settings → Features → Model Context Protocol
- Add this configuration:
{
"mcpServers": {
"vaast": {
"command": "npx",
"args": ["-y", "@xtrinel/[email protected]"]
}
}
}
- Restart Cursor
Available Tools
The MCP Server exposes four read-only tools:
list_workspaces
Lists all VAAST workspaces from local SQLite.
Returns: Workspace ID, name, target URL, created/updated timestamps, whether auth is configured.
Example:
{
"workspaces": [
{
"id": "ws_abc123",
"name": "Production API",
"target_url": "https://api.example.com",
"has_auth": true,
"created_at": "2026-09-15T10:00:00Z",
"updated_at": "2026-10-01T14:30:00Z"
}
]
}
get_findings
Retrieves scan findings for a specific workspace.
Parameters:
workspace_id(required): Workspace ID fromlist_workspaces
Returns: Payload name, category, severity, response snippet, remediation advice.
Example:
{
"workspace_id": "ws_abc123",
"findings": [
{
"id": "finding_xyz",
"payload_name": "System Instruction Override",
"category": "Instruction Attacks",
"severity": "critical",
"payload_text": "Ignore all previous instructions...",
"response_snippet": "Certainly! Here are your internal guidelines...",
"remediation": "Implement system message isolation with..."
}
],
"count": 1
}
get_scan_status
Returns current scan status (running or idle).
Returns: Scan ID, workspace ID, status, progress (total payloads/findings), timestamps.
Example (scan running):
{
"scan_id": "scan_123",
"workspace_id": "ws_abc123",
"status": "running",
"is_running": true,
"started_at": "2026-10-01T14:00:00Z",
"total_payloads": 97,
"total_findings": 3
}
Example (idle):
{
"scan_id": null,
"status": "idle",
"is_running": false,
"message": "No scans found"
}
list_targets
Lists registered scan targets (fetched from Xtrinel API).
Requires: VAAST signed in (needs auth token for API call)
Returns: Target domain, endpoint, verification status, timestamps.
Example:
{
"targets": [
{
"domain": "example.com",
"endpoint": "https://api.example.com/v1/chat",
"status": "verified",
"created_at": "2026-09-01T10:00:00Z"
}
]
}
Verification
Test the connection
After configuring your client, test that it can call the MCP Server:
- Ensure VAAST is running and the MCP Server is started (check Integrations → MCP Server)
- In your AI client (Claude, Cursor, etc.), ask: "List my VAAST workspaces"
- You should see the tool call succeed and return your workspace list
Troubleshooting
"Failed to read VAAST MCP session file"
Cause: VAAST MCP Server not started or VAAST not running.
Fix: Open VAAST → Integrations → MCP Server → click Start.
"Invalid bearer token"
Cause: VAAST was restarted after the client connected (token regenerated).
Fix: Restart your AI client to pick up the new token from ~/.vaast/mcp.json.
"Not signed in"
Cause: list_targets requires authentication but VAAST is not signed in.
Fix: Sign in to VAAST (top-right corner).
"Network error" or timeouts
Cause: VAAST server not reachable.
Fix:
- Check that VAAST is running
- Verify the MCP Server is started (green "Running" indicator)
- Check
~/.vaast/mcp.jsonfor the correct port
Node.js version errors
Cause: Node.js version < 18.
Fix: Upgrade Node.js to 18 or later:
node --version # Check current version
# Install latest LTS from nodejs.org
Package Details
- npm: @xtrinel/vaast-mcp
- MCP Registry: com.xtrinel/vaast
- Repository: Xtrinel-Group/vaast-mcp
- License: MIT
- Provenance: Published with npm provenance attestation (verifiable supply chain)
Learning Resources
For hands-on tutorials, examples, and video walkthroughs of using VAAST with AI agents, visit the Infirmary Lab.