Sponsored by Deepsite.site

PCI DSS MCP

Created By
shyshlakov10 days ago
PCI DSS v4.0.1 static-analysis MCP server for Go payment service codebases. 12 scanners detect PAN/CVV exposure, weak crypto, missing audit logs, vulnerable deps, TLS misconfig, auth weaknesses, plus CycloneDX 1.6 SBOM generation. Each finding maps to the exact PCI requirement. AI-assisted triage via triage_findings tool. Keyless-signed multi-arch Docker image on ghcr.io.
Overview

pci-dss-mcp

Static-analysis MCP server that detects PCI DSS v4.0.1 violations in Go payment service codebases. Every finding maps to a specific PCI DSS requirement number. Built for developers, QSAs, and CI gates.

What it detects

12 scanners over Go source + configs, each mapped to PCI DSS requirements:

ToolDetectsPCI DSS
scan_pan_dataPAN/CVV storage, masking, zeroing3.3.1, 3.4.1, 3.5.1
check_encryptionweak hashes, hardcoded keys, plain HTTP6.2.4, 4.2.1
check_tls_configInsecureSkipVerify, weak MinVersion, prohibited ciphers4.2.1
check_secrets_in_configsAPI keys, passwords, connection strings in configs8.6.2
check_error_handlingpayment-handler error disclosure6.2.4
check_auth_strengthhardcoded passwords, weak password policy, missing MFA8.3.1, 8.3.6, 8.4.2
audit_log_coveragemissing/unstructured audit logs in payment handlers10.2.1
check_data_retentionCVV/PAN without TTL, incorrect memory zeroing3.2.1, 3.3.1
check_payment_page_scriptsCSP, SRI, nonce, FIM for payment pages6.4.3, 11.6.1
check_dependenciesvulnerable go.mod deps via OSV.dev (offline mode supported)6.3.3
generate_sbomCycloneDX 1.6 SBOM with SPDX licenses6.3.2
triage_findingsAI-assisted prioritization + file:line enrichment(orchestrator)

Plus generate_compliance_report (full multi-scanner report), update_vulnerability_db (refresh OSV cache), explain_requirement (PCI DSS lookup).

Quick install (Docker)

{
  "mcpServers": {
    "pci-dss-mcp": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "--mount", "type=bind,src=/path/to/your/go/src,dst=/path/to/your/go/src,readonly",
        "ghcr.io/shyshlakov/pci-dss-mcp:v0.6.2"
      ]
    }
  }
}

src= and dst= mirror the same absolute path so the container sees your code at the same path your host uses.

Quick install (Go)

go install github.com/shyshlakov/pci-dss-mcp@v0.6.2

Then add {"command": "pci-dss-mcp"} to your MCP client config.

What pci-dss-mcp is NOT

  • Not a replacement for broad SAST (Semgrep, CodeQL, gosec for OWASP-Top-10)
  • Not a replacement for LLM-based code review
  • Not a QSA replacement: static analysis covers ~6% of PCI DSS v4.0.1; a Qualified Security Assessor must sign off on the rest

Distribution

  • MCP Registry: io.github.shyshlakov/pci-dss-mcp
  • Docker: ghcr.io/shyshlakov/pci-dss-mcp:v0.6.2 (keyless-signed via cosign + OIDC)
  • Go: go install github.com/shyshlakov/pci-dss-mcp@v0.6.2
  • Source: https://github.com/shyshlakov/pci-dss-mcp

License

MIT

Server Config

{
  "mcpServers": {
    "pci-dss-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "--mount",
        "type=bind,src=/path/to/your/go/src,dst=/path/to/your/go/src,readonly",
        "ghcr.io/shyshlakov/pci-dss-mcp:v0.6.2"
      ]
    }
  }
}
Recommend Servers
TraeBuild with Free GPT-4.1 & Claude 3.7. Fully MCP-Ready.
AiimagemultistyleA Model Context Protocol (MCP) server for image generation and manipulation using fal.ai's Stable Diffusion model.
Baidu Map百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Jina AI MCP ToolsA Model Context Protocol (MCP) server that integrates with Jina AI Search Foundation APIs.
Visual Studio Code - Open Source ("Code - OSS")Visual Studio Code
Amap Maps高德地图官方 MCP Server
Howtocook Mcp基于Anduin2017 / HowToCook (程序员在家做饭指南)的mcp server,帮你推荐菜谱、规划膳食,解决“今天吃什么“的世纪难题; Based on Anduin2017/HowToCook (Programmer's Guide to Cooking at Home), MCP Server helps you recommend recipes, plan meals, and solve the century old problem of "what to eat today"
Zhipu Web SearchZhipu Web Search MCP Server is a search engine specifically designed for large models. It integrates four search engines, allowing users to flexibly compare and switch between them. Building upon the web crawling and ranking capabilities of traditional search engines, it enhances intent recognition capabilities, returning results more suitable for large model processing (such as webpage titles, URLs, summaries, site names, site icons, etc.). This helps AI applications achieve "dynamic knowledge acquisition" and "precise scenario adaptation" capabilities.
RedisA Model Context Protocol server that provides access to Redis databases. This server enables LLMs to interact with Redis key-value stores through a set of standardized tools.
WindsurfThe new purpose-built IDE to harness magic
MiniMax MCPOfficial MiniMax Model Context Protocol (MCP) server that enables interaction with powerful Text to Speech, image generation and video generation APIs.
Y GuiA web-based graphical interface for AI chat interactions with support for multiple AI models and MCP (Model Context Protocol) servers.
CursorThe AI Code Editor
ChatWiseThe second fastest AI chatbot™
BlenderBlenderMCP connects Blender to Claude AI through the Model Context Protocol (MCP), allowing Claude to directly interact with and control Blender. This integration enables prompt assisted 3D modeling, scene creation, and manipulation.
MCP AdvisorMCP Advisor & Installation - Use the right MCP server for your needs
Playwright McpPlaywright MCP server
DeepChatYour AI Partner on Desktop
EdgeOne Pages MCPAn MCP service designed for deploying HTML content to EdgeOne Pages and obtaining an accessible public URL.
Serper MCP ServerA Serper MCP Server
Tavily Mcp