mcp-securityBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This repository contains Model Context Protocol (MCP) servers that enable MCP clients (like Claude Desktop or the cline.bot VS Code extension) to access Google's security products and services:
- Remote MCP Server for Google SecOps - Fully managed, enterprise-ready MCP server (Recommended)
- Google Security Operations (Chronicle) - For threat detection, investigation, and hunting
- Google Security Operations SOAR - For security orchestration, automation, and response
- Google Threat Intelligence (GTI) - For access to Google's threat intelligence data
- Security Command Center (SCC) - For cloud security and risk management
For the new Remote MCP Server, please see the launch announcement and the setup guide.
Each server can be enabled and run separately, allowing flexibility for environments that don't require all capabilities.
Documentation
Comprehensive documentation is available in the docs folder. You can:
- Read the markdown files directly in the repository
- View the documentation website at https://google.github.io/mcp-security/
- Generate HTML documentation locally using Sphinx (see instructions in the docs folder)
The documentation covers:
- Detailed information about each MCP server
- Configuration options and requirements
- Usage examples and best practices
To get started with the documentation, see docs/index.md.
Authentication
The server uses Google's authentication. Make sure you have either:
- Set up Application Default Credentials (ADC)
- Set a GOOGLEAPPLICATIONCREDENTIALS environment variable
- Used
gcloud auth application-default login
Standalone Usage
Each MCP server can be installed and used as a standalone package.
Installati
afbad2fbd487OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add google-secops-mcp --env GOOGLE_API_KEY=${GOOGLE_API_KEY} --env GOOGLE_APPLICATION_CREDENTIALS=${GOOGLE_APPLICATION_CREDENTIALS} --env IDP_CLIENT_SECRET=${IDP_CLIENT_SECRET} --env VT_APIKEY=${VT_APIKEY} -- uvx google-secops-mcp{
"mcpServers": {
"google-secops-mcp": {
"command": "uvx",
"args": [
"google-secops-mcp"
],
"env": {
"GOOGLE_API_KEY": "${GOOGLE_API_KEY}",
"GOOGLE_APPLICATION_CREDENTIALS": "${GOOGLE_APPLICATION_CREDENTIALS}",
"IDP_CLIENT_SECRET": "${IDP_CLIENT_SECRET}",
"VT_APIKEY": "${VT_APIKEY}"
}
}
}
}Exposed tools (117)
87 read · 26 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
activate_parser | read | Activate a parser for a specific log type in Chronicle. |
add_rows_to_data_table | write | Add rows to an existing data table in Chronicle SIEM. |
analyse_file | write | Upload and analyse the file in VirusTotal. |
authenticate | read | |
compute_rule_exclusion_activity | read | Calculate activity statistics for a rule exclusion. |
create_collection | write | Creates a new collection in Google Threat Intelligence. |
create_data_table | write | Create a new data table in Chronicle SIEM. |
create_feed | write | Create a new feed in Chronicle. |
create_parser | write | Create a new parser for a specific log type in Chronicle. |
create_reference_list | write | Create a new reference list in Chronicle SIEM. |
create_retrohunt | write | Create a retrohunt to run detection rule against historical data. |
create_rule | write | Create a new detection rule in Chronicle SIEM. |
create_rule_exclusion | write | Create a new rule exclusion in Chronicle SIEM. |
create_watchlist | write | Create a new watchlist in Chronicle SIEM. |
deactivate_parser | read | Deactivate a parser for a specific log type in Chronicle. |
delete_data_table_rows | destructive | Delete specific rows from a data table in Chronicle SIEM. |
delete_feed | destructive | Delete a feed from Chronicle. |
delete_watchlist | destructive | Delete a watchlist from Chronicle SIEM. |
disable_feed | write | Disable an active feed in Chronicle. |
do_update_security_alert | write | |
enable_feed | write | Enable a inactive feed in Chronicle. |
export_udm_search_csv | read | Export UDM search results to CSV format for analysis and reporting. |
fetch_associated_investigations | read | Retrieve investigations associated with alerts or cases. |
find_udm_field_values | read | Find and autocomplete UDM field values in Chronicle SIEM. |
generate_feed_secret | read | Generate authentication secret for a feed. |
get_alerts_for_host | read | |
get_available_log_types | read | Get available log types supported by Chronicle for ingestion. |
get_case_full_details | read | Retrieve comprehensive details for a specific case by aggregating its core information, associated alerts, and comments. |
get_collection_feature_matches | read | Retrieves Indicators of Compromise (IOCs) from a collection that match a specific feature. |
get_collection_mitre_tree | read | Retrieves the Mitre tactics and techniques associated with a threat. |
get_collection_report | read | At Google Threat Intelligence, threats are modeled as |
