此 MCP 可以做什么
Performs threat modeling, code security, API and cloud security scans, compliance analysis, and governed remediation.
工具
输入模式
{'type': 'object', 'required': ['threat_id', 'rule_id'], 'properties': {'rule_id': {'type': 'string', 'description': 'Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)'}, 'threat_id': {'type': 'string', 'description': 'Threat id/code to remediate'}, 'resource_context': {'type': 'object', 'description': 'provider/resource_id/region/account_id/metadata'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'description': 'Id of an existing code-review scan to (re)run'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['scan_type'], 'properties': {'source': {'type': 'string', 'description': 'Scan source (default: hybrid)'}, 'scan_type': {'enum': ['platform', 'compliance', 'pipeline', 'sbom', 'diagram', 'account'], 'type': 'string', 'description': 'platform | compliance | pipeline | sbom'}, 'account_id': {'type': 'string', 'description': 'Cloud account id (account-scoped scans)'}, 'diagram_id': {'type': 'string', 'description': 'Diagram id/uuid (diagram-scoped scans)'}, 'frameworks': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional standard/framework ids to scope the scan'}, 'severity_filter': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional severity levels to include'}, 'simulation_mode': {'type': 'boolean', 'description': 'Dry-run the scan without side effects'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': [], 'properties': {'scan_id': {'type': 'string', 'description': 'Optional anchor scan; latest is used if omitted'}, 'diagram_id': {'type': 'string', 'description': 'Optional diagram to add framework coverage for'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'integer', 'default': 15, 'description': 'Max discoveries to return'}, 'scan_id': {'type': 'string', 'description': 'Optional CodeReviewScan id; company-wide latest if omitted'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['nodes'], 'properties': {'name': {'type': 'string', 'description': 'Threat model name'}, 'edges': {'type': 'array', 'items': {'type': 'object'}, 'description': 'ReactFlow edges'}, 'nodes': {'type': 'array', 'items': {'type': 'object'}, 'description': 'ReactFlow nodes (each: id, position, data.label)'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'integer', 'default': 20, 'description': 'Max endpoints to return'}, 'scan_id': {'type': 'string', 'description': 'Optional CodeReviewScan id; company-wide if omitted'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': [], 'properties': {'request_plan': {'type': 'string', 'description': 'Optional plan key to request (pro|max|…) — files a request for super-admin approval; does not grant or charge'}, 'topup_amount': {'type': 'number', 'description': 'Optional EUR amount to top up the credit wallet (returns a hosted Checkout URL)'}, 'checkout_request_id': {'type': 'string', 'description': 'Approved license_request_id to complete payment for (returns a hosted Checkout URL)'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': [], 'properties': {'account_id': {'type': 'string', 'description': 'Optional single cloud Account id; all company accounts if omitted'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['diagram_id'], 'properties': {'diagram_id': {'type': 'string', 'description': 'Diagram id/uuid'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['diagram_id'], 'properties': {'framework': {'type': 'string', 'description': "Optional framework filter (e.g. 'NIST-800-53', 'SOC2')"}, 'diagram_id': {'type': 'string', 'description': 'Diagram pk or uuid'}, 'include_graph': {'type': 'boolean', 'default': False, 'description': 'Also return the crossmap node/edge graph'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['diagram_id'], 'properties': {'diagram_id': {'type': 'string', 'description': 'Diagram id/uuid'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['threat_id', 'rule_id'], 'properties': {'rule_id': {'type': 'string', 'description': 'Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)'}, 'threat_id': {'type': 'string', 'description': 'Threat id/code to remediate'}, 'resource_context': {'type': 'object', 'description': 'provider/resource_id/region/account_id/metadata'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'description': 'Code-review scan id'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': [], 'properties': {'agents': {'type': 'array', 'items': {}, 'description': 'Agent ids or descriptors ({agent_id, display?, cohort?})'}, 'cohort': {'type': 'string', 'description': 'Optional shared cohort (provider/model/deployment group)'}, 'agent_cards': {'type': 'array', 'items': {'type': 'object'}, 'description': 'A2A 1.0 Agent Cards ({name, url, provider, version, protocolVersion, ...})'}, 'auto_suspend_threshold': {'type': 'number', 'description': 'Optional 0..1 auto-suspend deviation threshold for the cohort policy'}}, 'additionalProperties': False}
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'async_': {'type': 'boolean', 'default': True}, 'scan_id': {'type': 'string', 'description': 'CodeReviewScan id (uuid)'}, 'threat_id': {'type': 'string', 'description': 'Optional: a single threat id or code'}, 'code_content': {'type': 'string', 'description': 'Optional inline code context'}, 'repository_id': {'type': 'string', 'description': 'Optional connected repo to fetch code from'}}, 'additionalProperties': False}
近期工具变更
类似的 MCP 服务器
AgentAegis
Performs cybersecurity assessments including vulnerability scans, code and dependency audits, secret detection, threat intelligen…
Signal Oracle
Provides change-intelligence feeds for software dependencies, security, regulations, tariffs, vendor risk, and related operationa…
krabbot-devtools
Checks package installation risks, software stack end-of-life and exploited vulnerabilities, regulatory deadlines, and the credib…
dbtrail
Tracks MySQL row changes and supports recovery and attribution for forensic and compliance purposes.
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…