StackHawk

MCP-Server von StackHawk

Set up StackHawk, run security scans and triage findings from your IDE or chat.

Läuft lokal (Läuft auf deinem Rechner: Die Seite nennt den Installationsbefehl)Läuft mit uvxBraucht API-Schlüssel

StackHawk installieren

Läuft auf deinem Rechner. Dein Client startet ihn mit diesem Befehl:

uvx stackhawk-mcp

Braucht uv (Python) auf deinem Rechner. Die Schritte unten zeigen, wo der Befehl in jedem Client hingehört.

  • STACKHAWK_API_KEY geheim StackHawk API key

Diesen Server teilen

Öffnet diese Seite, mit dem Installationsbefehl und den Einrichtungsschritten.

mcp.tc/i/stackhawk

Über den Server

Connects an AI assistant to the StackHawk security scanning platform. It can detect your project, create a StackHawk application, generate a stackhawk.yml, run scans with the StackHawk CLI, and return findings at or above your failure threshold for remediation. It also validates YAML configs against the official schema.

Runs locally over stdio as the PyPI package stackhawk-mcp (for example with uvx), and requires Python 3.10 or higher. A StackHawk API key is required and is passed in the STACKHAWK_API_KEY environment variable. An optional FastAPI HTTP server is also included.

Was du damit machen kannst

  • Detect a project and create a StackHawk application
  • Generate a ready-to-scan stackhawk.yml
  • Run StackHawk scans from the IDE or chat
  • Triage findings at or above the failure threshold
  • Validate YAML configs against the official schema
  • Validate field paths to avoid invented config keys

Tools

StackHawk zeigt seine Tools nur Clients mit Schlüssel, deshalb können wir sie hier nicht auflisten.

Beispiel-Prompts

  • Set up StackHawk for this project and create a stackhawk.yml.

  • Validate this StackHawk YAML config for errors.

  • Run a StackHawk scan on my app and summarize the findings.

  • Show the findings above my failure threshold and suggest fixes.

Einrichtung

Jeder Client startet StackHawk mit demselben Befehl auf deinem Rechner. Wähl deinen; die Seite merkt sich deine Wahl.

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport stdio stackhawk --env "STACKHAWK_API_KEY=<YOUR_STACKHAWK_API_KEY>" -- uvx stackhawk-mcp
  1. Start Claude Code and type /mcp. stackhawk should show as connected.

Add --scope user to make it available in every project. Replace the placeholders with your own values.

Claude Desktop

  1. Open Settings → Developer → Edit Config. It opens claude_desktop_config.json. Add:
claude_desktop_config.json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}
  1. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}

Needs uv (Python) on your computer. Replace the placeholders with your own values.

VS Code

Add it to .vscode/mcp.json. VS Code asks for the secret the first time and stores it securely:

.vscode/mcp.json
{
  "servers": {
    "stackhawk": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "${input:stackhawk-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "stackhawk-api-key",
      "description": "STACKHAWK_API_KEY",
      "password": true
    }
  ]
}

Needs uv (Python) on your computer.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}
  1. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

Codex

codex mcp add stackhawk --env "STACKHAWK_API_KEY=<YOUR_STACKHAWK_API_KEY>" -- uvx stackhawk-mcp

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.stackhawk]
command = "uvx"
args = ["stackhawk-mcp"]
env = { STACKHAWK_API_KEY = "<YOUR_STACKHAWK_API_KEY>" }

Needs uv (Python) on your computer. Replace the placeholders with your own values.

Gemini CLI

gemini mcp add -e "STACKHAWK_API_KEY=<YOUR_STACKHAWK_API_KEY>" stackhawk uvx stackhawk-mcp

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients that start local servers accept this shape:

{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}

Zed puts servers under context_servers in its settings, with the same command, args and env fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

Häufige Fragen

Can I paste mcp.tc/i/stackhawk into my MCP client?

No. StackHawk runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is uvx stackhawk-mcp.

Does StackHawk need an API key?

Yes. It reads STACKHAWK_API_KEY from its environment, and STACKHAWK_API_KEY is a secret. Put the value in your client’s config on your own machine, never in a shared file.

Is StackHawk a remote or a local server?

Local. Your client starts it as a process on your computer with uvx stackhawk-mcp, which needs uv (Python).

What can StackHawk do?

You can Detect a project and create a StackHawk application, Generate a ready-to-scan stackhawk.yml und Run StackHawk scans from the IDE or chat.

Which clients can use it?

Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.

Who wrote this page?

mcp.tc’s robot read StackHawk’s public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can’t confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

Einbinden

Zeig StackHawk in einem README oder auf deiner Website. Jede Einbindung verlinkt auf diese Seite, nutzt den Installationsbefehl des Servers und setzt keine Cookies. So funktionieren Einbindungen

README-Badge

Badge-Vorschau, hellBadge-Vorschau, dunkel
Markdown
[![StackHawk on mcp.tc](https://mcp.tc/i/stackhawk/badge.svg)](https://mcp.tc/i/stackhawk)
HTML
<a href="https://mcp.tc/i/stackhawk"><img src="https://mcp.tc/i/stackhawk/badge.svg" alt="StackHawk on mcp.tc" height="20"></a>

Es folgt dem hellen oder dunklen Modus der Lesenden. Hänge ?theme=light oder ?theme=dark an, um ihn festzulegen, oder ?style=compact, um das Zeichen ohne Schriftzug zu zeigen.

Website-Karte

HTML
<script src="https://mcp.tc/w/stackhawk.js" async></script>

Die Karte erscheint dort, wo das Tag steht. Füge dem Tag data-theme="dark" oder data-size="compact" hinzu, um sie zu ändern. Die Datei enthält alles, was sie braucht, stellt also keine weiteren Anfragen und setzt keine Cookies.

iframe

HTML
<iframe src="https://mcp.tc/embed/stackhawk" title="StackHawk on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

Nutze es auf Seiten, die keine Skripte erlauben. Hänge ?theme=light oder ?theme=dark an die Adresse an, um die Farben festzulegen.

JSON

Der Eintrag als Daten für deine eigenen Seiten und Tools: Name, Kurzbeschreibung, Installationsbefehl, Tools und die „Add to“-Links. Jede Website kann ihn lesen (CORS ist offen).

https://mcp.tc/i/stackhawk.json

Was jedes Feld bedeutet

mcp.tc ist nicht mit StackHawk verbunden. Diese Seite entstand aus den öffentlichen Metadaten von StackHawk, zuletzt geprüft am 4. Okt. 2026, und ein KI-Modell hat die Beschreibung geschrieben, sie kann also Fehler enthalten. Namen und Marken gehören ihren Inhabern. Stimmt etwas nicht? Eintrag melden.