Atlas / MCP servers / stevenyu113228 / BloodHound

BloodHoundSAFE

mcp/stevenyu113228/bloodhound
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
106 104r · 2w · 0d
Transport
stdio
License
—
Stars
160
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

BloodHound MCP (Model Context Protocol) is an innovative extension of the BloodHound tool, designed to enable Large Language Models (LLMs) to interact with and analyze Active Directory (AD) and Azure Active Directory (AAD) environments through natural language queries. By leveraging the power of LLMs, BloodHound MCP allows users to perform complex queries and retrieve insights from their AD/AAD environments using simple, conversational commands.

Features

  • Natural Language Queries: Use conversational language to query your AD/AAD environment without needing to write Cypher queries manually.
  • LLM-Powered Analysis: Harness the capabilities of Large Language Models to interpret and execute queries on your behalf.
  • Seamless Integration: Works with existing BloodHound data stored in Neo4j, providing a user-friendly interface for complex analysis.
  • Customizable: Easily configure the system to work with your specific environment and tools.

Configure the MCP Server

{
"mcpServers": {
"BloodHound": {
"name": "BloodHound",
"isActive": true,
"command": "uv",
"args": [
"run",
"--with",
"mcp[cli],neo4j",
"mcp",
"run",
"server.py"
],
"env": {
"BLOODHOUND_URI": "bolt://localhost:7687",
"BLOODHOUND_USERNAME": "neo4j",
"BLOODHOUND_PASSWORD": "bloodhound"
}
}
}
}

Usage

Configuration

To customize BloodHound MCP, update the configuration file in your MCP-supported tool. Key settings include:

  • Neo4j Database Connection:
  • BLOODHOUND_URI: The URI of your Neo4j database (e.g., bolt://localhost:7687).
  • BLOODHOUND_USERNAME: Your Neo4j username.
  • BLOODHOUND_PASSWORD: Your Neo4j password.
  • Server Settings: Adjust the command and args to match your environment and tool requirements.

Contributing

We welcome contribut

Read from source at commit 3a9d10d79833OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add bloodhound-mcp --env BLOODHOUND_PASSWORD=${BLOODHOUND_PASSWORD} -- uvx bloodhound-mcp
claude-desktop
{
  "mcpServers": {
    "bloodhound-mcp": {
      "command": "uvx",
      "args": [
        "bloodhound-mcp"
      ],
      "env": {
        "BLOODHOUND_PASSWORD": "${BLOODHOUND_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (106)

104 read · 2 write · 0 destructive.

ToolRiskDescription
computers_with_most_sessionsread
find_all_enabled_as_rep_roastable_usersread
find_all_enabled_kerberoastable_usersread
find_all_owned_groups_granting_network_share_accessread
find_allshortestpaths_with_dcsync_to_domainread
find_allshortestpaths_with_shadow_credential_permissionread
find_azure_app_owners_with_dangerous_rightsread
find_enabled_certificate_templatesread
find_owned_users_with_azure_tenancy_accessread
find_owned_users_with_group_granted_azure_accessread
find_paths_dangerous_rights_to_adminsdholderread
list_all_aad_groups_synchronized_with_adread
list_all_ad_principals_with_edges_to_azure_principalsread
list_all_authenticated_users_group_membershipsread
list_all_certificate_templatesread
list_all_cross_domain_user_sessions_and_membershipsread
list_all_domain_users_group_membershipsread
list_all_enabled_azure_usersread
list_all_enabled_azure_users_group_membershipsread
list_all_enabled_users_logged_in_last_90_daysread
list_all_enabled_users_never_logged_inread
list_all_enabled_users_set_password_last_90_dayswrite
list_all_enabled_users_with_foreign_group_membershipread
list_all_enabled_users_with_no_password_requiredread
list_all_enabled_users_with_password_never_expiresread
list_all_enabled_users_with_userpassword_attributeread
list_all_enrollment_rights_for_certificate_templatesread
list_all_gposread
list_all_groupsread
list_all_owned_computersread
list_all_owned_enabled_usersread
list_all_owned_enabled_users_with_emailread
list_all_owned_enabled_users_with_rdp_and_sessionsread
list_all_owned_enabled_users_with_sqladminread
list_all_owned_usersread
list_all_principals_used_for_syncing_ad_and_aadread
list_all_principals_with_local_admin_permissionread
list_all_principals_with_rdp_permissionread
list_all_principals_with_sqladmin_permissionread
list_all_tenancyread
list_all_user_sessionsread
list_all_users_with_description_fieldread
list_certificate_authority_serversread
list_computers_without_lapsread
list_custom_privileged_groupsread
list_domain_computersread
list_domain_controllersread
list_domain_trustsread
list_domainsread
list_en_svc_accts_priv_grp_memsread
list_enabled_non_privileged_users_with_local_adminread
list_enabled_non_privileged_users_with_rdpread
list_enabled_non_privileged_users_with_rdp_and_sessionsread
list_enabled_non_privileged_users_with_sqladminread
list_enabled_principals_with_constrained_delegationread
list_enabled_principals_with_unconstrained_delegationread
list_enabled_usersread
list_enabled_users_pwd_never_expires_unchanged_1yrread
list_enabled_users_with_emailread
list_esc1_vulnerable_certificate_templatesread
list_esc2_vulnerable_certificate_templatesread
list_esc3_vulnerable_certificate_templatesread
list_esc4_vulnerable_certificate_templatesread
list_esc6_vulnerable_certificate_templatesread
list_esc7_vulnerable_certificate_templatesread
list_esc8_vulnerable_certificate_templatesread
list_high_value_targetsread
list_network_shares_ignoring_sysvolread
list_non_managed_service_accountsread
list_non_priv_users_with_admin_and_sessionsread
list_own_en_usrs_local_adm_sessread
list_principals_with_azure_tenancy_accessread
list_privileged_users_without_protected_usersread
list_privileges_for_certificate_authority_serversread
non_privileged_users_with_dangerous_permissionsread
route_all_owned_enabled_group_membershipsread
route_all_owned_enabled_non_privileged_group_membershipsread
route_all_owned_enabled_privileged_group_membershipsread
route_all_sessions_to_computersread
route_all_sessions_to_computers_without_lapsread
route_azure_users_with_dangerous_rights_to_usersread
route_from_owned_enabled_principals_to_high_value_targetsread
route_non_priv_comps_dangerous_rights_to_compsread
route_non_priv_comps_dangerous_rights_to_gposread
route_non_priv_comps_dangerous_rights_to_groupsread
route_non_priv_comps_dangerous_rights_to_priv_nodesread
route_non_priv_comps_dangerous_rights_to_usersread
route_non_priv_users_dangerous_rights_to_compsread
route_non_priv_users_dangerous_rights_to_priv_nodesread
route_non_priv_usrs_dang_rts_grpsread
route_non_privileged_users_with_dangerous_permissionsread
route_non_privileged_users_with_dangerous_rights_to_gposread
route_non_privileged_users_with_dangerous_rights_to_usersread
route_own_en_usrs_dang_rts_usrsread
route_own_en_usrs_unconst_delread
route_owned_users_dangerous_rights_to_anyread
route_owned_users_dangerous_rights_to_groupsread
route_principals_to_azure_apps_and_spsread
route_principals_to_azure_vmread
route_principals_to_global_administratorsread
route_priv_users_sessions_to_non_priv_compsread
route_user_principals_to_azure_service_principalsread
run_querywrite
users_with_most_cross_domain_sessionsread
users_with_most_local_admin_rightsread
users_with_most_sessionsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha 3a9d10d79833full audit observations/trust-audit/mcp-server/stevenyu113228__bloodhound.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-063a9d10d79833SAFEB89first audit
06

Questions

What tools does BloodHound expose?

106 in total: 104 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is BloodHound safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does BloodHound need?

It reads BLOODHOUND_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does BloodHound run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as bloodhound-mcp.

How current is this page?

The grade is for one exact copy of the source (3a9d10d79833), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement