security MCP Server
WRG MCP server - exposes WinstonRedGuard tools (governance + research + pulse + breach + ransom + threat-intel + OSINT) to Claude Code and AI agents
Discovered via github-topic:mcp-server and last synced 3mo ago.
1. Install the package
pip install wrg-mcp-server
Surface
Read a scan report by `scan_id` (read-only)
Check ransom-radar watchlist status
Upstream
Convert fingerprint scan JSON into Sigma YAML rules
Web search through Arastirma Ussu
Report which remote services are configured
Execute `governance_check` across one or all apps
`wrg_vault` audit ledger inspection
Run policy / secrets / crypto scans on a path; empty `scan_types` runs combined `check`
Run code / person / network / full scan (**mutation** — requires `WRG_MCP_ALLOW_MUTATIONS=1`)
Scan or clean build artifacts (non-dry requires `WRG_MCP_ALLOW_MUTATIONS=1`)
Preview orphan / build-artifact targets (read-only)
Simple URL → markdown extraction
Query INFO_OPS actor corpus; enrich each match with linked incidents + Sigma rules; reverse-lookup via `mitre_technique` filter
Run the `tools/release_check.ps1` gate
Invoke `wrg-pulse check`
List configured policy profiles (baseline + strict) and presence
Dispatch a message to a configured channel (**mutation** — requires `WRG_MCP_ALLOW_MUTATIONS=1`)
Dark web brand mention monitoring
Full multi-agent trading analysis for a ticker
Fast RSI/price signal for a ticker
Scan a path for AI-generated code signals; supports `min_score`, `exclude[]`
List registered detectors and their weights
Simulate a rule set against sample contexts
List rule files under `$WRG_RULE_LAB_DIR` or `<repo>/.wrg/rules`
Username search across 3000+ sites (Maigret)
Ask a question to the Arastirma Ussu knowledge base
Search documents in the knowledge base
Default
auto-detect (walk up until `apps/` + `CLAUDE.md`)
Introspect available channel adapters (read-only)
Run a ransom-radar feed tick
Polymarket event signal analysis
Passive attack surface reconnaissance
Search memory entries
Override header name
Ransomware group/victim lookup
Override token scheme
Deep research with AI research platform
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.