Red Hat LightspeedCAUTION
An MCP server to connect Red Hat Lightspeed functionality to an AI / LLM
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
(formerly known as Insights MCP)
Red Hat Lightspeed Model Context Protocol (MCP) server is a lightweight, self-hosted solution that connects LLM-based agents - such as Claude Desktop and other MCP-compatible tools - to Red Hat Lightspeed services.
Features
- Supports read-only operations: The server runs in read-only mode by default. Use
--all-toolsto enable write tools (e.g. create blueprints, run composes). RBAC permissions can also restrict access. - Provides natural language prompts: provides an ability to use natural language for querying Red Hat Lightspeed services
Supported Lightspeed Services
Setup and usage
Authentication
Note: Authentication is only required for accessing Red Hat Lightspeed APIs. The MCP server itself does not require authentication.
There are two ways to authenticate:
- Service Account (clientid + clientsecret) — create a service account and provide the credentials via environment variables or HTTP headers.
- JWT Bearer Token — provide a pre-existing JWT token via the
Authorization: BearerHTTP hea
02331765173aOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add red-hat-lightspeed-mcp --env LIGHTSPEED_CLIENT_ID=${LIGHTSPEED_CLIENT_ID} --env LIGHTSPEED_CLIENT_SECRET=${LIGHTSPEED_CLIENT_SECRET} -- docker run -i --rm ghcr.io/redhatinsights/red-hat-lightspeed-mcp:NoneExposed tools (18)
15 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_vuln_playbook | write | Create remediation playbook for given CVEs on given systems to mitigate vulnerabilities. |
example_tool | read | Example tool. |
explain_cves | read | Explain why CVEs are affecting my environment. |
find_host_by_name | read | Find a host by its hostname/display name. |
get_activation_key | read | Get a specific activation key by name. |
get_cve | read | Get details about specific CVE. |
get_cve_systems | read | Get list of systems affected by a given CVE. |
get_cves | read | Get list of CVEs affecting the account. |
get_host_details | read | Get detailed information for specific hosts by their IDs. |
get_host_system_profile | read | Get detailed system profile information for specific hosts. |
get_host_tags | read | Get tags for specific hosts. |
get_openapi | read | Get $container_brand_long Vulnerability OpenAPI specification in JSON format. |
get_system_cves | read | Get list of CVEs affecting a given system. |
get_systems | read | Get list of systems in $container_brand_long Vulnerability inventory. |
get_with_auth | write | Send GET request to Insights API with authentication. |
get_without_auth | write | Send GET request to Insights API without authentication. |
get_workspace | read | Get details for one or more workspaces by ID. |
lookup_tool_requirements | read | Return the console role names required for an MCP tool. |
Trust audit
CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (17)
.claude/skills
configs/tool_rest_map.json
module = importlib.import_module(module_name)
server_url = f"http://127.0.0.1:{port}/sse"server_url = f"http://127.0.0.1:{port}/mcp/".pre-commit-config.yaml
.spellcheck-en-custom.txt
.spellcheck.yml
.yamllint
docs/mkdocs/mcp-llm-eval.md
docs/mkdocs/toolsets.md
docs/mkdocs/usage.md
module = importlib.import_module(module_name)
module = importlib.import_module(module_path)
[](https://cursor.com/en/install-mcp?name=red-hat-lightspeed-mcp&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoicG9kbWFuIH
[](https://cursor.com/en/install-mcp?name=red-hat-lightspeed-mcp&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoicG9kbWFuIH
[](https://cursor.com/en/install-mcp?name=red-hat-lightspeed-mcp&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoicG9kbWFuIH
Gates applied: no_behavioural_pass.
02331765173afull audit observations/trust-audit/mcp-server/redhatinsights__red-hat-lightspeed.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 02331765173a | CAUTION | B | 80 | first audit |
Questions
What is the Red Hat Lightspeed MCP server?
An MCP server to connect Red Hat Lightspeed functionality to an AI / LLM
What tools does Red Hat Lightspeed expose?
18 in total: 15 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Red Hat Lightspeed safe to connect to an agent?
With care. The audit graded it B (80/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Red Hat Lightspeed need?
It reads AUTH_AUDIENCE, AUTH_ISSUER, AUTH_REQUIRED_SCOPES, AUTH_RESOURCE, AUTH_SERVER, GH_TOKEN, GITHUB_TOKEN, INSIGHTS_CLIENT_SECRET, INSIGHTS_MCP_MAX_TOOL_INPUT_TOKENS, INSIGHTS_REFRESH_TOKEN, LIGHTSPEED_CLIENT_ID and LIGHTSPEED_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Red Hat Lightspeed run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as insights-mcp.
How current is this page?
The grade is for one exact copy of the source (02331765173a), read on 2026-10-09. The repository is watched and re-audited when it changes.