Atlas / MCP servers / redhatinsights / Red Hat Lightspeed

Red Hat LightspeedCAUTION

mcp/redhatinsights/red-hat-lightspeed

An MCP server to connect Red Hat Lightspeed functionality to an AI / LLM

Verdict
CAUTION
Grade
B
Trust score
80 /100
Exposed tools
18 15r · 3w · 0d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

(formerly known as Insights MCP)

Red Hat Lightspeed Model Context Protocol (MCP) server is a lightweight, self-hosted solution that connects LLM-based agents - such as Claude Desktop and other MCP-compatible tools - to Red Hat Lightspeed services.

Features

  • Supports read-only operations: The server runs in read-only mode by default. Use --all-tools to enable write tools (e.g. create blueprints, run composes). RBAC permissions can also restrict access.
  • Provides natural language prompts: provides an ability to use natural language for querying Red Hat Lightspeed services

Supported Lightspeed Services

Setup and usage

Authentication

Note: Authentication is only required for accessing Red Hat Lightspeed APIs. The MCP server itself does not require authentication.

There are two ways to authenticate:

  1. Service Account (clientid + clientsecret) — create a service account and provide the credentials via environment variables or HTTP headers.
  2. JWT Bearer Token — provide a pre-existing JWT token via the Authorization: Bearer HTTP hea
Read from source at commit 02331765173aOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add red-hat-lightspeed-mcp --env LIGHTSPEED_CLIENT_ID=${LIGHTSPEED_CLIENT_ID} --env LIGHTSPEED_CLIENT_SECRET=${LIGHTSPEED_CLIENT_SECRET} -- docker run -i --rm ghcr.io/redhatinsights/red-hat-lightspeed-mcp:None
03

Exposed tools (18)

15 read · 3 write · 0 destructive.

ToolRiskDescription
create_vuln_playbookwriteCreate remediation playbook for given CVEs on given systems to mitigate vulnerabilities.
example_toolreadExample tool.
explain_cvesreadExplain why CVEs are affecting my environment.
find_host_by_namereadFind a host by its hostname/display name.
get_activation_keyreadGet a specific activation key by name.
get_cvereadGet details about specific CVE.
get_cve_systemsreadGet list of systems affected by a given CVE.
get_cvesreadGet list of CVEs affecting the account.
get_host_detailsreadGet detailed information for specific hosts by their IDs.
get_host_system_profilereadGet detailed system profile information for specific hosts.
get_host_tagsreadGet tags for specific hosts.
get_openapireadGet $container_brand_long Vulnerability OpenAPI specification in JSON format.
get_system_cvesreadGet list of CVEs affecting a given system.
get_systemsreadGet list of systems in $container_brand_long Vulnerability inventory.
get_with_authwriteSend GET request to Insights API with authentication.
get_without_authwriteSend GET request to Insights API without authentication.
get_workspacereadGet details for one or more workspaces by ID.
lookup_tool_requirementsreadReturn the console role names required for an MCP tool.
04

Trust audit

CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (17)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
configs/tool_rest_map.json
configs/tool_rest_map.json
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/generate_test_prompts.py:35
module = importlib.import_module(module_name)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/insights_mcp/mcp_subprocess.py:68
server_url = f"http://127.0.0.1:{port}/sse"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/insights_mcp/mcp_subprocess.py:70
server_url = f"http://127.0.0.1:{port}/mcp/"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.spellcheck-en-custom.txt
.spellcheck-en-custom.txt
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.spellcheck.yml
.spellcheck.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.yamllint
.yamllint
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
docs/mkdocs/mcp-llm-eval.md
docs/mkdocs/mcp-llm-eval.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
docs/mkdocs/toolsets.md
docs/mkdocs/toolsets.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
docs/mkdocs/usage.md
docs/mkdocs/usage.md
Why it matters. link not followed
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/llm_prompt_catalog.py:24
module = importlib.import_module(module_name)
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_dashboard_ui.py:96
module = importlib.import_module(module_path)
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
.agents/skills/README.md:166
[![Install with Podman in Cursor](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/en/install-mcp?name=red-hat-lightspeed-mcp&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoicG9kbWFuIH
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:166
[![Install with Podman in Cursor](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/en/install-mcp?name=red-hat-lightspeed-mcp&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoicG9kbWFuIH
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/mkdocs/index.md:166
[![Install with Podman in Cursor](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/en/install-mcp?name=red-hat-lightspeed-mcp&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoicG9kbWFuIH

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 02331765173afull audit observations/trust-audit/mcp-server/redhatinsights__red-hat-lightspeed.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0902331765173aCAUTIONB80first audit
06

Questions

What is the Red Hat Lightspeed MCP server?

An MCP server to connect Red Hat Lightspeed functionality to an AI / LLM

What tools does Red Hat Lightspeed expose?

18 in total: 15 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Red Hat Lightspeed safe to connect to an agent?

With care. The audit graded it B (80/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Red Hat Lightspeed need?

It reads AUTH_AUDIENCE, AUTH_ISSUER, AUTH_REQUIRED_SCOPES, AUTH_RESOURCE, AUTH_SERVER, GH_TOKEN, GITHUB_TOKEN, INSIGHTS_CLIENT_SECRET, INSIGHTS_MCP_MAX_TOOL_INPUT_TOKENS, INSIGHTS_REFRESH_TOKEN, LIGHTSPEED_CLIENT_ID and LIGHTSPEED_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Red Hat Lightspeed run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as insights-mcp.

How current is this page?

The grade is for one exact copy of the source (02331765173a), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement