Atlas / MCP servers / google / mcp-security

mcp-securityBLOCK

mcp/google/mcp-security
Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
117 87r · 26w · 4d
Transport
stdio
License
Apache-2.0
Stars
531
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This repository contains Model Context Protocol (MCP) servers that enable MCP clients (like Claude Desktop or the cline.bot VS Code extension) to access Google's security products and services:

  1. Remote MCP Server for Google SecOps - Fully managed, enterprise-ready MCP server (Recommended)
  2. Google Security Operations (Chronicle) - For threat detection, investigation, and hunting
  3. Google Security Operations SOAR - For security orchestration, automation, and response
  4. Google Threat Intelligence (GTI) - For access to Google's threat intelligence data
  5. Security Command Center (SCC) - For cloud security and risk management

For the new Remote MCP Server, please see the launch announcement and the setup guide.

Each server can be enabled and run separately, allowing flexibility for environments that don't require all capabilities.

Documentation

Comprehensive documentation is available in the docs folder. You can:

  1. Read the markdown files directly in the repository
  2. View the documentation website at https://google.github.io/mcp-security/
  3. Generate HTML documentation locally using Sphinx (see instructions in the docs folder)

The documentation covers:

  • Detailed information about each MCP server
  • Configuration options and requirements
  • Usage examples and best practices

To get started with the documentation, see docs/index.md.

Authentication

The server uses Google's authentication. Make sure you have either:

  1. Set up Application Default Credentials (ADC)
  2. Set a GOOGLEAPPLICATIONCREDENTIALS environment variable
  3. Used gcloud auth application-default login

Standalone Usage

Each MCP server can be installed and used as a standalone package.

Installati

Read from source at commit afbad2fbd487OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add google-secops-mcp --env GOOGLE_API_KEY=${GOOGLE_API_KEY} --env GOOGLE_APPLICATION_CREDENTIALS=${GOOGLE_APPLICATION_CREDENTIALS} --env IDP_CLIENT_SECRET=${IDP_CLIENT_SECRET} --env VT_APIKEY=${VT_APIKEY} -- uvx google-secops-mcp
claude-desktop
{
  "mcpServers": {
    "google-secops-mcp": {
      "command": "uvx",
      "args": [
        "google-secops-mcp"
      ],
      "env": {
        "GOOGLE_API_KEY": "${GOOGLE_API_KEY}",
        "GOOGLE_APPLICATION_CREDENTIALS": "${GOOGLE_APPLICATION_CREDENTIALS}",
        "IDP_CLIENT_SECRET": "${IDP_CLIENT_SECRET}",
        "VT_APIKEY": "${VT_APIKEY}"
      }
    }
  }
}
03

Exposed tools (117)

87 read · 26 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activate_parserreadActivate a parser for a specific log type in Chronicle.
add_rows_to_data_tablewriteAdd rows to an existing data table in Chronicle SIEM.
analyse_filewriteUpload and analyse the file in VirusTotal.
authenticateread
compute_rule_exclusion_activityreadCalculate activity statistics for a rule exclusion.
create_collectionwriteCreates a new collection in Google Threat Intelligence.
create_data_tablewriteCreate a new data table in Chronicle SIEM.
create_feedwriteCreate a new feed in Chronicle.
create_parserwriteCreate a new parser for a specific log type in Chronicle.
create_reference_listwriteCreate a new reference list in Chronicle SIEM.
create_retrohuntwriteCreate a retrohunt to run detection rule against historical data.
create_rulewriteCreate a new detection rule in Chronicle SIEM.
create_rule_exclusionwriteCreate a new rule exclusion in Chronicle SIEM.
create_watchlistwriteCreate a new watchlist in Chronicle SIEM.
deactivate_parserreadDeactivate a parser for a specific log type in Chronicle.
delete_data_table_rowsdestructiveDelete specific rows from a data table in Chronicle SIEM.
delete_feeddestructiveDelete a feed from Chronicle.
delete_watchlistdestructiveDelete a watchlist from Chronicle SIEM.
disable_feedwriteDisable an active feed in Chronicle.
do_update_security_alertwrite
enable_feedwriteEnable a inactive feed in Chronicle.
export_udm_search_csvreadExport UDM search results to CSV format for analysis and reporting.
fetch_associated_investigationsreadRetrieve investigations associated with alerts or cases.
find_udm_field_valuesreadFind and autocomplete UDM field values in Chronicle SIEM.
generate_feed_secretreadGenerate authentication secret for a feed.
get_alerts_for_hostread
get_available_log_typesreadGet available log types supported by Chronicle for ingestion.
get_case_full_detailsreadRetrieve comprehensive details for a specific case by aggregating its core information, associated alerts, and comments.
get_collection_feature_matchesreadRetrieves Indicators of Compromise (IOCs) from a collection that match a specific feature.
get_collection_mitre_treereadRetrieves the Mitre tactics and techniques associated with a threat.
get_collection_reportreadAt Google Threat Intelligence, threats are modeled as
get_collection_rulesreadRetrieve top N community rules and all curated hunting rules for a specific collection.
get_collection_timeline_eventsreadRetrieves timeline events from the given collection, when available.
get_collections_commonalitiesreadRetrieve the common characteristics or features (attributes / relationships) of the indicators of compromise (IoC) within a collection, identified by its ID.
get_curated_rulereadRetrieve specific curated rule details by rule ID.
get_curated_rule_by_namereadFind curated rule by display name.
get_curated_rule_setwriteRetrieve specific curated rule set details by ID.
get_detection_rulereadRetrieve the complete definition and metadata of a specific detection rule from Chronicle SIEM.
get_domain_reportreadGet a comprehensive domain analysis report from Google Threat Intelligence.
get_entities_related_to_a_collectionreadRetrieve entities related to the the given collection ID.
get_entities_related_to_a_domainreadRetrieve entities related to the the given domain.
get_entities_related_to_a_filereadRetrieve entities related to the the given file hash.
get_entities_related_to_a_hunting_rulesetreadRetrieve entities related to the the given Hunting Ruleset.
get_entities_related_to_an_ip_addressreadRetrieve entities related to the the given IP Address.
get_entities_related_to_an_urlreadRetrieve entities related to the the given URL.
get_feedreadGet detailed information about a specific feed.
get_file_behavior_reportreadRetrieve the file behaviour report of the given file behaviour identifier.
get_file_behavior_summaryreadRetrieve a summary of all the file behavior reports from all the sandboxes.
get_file_reportreadGet a comprehensive file analysis report using its hash (MD5/SHA-1/SHA-256).
get_finding_detailsreadName: get_finding_details
get_finding_remediationreadName: get_finding_remediation
get_host_informationread
get_hunting_rulesetreadGet a Hunting Ruleset object from Google Threat Intelligence.
get_investigationreadRetrieve specific investigation by ID.
get_ioc_matchesreadGet Indicators of Compromise (IoCs) matches from Chronicle SIEM.
get_ip_address_reportreadGet a comprehensive IP Address analysis report from Google Threat Intelligence.
get_parserreadGet details of a specific parser in Chronicle.
get_recent_loginread
get_reference_listreadGet details and contents of a reference list in Chronicle SIEM.
get_retrohuntreadGet status and results of a retrohunt operation.
get_rule_detectionsreadRetrieves historical detections generated by a specific Chronicle SIEM rule.
get_rule_exclusionreadGet detailed information about a specific rule exclusion.
get_security_alert_by_idreadGet security alert by ID directly from Chronicle SIEM.
get_security_alertsreadGet security alerts directly from Chronicle SIEM.
get_threat_intelreadGet answers to security questions using Chronicle
get_threat_profilereadGet Threat Profile object.
get_threat_profile_associations_timelinereadRetrieves the associations timeline for the given Threat Profile.
get_threat_profile_recommendationsreadReturns the list of objects associated to a given Threat Profile.
get_url_reportreadGet a comprehensive URL analysis report from Google Threat Intelligence.
get_user_trust_assessmentread
get_watchlistreadGet detailed information about a specific watchlist.
ingest_raw_logreadIngest raw logs directly into Chronicle SIEM.
ingest_udm_eventsreadIngest UDM events directly into Chronicle SIEM.
list_casesreadList cases available in the Security Orchestration, Automation, and Response (SOAR) platform.
list_curated_rule_set_deploymentswriteList deployment status of all curated rule sets.
list_curated_rule_setsreadList all curated rule sets available in Chronicle.
list_curated_rulesreadList all curated detection rules available in Chronicle.
list_data_table_rowsreadList rows in a data table in Chronicle SIEM.
