Model Context Protocol (MCP) scanning

Use manual explore workflows to test applications that use the Model Context Protocol (MCP) and analyze MCP tool calls during the scan.

AppScan now supports security testing for applications that use the Model Context Protocol (MCP). This capability is available through manual explore workflows and allows AppScan to capture traffic, analyze MCP tool calls, and perform a comprehensive security analysis.

Workflow and configuration

  • MCP scanning is supported through manual exploration workflows using tools such as Postman. For Postman-based workflows, use Postman version 11.42.3 or later.
  • When starting a scan, select the dedicated MCP template to ensure appropriate coverage for MCP-based traffic. The new MCP.scant template is located in the Templates folder of the AppScan Standard installation directory and is recommended for all MCP scans. The default location is:
    C:\Program Files (x86)\HCL\AppScan Standard\Templates\MCP.scant
  • For AppScan Connect, first load the MCP template, then open Postman to perform manual crawling. You can then run the scan through AppScan Connect as usual.

Current limitations

  • Direct import of Postman collections for MCP scanning is currently not supported because Postman cannot export collections that include MCP requests.
  • The current implementation relies on a manual process and is intended as a specialized workflow for this release. Automatic scanning is planned for a future release.