Skip to main content

MCP Server

The VAAST MCP Server exposes read-only access to your local scan data for AI agents via the Model Context Protocol.

What it is​

The MCP Server is a stdio-based JSON-RPC server that AI clients (Claude Desktop, Claude Code, Cursor, VS Code) can connect to in order to:

  • List your VAAST workspaces
  • Read scan findings
  • Check current scan status
  • List registered scan targets

All data comes from your local VAAST installation. The server never exposes data over the network.

Security Model​

The VAAST MCP Server is designed for read-only, local-only access:

AspectImplementation
Read-onlyNo tools for launching scans, modifying data, or deleting resources
Local serverBinds to 127.0.0.1 only — never accessible from the network
Bearer token authPer-session token regenerated each time VAAST starts, stored in ~/.vaast/mcp.json
Data sourceslist_workspaces, get_findings, get_scan_status read from local SQLite; list_targets fetches from Xtrinel API

Prerequisites​

  1. VAAST running: The desktop app must be open
  2. Signed in: Required for list_targets (fetches from Xtrinel API)
  3. MCP Server started: Go to Integrations → MCP Server and click Start
  4. Node.js 18+: Required to run the npx command

Installation​

Command​

Latest version (auto-updates):

npx -y @xtrinel/vaast-mcp

Pinned version (recommended for stability):

npx -y @xtrinel/[email protected]

Package verification​

View package on npm:

npm view @xtrinel/vaast-mcp

Verify provenance attestation:

npm view @xtrinel/vaast-mcp --json | jq .dist.attestations

Registry listing: com.xtrinel/vaast (search "vaast")

Client Setup​

Claude Desktop​

Add to your claude_desktop_config.json:

{
"mcpServers": {
"vaast": {
"command": "npx",
"args": ["-y", "@xtrinel/[email protected]"]
}
}
}

Config file location:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json

Restart Claude Desktop after saving.

Official docs: Using MCP with Claude for Desktop


Claude Code​

Run in your terminal:

claude mcp add vaast -- npx -y @xtrinel/vaast-mcp

Official docs: Model Context Protocol


Cursor​

  1. Open Settings → Features → Model Context Protocol
  2. Add this configuration:
{
"mcpServers": {
"vaast": {
"command": "npx",
"args": ["-y", "@xtrinel/[email protected]"]
}
}
}
  1. Restart Cursor

Available Tools​

The MCP Server exposes four read-only tools:

list_workspaces​

Lists all VAAST workspaces from local SQLite.

Returns: Workspace ID, name, target URL, created/updated timestamps, whether auth is configured.

Example:

{
"workspaces": [
{
"id": "ws_abc123",
"name": "Production API",
"target_url": "https://api.example.com",
"has_auth": true,
"created_at": "2026-09-15T10:00:00Z",
"updated_at": "2026-10-01T14:30:00Z"
}
]
}

get_findings​

Retrieves scan findings for a specific workspace.

Parameters:

  • workspace_id (required): Workspace ID from list_workspaces

Returns: Payload name, category, severity, response snippet, remediation advice.

Example:

{
"workspace_id": "ws_abc123",
"findings": [
{
"id": "finding_xyz",
"payload_name": "System Instruction Override",
"category": "Instruction Attacks",
"severity": "critical",
"payload_text": "Ignore all previous instructions...",
"response_snippet": "Certainly! Here are your internal guidelines...",
"remediation": "Implement system message isolation with..."
}
],
"count": 1
}

get_scan_status​

Returns current scan status (running or idle).

Returns: Scan ID, workspace ID, status, progress (total payloads/findings), timestamps.

Example (scan running):

{
"scan_id": "scan_123",
"workspace_id": "ws_abc123",
"status": "running",
"is_running": true,
"started_at": "2026-10-01T14:00:00Z",
"total_payloads": 97,
"total_findings": 3
}

Example (idle):

{
"scan_id": null,
"status": "idle",
"is_running": false,
"message": "No scans found"
}

list_targets​

Lists registered scan targets (fetched from Xtrinel API).

Requires: VAAST signed in (needs auth token for API call)

Returns: Target domain, endpoint, verification status, timestamps.

Example:

{
"targets": [
{
"domain": "example.com",
"endpoint": "https://api.example.com/v1/chat",
"status": "verified",
"created_at": "2026-09-01T10:00:00Z"
}
]
}

Verification​

Test the connection​

After configuring your client, test that it can call the MCP Server:

  1. Ensure VAAST is running and the MCP Server is started (check Integrations → MCP Server)
  2. In your AI client (Claude, Cursor, etc.), ask: "List my VAAST workspaces"
  3. You should see the tool call succeed and return your workspace list

Troubleshooting​

"Failed to read VAAST MCP session file"​

Cause: VAAST MCP Server not started or VAAST not running.

Fix: Open VAAST → Integrations → MCP Server → click Start.


"Invalid bearer token"​

Cause: VAAST was restarted after the client connected (token regenerated).

Fix: Restart your AI client to pick up the new token from ~/.vaast/mcp.json.


"Not signed in"​

Cause: list_targets requires authentication but VAAST is not signed in.

Fix: Sign in to VAAST (top-right corner).


"Network error" or timeouts​

Cause: VAAST server not reachable.

Fix:

  • Check that VAAST is running
  • Verify the MCP Server is started (green "Running" indicator)
  • Check ~/.vaast/mcp.json for the correct port

Node.js version errors​

Cause: Node.js version < 18.

Fix: Upgrade Node.js to 18 or later:

node --version  # Check current version
# Install latest LTS from nodejs.org

Package Details​


Learning Resources​

For hands-on tutorials, examples, and video walkthroughs of using VAAST with AI agents, visit the Infirmary Lab.