list_feedsreadList all feeds configured in Chronicle.
list_investigationsreadList all investigations in Chronicle instance.
list_parsersreadList parsers in Chronicle, optionally filtered by log type.
list_rule_errorsreadLists execution errors for a specific Chronicle SIEM rule.
list_rule_exclusionsreadList all rule exclusions in Chronicle SIEM.
list_security_rulesreadList security detection rules configured in Chronicle SIEM, with support for pagination.
list_threat_profilesreadList your Threat Profiles at Google Threat Intelligence.
list_watchlistsreadList all watchlists in Chronicle SIEM.
lookup_entityreadLook up an entity (IP, domain, hash, user, etc.) in Chronicle SIEM for enrichment.
patch_rule_exclusionwriteUpdate an existing rule exclusion in Chronicle SIEM.
run_parser_against_sample_logswriteRun a parser against sample logs to test parsing logic.
search_campaignsreadSearch threat campaigns in the Google Threat Intelligence platform.
search_curated_detectionsreadSearch detections generated by a specific curated rule.
search_digital_threat_monitoringreadSearch for historical data in Digital Threat Monitoring (DTM) using Lucene syntax.
search_findingsreadName: search_findings
search_findings_by_compliancereadName: search_findings_by_compliance
search_iocsreadSearch Indicators of Compromise (IOC) in the Google Threat Intelligence platform.
search_malware_familiesreadSearch malware families in the Google Threat Intelligence platform.
search_rule_alertsreadSearch for alerts generated by detection rules across time range.
search_security_eventsreadSearch for security events in Chronicle SIEM using natural language.
search_security_rulesreadSearch security detection rules configured in Chronicle SIEM.
search_software_toolkitsreadSearch software toolkits (or just tools) in the Google Threat Intelligence platform.
search_threat_actorsreadSearch threat actors in the Google Threat Intelligence platform.
search_threat_reportsreadSearch threat reports in the Google Threat Intelligence platform.
search_threatsreadSearch threats in the Google Threat Intelligence platform.
search_udmreadSearch UDM events using UDM query in Chronicle.
search_vulnerabilitiesreadSearch vulnerabilities (CVEs) in the Google Threat Intelligence platform.
set_finding_mutewriteName: set_finding_mute
test_rulereadTest a detection rule against historical data in Chronicle SIEM.
top_vulnerability_findingsreadName: top_vulnerability_findings
trigger_investigationwriteCreate new investigation for a specific alert.
update_collection_attributeswriteAllows updating a collection
update_curated_rule_set_deploymentwriteUpdate deployment configuration for a curated rule set.
update_feedwriteUpdate an existing feed in Chronicle.
update_iocs_in_collectiondestructiveUpdates (add or remove) Indicators of Compromise (IOCs) to a collection.
update_reference_listwriteUpdate an existing reference list in Chronicle SIEM.
update_rule_exclusion_deploymentwriteManage deployment settings for a rule exclusion.
update_watchlistwriteUpdate an existing watchlist in Chronicle SIEM.
validate_rulereadValidate a YARA-L 2.0 detection rule syntax in Chronicle SIEM.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
run-with-google-adk/src/mcp_security_agent/cli.py:40
console.print(f"ADC: [cyan]{settings.google_application_credentials or 'Default (~/.config/gcloud/...)'}[/cyan]")
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agent
.agent
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
server/secops-soar/secops_soar_mcp/server.py:108
module = importlib.import_module(module_import_path)
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
extensions/google-secops/skills/setup-gemini-cli/SKILL.md:18
*   If not, guide: `curl -LsSf https://astral.sh/uv/install.sh | sh`
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_data_table_rows, delete_feed, delete_watchlist, update_iocs_in_collection
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
server/secops-soar/secops_soar_mcp/utils/utils.py:92
name_hash = hashlib.md5(original_name_for_fallback.encode()).hexdigest()[:6]
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server/secops/secops_mcp/tools/parser_management.py:225
parser_code = base64.b64decode(parser["cbn"]).decode("utf-8")
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs/requirements.txt
sphinx, furo, sphinx-autobuild, sphinx-copybutton, sphinx-design, sphinx-rtd-theme, sphinx-tabs, myst-parser
Why it matters. 13 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/soar_integrations/risk_iq_passive_total.md:69
*(Details on configuring the integration, including the PassiveTotal API endpoint URL, API User email, and API Key, along with any specific SOAR platform settings, should be added here.)*
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/servers/scc_mcp.md:100
Description: Firewall rule allows unrestricted access
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/servers/secops_soar_mcp.md:10
2. **API Access** - SOAR API key with appropriate permissions
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/superpowers/plans/2026-08-30-adk-v2-refactor.md:16
- All tests must be hermetic and executable via `pytest` without requiring external network access or live cloud credentials.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha afbad2fbd487full audit observations/trust-audit/mcp-server/google__mcp-security.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06afbad2fbd487BLOCKD69first audit
06

Questions

What tools does mcp-security expose?

117 in total: 87 read-only, 26 that write, and 4 that can delete or overwrite (delete_data_table_rows, delete_feed, delete_watchlist, update_iocs_in_collection). Every one is listed on this page with its risk.

Is mcp-security safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does mcp-security need?

It reads GOOGLE_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, IDP_CLIENT_SECRET, VT_APIKEY and XDR_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does mcp-security run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as google-secops-mcp.

How current is this page?

The grade is for one exact copy of the source (afbad2fbd487), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement