Plexicus MCP

Bring Plexicus security context into your IDE.

The Plexicus MCP server connects your IDE agent to repository and security finding data, so you can investigate and request actions without switching tools.

Read the MCP setup guide →

CONNECTION FLOW

From your IDE to Plexicus

10 TOOLS

MCP-compatible IDE

Claude Code, Cursor, VS Code, Windsurf

Plexicus MCP server

Local · stdio · Python 3.10+

Plexicus API

Repositories · findings · scans

Your IDE agent calls Plexicus tools through the local MCP server.
WHAT YOU CAN DO

Explore security context from your editor

The MCP server exposes these documented tools to compatible IDE clients. Your agent can use them as part of a security review.

Find the right repository

Match your local Git workspace to a Plexicus repository or browse repositories in your account.

Investigate findings

Filter findings by severity, status, or CWE, then inspect details and code context.

Review suggested fixes

Request AI remediation suggestions and review proposed diffs before applying changes.

Request scans

Start an application scan and check its progress from your IDE.

GET CONNECTED

Connect your IDE in three steps

The detailed commands and client configuration are maintained in the MCP documentation.

  1. 01

    Choose an MCP client

    The guide covers Claude Code, Cursor, VS Code, and Windsurf.

  2. 02

    Choose a launch method

    Use the documented uvx, pipx, or pip method to make the Python 3.10+ server available to your IDE.

  3. 03

    Configure your token and connect

    Set PLEXICUS_API_TOKEN in your IDE’s MCP configuration, then connect. API Tokens settings are rolling out with the MCP release; if unavailable, contact support or use an existing automation token.

Ready to configure Plexicus MCP?

The guide includes current setup commands, environment variables, tool references, and troubleshooting.

Read the MCP setup guide →
Qualification

Check whether AI Swarm Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

0 / 280

No commitment. If you don't fit, we'll tell you.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)