Skip to main content

Windsurf Setup

Prerequisites

  • Windsurf IDE
  • Unizo API key and VMS integration ID
  • Node.js v20 or higher

Setup Instructions

  1. Install @mcp-remote if not already installed:

    npm i mcp-remote
  2. Locate Windsurf's MCP configuration:

    • macOS/Linux: ~/.windsurf/mcp_settings.json
    • Windows: %USERPROFILE%\.windsurf\mcp_settings.json
  3. Add Unizo Vulnerability Management configuration:

{
"mcpServers": {
"unizo": {
"command": "/Users/{user_name}/.nvm/versions/node/v18.x.x/bin/node",
"args": [
"/Users/{user_name}/.nvm/versions/node/v18.x.x/bin/mcp-remote",
"https://api.unizo.ai/mcp",
"--header",
"apikey:${UNIZO_API_KEY}",
"--header",
"x-mcp-scopes:vms"
],
"env": {
"UNIZO_API_KEY": "your_api_key"
}
}
}
}
  1. Restart Windsurf to load the MCP server

Flags: If npx is producing errors, consider adding -y as the first argument to auto-accept the installation of the mcp-remote package.

{
"mcpServers": {
"unizo": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://api.unizo.ai/mcp",
"--header",
"apikey:${UNIZO_API_KEY}",
"--header",
"x-mcp-scopes:vms"
],
"env": {
"UNIZO_API_KEY": "your_api_key"
}
}
}
}

Available Tools

Once configured, you'll have access to:

  • vms_list_connectors - Get list of available vulnerability management services
  • vms_list_integrations - Get integrations for a specific VMS service
  • vms_list_vulnerabilities - Browse vulnerabilities with filtering and pagination
  • vms_get_vulnerability_summary - Retrieve comprehensive vulnerability information
  • vms_list_assets - Browse assets with pagination and sorting
  • vms_get_asset_details - Retrieve detailed asset information
  • vms_get_asset_risk_assessment - Get risk assessment for a specific asset
  • vms_list_scans - Browse vulnerability scans
  • vms_get_scan_details - Retrieve detailed scan information

Cascade AI Integration

Enable Cascade AI to use MCP tools:

{
"cascade.mcp.enabled": true,
"cascade.mcp.autoConnect": true
}

Multiple Integrations

To work with multiple categories or integrations, add them as a comma-separated list under the x-mcp-scopes header:

{
"mcpServers": {
"unizo": {
"command": "npx",
"args": [
"mcp-remote",
"https://api.unizo.ai/mcp",
"--header",
"apikey:${UNIZO_API_KEY}",
"--header",
"x-mcp-scopes : vms,scm,ticketing"
],
"env": {
"UNIZO_API_KEY": "your_api_key"
}
}
}
}

Troubleshooting

MCP not detected

  • Check Windsurf logs: View → Output → MCP
  • Ensure Node.js v20+ is installed

Authentication errors

  • Verify your API key in Unizo dashboard
  • Check that the integration ID is correct
  • Ensure the integration is active

Debug mode

Enable debug logging in settings.json:

{
"args": [
"--debug"
]
}