MCP 服务器

aribot-mcp

com.ayurak/aribot-mcp
开发者工具 法律与合规 安全 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Performs threat modeling, code security, API and cloud security scans, compliance analysis, and governed remediation.

apply_remediation
Apply a remediation (governed)
Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.
可能执行破坏性操作 可访问外部资源
输入模式
{'type': 'object', 'required': ['threat_id', 'rule_id'], 'properties': {'rule_id': {'type': 'string', 'description': 'Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)'}, 'threat_id': {'type': 'string', 'description': 'Threat id/code to remediate'}, 'resource_context': {'type': 'object', 'description': 'provider/resource_id/region/account_id/metadata'}}, 'additionalProperties': False}
code_review_scan
Run a code security scan
Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.
可访问外部资源
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'description': 'Id of an existing code-review scan to (re)run'}}, 'additionalProperties': False}
compliance_scan
Run a platform / compliance scan
Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.
可访问外部资源
输入模式
{'type': 'object', 'required': ['scan_type'], 'properties': {'source': {'type': 'string', 'description': 'Scan source (default: hybrid)'}, 'scan_type': {'enum': ['platform', 'compliance', 'pipeline', 'sbom', 'diagram', 'account'], 'type': 'string', 'description': 'platform | compliance | pipeline | sbom'}, 'account_id': {'type': 'string', 'description': 'Cloud account id (account-scoped scans)'}, 'diagram_id': {'type': 'string', 'description': 'Diagram id/uuid (diagram-scoped scans)'}, 'frameworks': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional standard/framework ids to scope the scan'}, 'severity_filter': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional severity levels to include'}, 'simulation_mode': {'type': 'boolean', 'description': 'Dry-run the scan without side effects'}}, 'additionalProperties': False}
compliance_status
Get Compliance Status
Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceability company rollup.
只读
输入模式
{'type': 'object', 'required': [], 'properties': {'scan_id': {'type': 'string', 'description': 'Optional anchor scan; latest is used if omitted'}, 'diagram_id': {'type': 'string', 'description': 'Optional diagram to add framework coverage for'}}, 'additionalProperties': False}
discover_shadow_ai
Shadow-AI posture (part of Code Security): unsanctioned / unknown AI-service usage discovered in code — totals, risk score, provider/type breakdown, hardcoded-key count, and top discoveries. Company latest, or one scan with `scan_id`. Reads code_review ShadowAIReport/ShadowAIDiscovery.
输入模式
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'integer', 'default': 15, 'description': 'Max discoveries to return'}, 'scan_id': {'type': 'string', 'description': 'Optional CodeReviewScan id; company-wide latest if omitted'}}, 'additionalProperties': False}
generate_threat_model
Generate Threat Model
Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.
可访问外部资源
输入模式
{'type': 'object', 'required': ['nodes'], 'properties': {'name': {'type': 'string', 'description': 'Threat model name'}, 'edges': {'type': 'array', 'items': {'type': 'object'}, 'description': 'ReactFlow edges'}, 'nodes': {'type': 'array', 'items': {'type': 'object'}, 'description': 'ReactFlow nodes (each: id, position, data.label)'}}, 'additionalProperties': False}
get_api_security
API security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Company-wide or one scan with `scan_id`. Reads code_review ApiEndpointDiscovery.
输入模式
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'integer', 'default': 20, 'description': 'Max endpoints to return'}, 'scan_id': {'type': 'string', 'description': 'Optional CodeReviewScan id; company-wide if omitted'}}, 'additionalProperties': False}
get_billing
Billing status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasable plans, and any approved-but-unpaid plans. Pass `checkout_request_id` to get a hosted Stripe Checkout URL to COMPLETE an approved plan, `topup_amount` (EUR) to get one to TOP UP the wallet, or `request_plan` (starter|pay_per_use|pro|max|enterprise) to REQUEST a plan (files a request for super-admin approval — never grants). Use this to view or RESOLVE a 402 without leaving the connector.
输入模式
{'type': 'object', 'required': [], 'properties': {'request_plan': {'type': 'string', 'description': 'Optional plan key to request (pro|max|…) — files a request for super-admin approval; does not grant or charge'}, 'topup_amount': {'type': 'number', 'description': 'Optional EUR amount to top up the credit wallet (returns a hosted Checkout URL)'}, 'checkout_request_id': {'type': 'string', 'description': 'Approved license_request_id to complete payment for (returns a hosted Checkout URL)'}}, 'additionalProperties': False}
