
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@xtrinel/vaast-mcp
Advanced tools
MCP server shim for VAAST - provides read-only access to local VAAST data for AI agents
Read-only MCP server shim for VAAST — gives AI agents secure, local-only access to your VAAST vulnerability data.
vaast-mcp is a Model Context Protocol server that forwards requests to a locally running VAAST application. It provides AI agents (Claude, Cursor, etc.) with read-only access to your scan findings, workspaces, and targets.
127.0.0.1 — never touches the network~/.vaast/mcp.jsonlocalhost| Tool | Description |
|---|---|
list_workspaces | List all VAAST workspaces (local SQLite) |
get_findings | Get scan findings for a workspace |
get_scan_status | Get current scan status |
list_targets | List registered scan targets (via Xtrinel API) |
All tools are read-only. No scanning, installation, or deletion capabilities.
claude mcp add vaast
When prompted, use:
npx -y @xtrinel/vaast-mcp (after package is published)node /path/to/vaast-mcp/dist/index.jsEdit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
After npm publish:
{
"mcpServers": {
"vaast": {
"command": "npx",
"args": ["-y", "@xtrinel/vaast-mcp"]
}
}
}
Local development (before publish):
{
"mcpServers": {
"vaast": {
"command": "node",
"args": ["/absolute/path/to/vaast-mcp/dist/index.js"]
}
}
}
Add to Cursor's MCP settings:
{
"mcpServers": {
"vaast": {
"command": "npx",
"args": ["-y", "@xtrinel/vaast-mcp"]
}
}
}
Add to ~/.continue/config.json:
{
"mcpServers": [
{
"name": "vaast",
"command": "npx",
"args": ["-y", "@xtrinel/vaast-mcp"]
}
]
}
# Build the shim
cd vaast-mcp
npm install
npm run build
# Start VAAST and enable MCP server first!
# Test with inspector
npx @modelcontextprotocol/inspector node dist/index.js
When VAAST MCP server is running:
When VAAST MCP server is NOT running:
Failed to read VAAST MCP session file at ~/.vaast/mcp.json127.0.0.1:<random-port> when you click Start~/.vaast/mcp.json with the port and a session bearer tokenvaast-mcp as a subprocessvaast-mcp reads the session file and forwards MCP requests via HTTP to VAASTCause: VAAST MCP server is not running.
Fix: Open VAAST → Integrations → MCP Server → Start
Cause: VAAST MCP server stopped or crashed.
Fix: Restart the MCP server in VAAST.
Cause: MCP config incorrect or agent needs restart.
Fix:
# Clone and install
git clone <repo>
cd vaast-mcp
npm install
# Build
npm run build
# Test locally (see Local development config above)
node dist/index.js
Apache-2.0 — See LICENSE
See SECURITY.md for vulnerability disclosure policy.
Made by Xtrinel — Offensive security tools for AI applications.
FAQs
MCP server shim for VAAST - provides read-only access to local VAAST data for AI agents
We found that @xtrinel/vaast-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.