get_collection_rules | read | Retrieve top N community rules and all curated hunting rules for a specific collection. |
get_collection_timeline_events | read | Retrieves timeline events from the given collection, when available. |
get_collections_commonalities | read | Retrieve the common characteristics or features (attributes / relationships) of the indicators of compromise (IoC) within a collection, identified by its ID. |
get_curated_rule | read | Retrieve specific curated rule details by rule ID. |
get_curated_rule_by_name | read | Find curated rule by display name. |
get_curated_rule_set | write | Retrieve specific curated rule set details by ID. |
get_detection_rule | read | Retrieve the complete definition and metadata of a specific detection rule from Chronicle SIEM. |
get_domain_report | read | Get a comprehensive domain analysis report from Google Threat Intelligence. |
get_entities_related_to_a_collection | read | Retrieve entities related to the the given collection ID. |
get_entities_related_to_a_domain | read | Retrieve entities related to the the given domain. |
get_entities_related_to_a_file | read | Retrieve entities related to the the given file hash. |
get_entities_related_to_a_hunting_ruleset | read | Retrieve entities related to the the given Hunting Ruleset. |
get_entities_related_to_an_ip_address | read | Retrieve entities related to the the given IP Address. |
get_entities_related_to_an_url | read | Retrieve entities related to the the given URL. |
get_feed | read | Get detailed information about a specific feed. |
get_file_behavior_report | read | Retrieve the file behaviour report of the given file behaviour identifier. |
get_file_behavior_summary | read | Retrieve a summary of all the file behavior reports from all the sandboxes. |
get_file_report | read | Get a comprehensive file analysis report using its hash (MD5/SHA-1/SHA-256). |
get_finding_details | read | Name: get_finding_details |
get_finding_remediation | read | Name: get_finding_remediation |
get_host_information | read | |
get_hunting_ruleset | read | Get a Hunting Ruleset object from Google Threat Intelligence. |
get_investigation | read | Retrieve specific investigation by ID. |
get_ioc_matches | read | Get Indicators of Compromise (IoCs) matches from Chronicle SIEM. |
get_ip_address_report | read | Get a comprehensive IP Address analysis report from Google Threat Intelligence. |
get_parser | read | Get details of a specific parser in Chronicle. |
get_recent_login | read | |
get_reference_list | read | Get details and contents of a reference list in Chronicle SIEM. |
get_retrohunt | read | Get status and results of a retrohunt operation. |
get_rule_detections | read | Retrieves historical detections generated by a specific Chronicle SIEM rule. |
get_rule_exclusion | read | Get detailed information about a specific rule exclusion. |
get_security_alert_by_id | read | Get security alert by ID directly from Chronicle SIEM. |
get_security_alerts | read | Get security alerts directly from Chronicle SIEM. |
get_threat_intel | read | Get answers to security questions using Chronicle |
get_threat_profile | read | Get Threat Profile object. |
get_threat_profile_associations_timeline | read | Retrieves the associations timeline for the given Threat Profile. |
get_threat_profile_recommendations | read | Returns the list of objects associated to a given Threat Profile. |
get_url_report | read | Get a comprehensive URL analysis report from Google Threat Intelligence. |
get_user_trust_assessment | read | |
get_watchlist | read | Get detailed information about a specific watchlist. |
ingest_raw_log | read | Ingest raw logs directly into Chronicle SIEM. |
ingest_udm_events | read | Ingest UDM events directly into Chronicle SIEM. |
list_cases | read | List cases available in the Security Orchestration, Automation, and Response (SOAR) platform. |
list_curated_rule_set_deployments | write | List deployment status of all curated rule sets. |
list_curated_rule_sets | read | List all curated rule sets available in Chronicle. |
list_curated_rules | read | List all curated detection rules available in Chronicle. |
list_data_table_rows | read | List rows in a data table in Chronicle SIEM. |
list_feeds | read | List all feeds configured in Chronicle. |
list_investigations | read | List all investigations in Chronicle instance. |
list_parsers | read | List parsers in Chronicle, optionally filtered by log type. |
list_rule_errors | read | Lists execution errors for a specific Chronicle SIEM rule. |
list_rule_exclusions | read | List all rule exclusions in Chronicle SIEM. |
list_security_rules | read | List security detection rules configured in Chronicle SIEM, with support for pagination. |
list_threat_profiles | read | List your Threat Profiles at Google Threat Intelligence. |
