ROADreconSAFE
Claude MCP server to perform analysis on ROADrecon data
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This MCP (Model Context Protocol) server provides AI assistants like Claude with access to your ROADRecon Azure AD data for security analysis.
The amazing ROADtools suite by dirkjanm can be found here: ROADRecon
Features
- Resources: Access Azure AD data from your ROADRecon instance
- Tools: Run security analysis on the data
- Prompts: Pre-built analysis templates for common security tasks
Prerequisites
- Python 3.8+
- A running ROADRecon instance with the web GUI accessible
- MCP-compatible client (Claude Desktop, etc.)
Installation
- Clone this repository
- Install dependencies:
pip install -r requirements.txt
Usage
Running the server
- Make sure your ROADRecon GUI is running (default: http://localhost:5000)
- Run the MCP server:
python roadrecon_mcp_server.py
- To specify a different ROADRecon URL:
ROADRECON_URL=http://localhost:8080 python roadrecon_mcp_server.py
Connecting with Claude Desktop
- Open Claude Desktop
- Go to Settings → Servers → Add Server
- Select "Add from running server"
- The server should appear in the list - click "Install"
More details on this step can be found here: https://modelcontextprotocol.io/quickstart/server
Using in Claude
Once connected, Claude can:
- Access Azure AD data via resources (e.g.,
roadrecon://users) - Run security analysis with tools (e.g.,
find_privileged_users) - Use pre-built prompts for common security tasks
Example Queries
- "Analyze the MFA status of users in this Azure AD tenant"
- "Find all users with privileged roles"
- "Check for applications with secrets or certificates"
- "Analyze the overall security posture of this Azure AD environment"
https://github.com/user-attachments/assets/806e9ccd-d80e-4058-be4f-9d37095f1fd6
Resources Available
roadrecon://stats- Summary statisticsroadrecon://users- All users
6aa65d81bd18OBSERVED · 2026-10-08Exposed tools (9)
9 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_conditional_access_policies | read | Analyze conditional access policies for security gaps and best practice alignment |
analyze_groups | read | Analyze group types and membership in the tenant |
analyze_legacy_authentication | read | Analyze for potential legacy authentication protocols that bypass MFA |
analyze_mfa_status | read | Analyze MFA status across all users |
analyze_pim_implementation | read | Analyze whether Privileged Identity Management (PIM) is implemented for just-in-time admin access |
analyze_service_principal_credentials | read | Analyze service principals for over-permissioned credentials with long expiration times |
find_applications_with_secrets | read | Find applications with secrets or certificates and analyze their expiration |
find_privileged_users | read | Find users with high-privilege directory roles |
identify_stale_accounts | read | Find user accounts that have not logged in or changed password in a specified number of days |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
mcp, httpx
Gates applied: no_behavioural_pass.
6aa65d81bd18full audit observations/trust-audit/mcp-server/atomicchonk__roadrecon.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 6aa65d81bd18 | SAFE | B | 89 | first audit |
Questions
What is the ROADrecon MCP server?
Claude MCP server to perform analysis on ROADrecon data
What tools does ROADrecon expose?
9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ROADrecon safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does ROADrecon need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (6aa65d81bd18), read on 2026-10-08. The repository is watched and re-audited when it changes.