get_cloud_compliance
Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Account.latest_scan -> compliances.ScanResults.
输入模式
{'type': 'object', 'required': [], 'properties': {'account_id': {'type': 'string', 'description': 'Optional single cloud Account id; all company accounts if omitted'}}, 'additionalProperties': False}
get_diagram_summary
Get a diagram summary
The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.
只读 可访问外部资源
输入模式
{'type': 'object', 'required': ['diagram_id'], 'properties': {'diagram_id': {'type': 'string', 'description': 'Diagram id/uuid'}}, 'additionalProperties': False}
get_framework_coverage
Get Framework Coverage
Compliance-framework coverage for a diagram (real, ControlCodeMap-backed), optionally for one framework, plus an optional crossmap relationship graph. Wraps derive_framework_coverage + crossmap_cypher.build_graph.
只读
输入模式
{'type': 'object', 'required': ['diagram_id'], 'properties': {'framework': {'type': 'string', 'description': "Optional framework filter (e.g. 'NIST-800-53', 'SOC2')"}, 'diagram_id': {'type': 'string', 'description': 'Diagram pk or uuid'}, 'include_graph': {'type': 'boolean', 'default': False, 'description': 'Also return the crossmap node/edge graph'}}, 'additionalProperties': False}
get_insights
Get diagram insights
Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.
只读 可访问外部资源
输入模式
{'type': 'object', 'required': ['diagram_id'], 'properties': {'diagram_id': {'type': 'string', 'description': 'Diagram id/uuid'}}, 'additionalProperties': False}
get_remediation
Get Remediation Guidance
Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.
只读 可访问外部资源
输入模式
{'type': 'object', 'required': ['threat_id', 'rule_id'], 'properties': {'rule_id': {'type': 'string', 'description': 'Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)'}, 'threat_id': {'type': 'string', 'description': 'Threat id/code to remediate'}, 'resource_context': {'type': 'object', 'description': 'provider/resource_id/region/account_id/metadata'}}, 'additionalProperties': False}
get_traceability
Get Traceability Matrix
Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.
只读
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'description': 'Code-review scan id'}}, 'additionalProperties': False}
onboard_agents
Bulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cards` (name/url/provider/version/protocolVersion), or MCP client descriptors, under an optional `cohort` + shared auto-suspend policy. Idempotent. Requires the agent_governance licence + a manage:agents grant (or a first-party super-admin). Agents also self-onboard on first token/call.
输入模式
{'type': 'object', 'required': [], 'properties': {'agents': {'type': 'array', 'items': {}, 'description': 'Agent ids or descriptors ({agent_id, display?, cohort?})'}, 'cohort': {'type': 'string', 'description': 'Optional shared cohort (provider/model/deployment group)'}, 'agent_cards': {'type': 'array', 'items': {'type': 'object'}, 'description': 'A2A 1.0 Agent Cards ({name, url, provider, version, protocolVersion, ...})'}, 'auto_suspend_threshold': {'type': 'number', 'description': 'Optional 0..1 auto-suspend deviation threshold for the cohort policy'}}, 'additionalProperties': False}
verify_threats_in_code
Verify Threats in Code
Verify whether threats are mitigated in a scan's uploaded code. With `threat_id`, verifies one threat synchronously and returns the verdict; without it, verifies every diagram threat in the background. Wraps code_review ThreatVerificationService.
只读 可访问外部资源
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'async_': {'type': 'boolean', 'default': True}, 'scan_id': {'type': 'string', 'description': 'CodeReviewScan id (uuid)'}, 'threat_id': {'type': 'string', 'description': 'Optional: a single threat id or code'}, 'code_content': {'type': 'string', 'description': 'Optional inline code context'}, 'repository_id': {'type': 'string', 'description': 'Optional connected repo to fetch code from'}}, 'additionalProperties': False}
已添加
get_insights
2026年9月17日 12:33
已添加
get_diagram_summary
2026年9月17日 12:33
已添加
apply_remediation
2026年9月17日 12:33
已添加
compliance_scan
2026年9月17日 12:33
已添加
code_review_scan
2026年9月17日 12:33
已添加
get_cloud_compliance
2026年9月17日 12:33
已添加
get_api_security
2026年9月17日 12:33
已添加
discover_shadow_ai
2026年9月17日 12:33
已添加
compliance_status
2026年9月17日 12:33
已添加
get_remediation
2026年9月17日 12:33
已添加
get_framework_coverage
2026年9月17日 12:33
已添加
get_traceability
2026年9月17日 12:33
已添加
verify_threats_in_code
2026年9月17日 12:33
已添加
generate_threat_model
2026年9月17日 12:33
已添加
onboard_agents
2026年9月17日 12:33
已添加
get_billing
2026年9月17日 12:33