list_watchlists | read | List all watchlists in Chronicle SIEM. |
lookup_entity | read | Look up an entity (IP, domain, hash, user, etc.) in Chronicle SIEM for enrichment. |
patch_rule_exclusion | write | Update an existing rule exclusion in Chronicle SIEM. |
run_parser_against_sample_logs | write | Run a parser against sample logs to test parsing logic. |
search_campaigns | read | Search threat campaigns in the Google Threat Intelligence platform. |
search_curated_detections | read | Search detections generated by a specific curated rule. |
search_digital_threat_monitoring | read | Search for historical data in Digital Threat Monitoring (DTM) using Lucene syntax. |
search_findings | read | Name: search_findings |
search_findings_by_compliance | read | Name: search_findings_by_compliance |
search_iocs | read | Search Indicators of Compromise (IOC) in the Google Threat Intelligence platform. |
search_malware_families | read | Search malware families in the Google Threat Intelligence platform. |
search_rule_alerts | read | Search for alerts generated by detection rules across time range. |
search_security_events | read | Search for security events in Chronicle SIEM using natural language. |
search_security_rules | read | Search security detection rules configured in Chronicle SIEM. |
search_software_toolkits | read | Search software toolkits (or just tools) in the Google Threat Intelligence platform. |
search_threat_actors | read | Search threat actors in the Google Threat Intelligence platform. |
search_threat_reports | read | Search threat reports in the Google Threat Intelligence platform. |
search_threats | read | Search threats in the Google Threat Intelligence platform. |
search_udm | read | Search UDM events using UDM query in Chronicle. |
search_vulnerabilities | read | Search vulnerabilities (CVEs) in the Google Threat Intelligence platform. |
set_finding_mute | write | Name: set_finding_mute |
test_rule | read | Test a detection rule against historical data in Chronicle SIEM. |
top_vulnerability_findings | read | Name: top_vulnerability_findings |
trigger_investigation | write | Create new investigation for a specific alert. |
update_collection_attributes | write | Allows updating a collection |
update_curated_rule_set_deployment | write | Update deployment configuration for a curated rule set. |
update_feed | write | Update an existing feed in Chronicle. |
update_iocs_in_collection | destructive | Updates (add or remove) Indicators of Compromise (IOCs) to a collection. |
update_reference_list | write | Update an existing reference list in Chronicle SIEM. |
update_rule_exclusion_deployment | write | Manage deployment settings for a rule exclusion. |
update_watchlist | write | Update an existing watchlist in Chronicle SIEM. |
validate_rule | read | Validate a YARA-L 2.0 detection rule syntax in Chronicle SIEM. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
console.print(f"ADC: [cyan]{settings.google_application_credentials or 'Default (~/.config/gcloud/...)'}[/cyan]").agent
module = importlib.import_module(module_import_path)
* If not, guide: `curl -LsSf https://astral.sh/uv/install.sh | sh`
delete_data_table_rows, delete_feed, delete_watchlist, update_iocs_in_collection
.gitmodules
.nojekyll
name_hash = hashlib.md5(original_name_for_fallback.encode()).hexdigest()[:6]
parser_code = base64.b64decode(parser["cbn"]).decode("utf-8")sphinx, furo, sphinx-autobuild, sphinx-copybutton, sphinx-design, sphinx-rtd-theme, sphinx-tabs, myst-parser
*(Details on configuring the integration, including the PassiveTotal API endpoint URL, API User email, and API Key, along with any specific SOAR platform settings, should be added here.)*
Description: Firewall rule allows unrestricted access
2. **API Access** - SOAR API key with appropriate permissions
- All tests must be hermetic and executable via `pytest` without requiring external network access or live cloud credentials.
Gates applied: no_behavioural_pass.
afbad2fbd487full audit observations/trust-audit/mcp-server/google__mcp-security.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | afbad2fbd487 | BLOCK | D | 69 | first audit |
Questions
What tools does mcp-security expose?
117 in total: 87 read-only, 26 that write, and 4 that can delete or overwrite (delete_data_table_rows, delete_feed, delete_watchlist, update_iocs_in_collection). Every one is listed on this page with its risk.
Is mcp-security safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does mcp-security need?
It reads GOOGLE_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, IDP_CLIENT_SECRET, VT_APIKEY and XDR_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcp-security run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as google-secops-mcp.
How current is this page?
The grade is for one exact copy of the source (afbad2fbd487), read on 2026-10-06. The repository is watched and re-audited when it changes.