Atlas / MCP servers / mordavid / BloodHound AI

BloodHound AISAFE

mcp/mordavid/bloodhound-ai

BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
75 75r · 0w · 0d
Transport
stdio
License
—
Stars
377
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) Server for BloodHound

BloodHound-MCP is a powerful integration that brings the capabilities of Model Context Procotol (MCP) Server to BloodHound, the industry-standard tool for Active Directory security analysis. This integration allows you to analyze BloodHound data using natural language, making complex Active Directory attack path analysis accessible to everyone.

🥇 First-Ever BloodHound AI Integration! This is the first integration that connects BloodHound with AI through MCP, originally announced here.

🔍 What is BloodHound-MCP?

BloodHound-MCP combines the power of:

  • BloodHound: Industry-standard tool for visualizing and analyzing Active Directory attack paths
  • Model Context Protocol (MCP): An open protocol for creating custom AI tools, compatible with various AI models
  • Neo4j: Graph database used by BloodHound to store AD relationship data

With over 75 specialized tools based on the original BloodHound CE Cypher queries, BloodHound-MCP allows security professionals to:

  • Query BloodHound data using natural language
  • Discover complex attack paths in Active Directory environments
  • Assess Active Directory security posture more efficiently
  • Generate detailed security reports for stakeholders

📱 Community

Join our Telegram channel for updates, tips, and discussion:

🌟 Star History

[](https://www.star-history.com/#MorDavid/BloodHound-MCP-AI&Date)

✨ Features

  • Natural Language Interface: Query BloodHound data using plain English
  • Comprehensive Analysis Categories:
  • Domain structure mapping
  • Privilege escalation paths
  • Kerberos security issues (Kerbero
Read from source at commit 0224c0cdad38OBSERVED · 2026-10-02
02

Exposed tools (75)

75 read · 0 write · 0 destructive.

ToolRiskDescription
find_all_domain_adminsreadquery =
find_all_kerberoastable_usersreadquery =
find_asreproast_usersreadquery =
find_ca_administratorsreadquery =
find_certificate_enrollment_rightsreadquery =
find_computers_in_protected_usersreadquery =
find_computers_no_smb_signingreadquery =
find_computers_outbound_ntlm_denyreadquery =
find_computers_webclient_runningreadquery =
find_dcs_vulnerable_ntlm_relayreadquery =
find_dcs_weak_certificate_bindingreadquery =
find_dcsync_privilegesreadquery =
find_devices_unsupported_osreadquery =
find_disabled_azure_tier_zero_principalsreadquery =
find_disabled_tier_zero_principalsreadquery =
find_domain_admin_non_dc_logonsreadquery =
find_domain_users_high_value_pathsreadquery =
find_domain_users_laps_readersreadquery =
find_domain_users_local_adminsreadquery =
find_domain_users_privilegesreadquery =
find_domain_users_server_rdpreadquery =
find_domain_users_workstation_rdpreadquery =
find_domains_with_machine_quotareadquery =
find_enrollment_agent_templatesreadquery =
find_entra_users_in_domain_adminsreadquery =
find_esc1_vulnerable_templatesreadquery =
find_esc2_vulnerable_templatesreadquery =
find_esc8_vulnerable_casreadquery =
find_external_tier_zero_usersreadquery =
find_foreign_group_membershipsreadquery =
find_foreign_tier_zero_principalsreadquery =
find_global_administratorsreadquery =
find_high_privileged_role_membersreadquery =
find_inactive_tier_zero_principalsreadquery =
find_kerberoastable_most_adminreadquery =
find_kerberoastable_tier_zeroreadquery =
find_nested_tier_zero_groupsreadquery =
find_ntlm_relay_edgesreadquery =
find_onprem_users_in_entra_groupsreadquery =
find_onprem_users_owning_entra_objectsreadquery =
find_paths_from_azure_apps_to_tier_zeroreadquery =
find_paths_from_domain_users_to_tier_zeroreadquery =
find_paths_from_entra_to_tier_zeroreadquery =
find_paths_from_kerberoastable_to_dareadquery =
find_paths_from_owned_objectsreadquery =
find_paths_to_azure_subscriptionsreadquery =
find_paths_to_privileged_rolesreadquery =
find_pki_hierarchyreadquery =
find_principals_des_only_kerberosreadquery =
find_principals_reversible_encryptionreadquery =
find_principals_weak_kerberos_encryptionreadquery =
find_public_key_servicesreadquery =
find_shortest_paths_to_domain_adminsreadquery =
find_shortest_paths_to_tier_zeroreadquery =
find_shortest_paths_unconstrained_delegationreadquery =
find_smartcard_dont_expire_domainsreadquery =
find_sp_graph_assignmentsreadquery =
find_synced_tier_zero_principalsreadquery =
find_tier_zero_locationsreadquery =
find_tier_zero_non_expiring_passwordsreadquery =
find_tier_zero_without_smartcardreadquery =
find_two_way_forest_trust_delegationreadquery =
find_unsupported_operating_systemsreadquery =
find_users_password_not_rotatedreadquery =
find_users_with_no_password_requiredreadquery =
map_domain_trustsreadquery =
map_ou_structurereadquery =
onprem_users_direct_azure_rolesreadquery =
onprem_users_direct_entra_rolesreadquery =
onprem_users_group_azure_rolesreadquery =
onprem_users_group_entra_rolesreadquery =
query_bloodhoundreaddatabases = [
sp_app_role_grantreadquery =
templates_no_security_extreadquery =
templates_with_user_sanreadquery =
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
BloodHound-MCP.py:550
OR 'RC4-HMAC-MD5' IN u.supportedencryptiontypes
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
neo4j, python-dotenv, mcp-server, fastmcp
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-02 · audit v0.4.1 · source sha 0224c0cdad38full audit observations/trust-audit/mcp-server/mordavid__bloodhound-ai.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-020224c0cdad38SAFEB89first audit
05

Questions

What is the BloodHound AI MCP server?

BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.

What tools does BloodHound AI expose?

75 in total: 75 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is BloodHound AI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does BloodHound AI need?

It reads BLOODHOUND_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does BloodHound AI run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (0224c0cdad38), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement