Vulnerability and exposure
Scanners and exposure-management platforms an agent can query for findings and asset coverage. 19 integrations, 281 tools.
Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.
Armis Centrix
Section titled “Armis Centrix”9 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
armis_get_alert | Fetch a single Armis alert by its numeric ID. Returns full alert metadata including severity, status, policy, affected device, and evidence. Returns an empty object if the alert is not found. | required alert_id |
armis_get_device | Fetch a single Armis device by its numeric ID. Returns the full device profile including risk score, OS, category, network info, tags, first/last seen, and any attached vulnerabilities. Returns an empty object if the device is not found. | required device_id |
armis_get_vulnerability | — | required vulnerability_id |
armis_get_vulnerability_exposure | List the device-CVE matches for ONE CVE or ONE device, each with its VIPR remediation lifecycle status — this answers ‘who is exposed to this CVE, and where does each exposure stand?’. | optional cve_id, device_id, limit, offset, status |
armis_run_asq_query | — | required aqloptional limit |
armis_search_alerts | — | optional asq_filter, limit |
armis_search_devices | — | optional asq_filter, limit |
armis_search_vulnerabilities | — | optional asq_filter, limit |
armis_summarize_remediation_posture | Summarize VIPR remediation posture for a scope: how many findings sit in each lifecycle status and severity tier, plus the highest-priority open findings. | optional asq_filter, top |
Bitsight
Section titled “Bitsight”19 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
bitsight_create_company_request | Request that a company be added to the Bitsight inventory by domain so it can later be monitored. Mapping is asynchronous (typically 3-10 days). Optionally set a subscription_type to auto-subscribe once added. | required domainoptional subscription_type |
bitsight_get_company | Get full details for a single company: current rating, rating history, and risk-vector grades. Requires a company_guid (use search_companies to resolve one from a name or domain). | required company_guid |
bitsight_get_company_request | Get the details and status of a single company-addition request. | required request_guid |
bitsight_get_portfolio_risk_vector_grades | Get per-risk-vector letter grades for companies in your portfolio (e.g. Botnet Infections, Patching Cadence). Optionally scope to a folder, tier, or single company, and choose latest grades or a 1-year monthly history. | optional company_guid, folder_guid, limit, period, tier_guid |
bitsight_get_portfolio_statistics | Get aggregate statistics across your portfolio: distribution by rating category (advanced/intermediate/basic), highest/lowest/median ratings, and risk-vector averages. | — |
bitsight_get_subscription_info | Get subscription/entitlement information: per-product quotas and remaining capacity. Useful to distinguish a 403 ‘not entitled’ from a genuine error and to check available monitoring slots. | — |
bitsight_get_threat_evidence | Get a specific company’s evidence for a given threat: certainty, exposure detection, and evidence tags. Requires both the threat_guid (from list_threats) and the company_guid. | required threat_guid, company_guidoptional limit |
bitsight_get_vendor_action_plan | Get vendor company GUIDs grouped by recommended action plan (monitor / review / escalate) across your tiers. | — |
bitsight_list_alerts | List Continuous Monitoring alerts (rating changes, threshold breaches, risk-vector grade changes, public disclosures, vulnerabilities). Filter by type, severity, company, folder, and date range. | optional alert_type, company_guid, end_date, folder_guid, latest, limit, severity, start_date |
bitsight_list_breach_events | List public-disclosure ‘company events’ (breaches and security incidents) impacting portfolio companies. Optionally scope to a single company. Each event includes type, category, description, severity, and the affected company. | optional company_guid, limit |
bitsight_list_company_findings | List security findings for a company, or a rolled-up summary. Findings are the underlying evidence (events/records) behind a company’s rating. Set summary=true for aggregate counts instead of individual findings. | required company_guidoptional limit, summary |
bitsight_list_company_requests | List existing company-addition requests and their status. | optional limit |
bitsight_list_company_tree | List a company’s ratings tree — the company plus its subsidiaries (recursive corporate hierarchy) — for fourth-party / supply-chain analysis. | required company_guid |
bitsight_list_folders | List the folders used to group portfolio companies (and that drive alerts and reporting). Returns folder GUIDs, names, and sharing details. | — |
bitsight_list_portfolio | List the companies in your Continuous Monitoring portfolio along with their current security ratings. Optionally scope to a folder or tier. | optional folder_guid, limit, tier_guid |
bitsight_list_ratings_tree_product_types | List the product types used by all companies in a third party’s ratings tree (parent + subsidiaries), for fourth-party concentration / supply-chain risk analysis. | required company_guid |
bitsight_list_threats | List portfolio threats (vulnerabilities and vulnerability groups) detected across monitored companies. Filter by impact scope, severity, folder, and tier. Each threat reports exposed/mitigated counts and CVSS. | optional folder_guid, impact, limit, severity, tier_guid |
bitsight_list_tiers | List vendor tiers used to prioritize vendors by criticality. Set summary=true for per-tier summary statistics instead of tier records. | optional summary |
bitsight_search_companies | Search the Bitsight inventory by company name and/or domain to find a company_guid. This is the entry point for most workflows — almost every other tool needs a company_guid that this call resolves. | optional domain, limit, name |
Black Duck
Section titled “Black Duck”14 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
black-duck_generate_sbom_report | Trigger SBOM (Software Bill of Materials) report generation for a project version. Supports SPDX 2.2 (JSON, YAML, RDF, TAG_VALUE) and CycloneDX 1.4 (JSON, YAML, XML). Note: TAG_VALUE is SPDX-only; XML is CycloneDX-only. | required project_id, version_idoptional sbom_format, sbom_type |
black-duck_get_component_vulnerabilities | Get all vulnerabilities for a specific component version. Returns CVE/BDSA IDs, CVSS v3 scores, severity, and descriptions (CVSS v4 fields are populated only on Black Duck 2025.1+). | required component_id, component_version_idoptional limit, offset |
black-duck_get_project | Get details of a single Black Duck project by its project ID. | required project_id |
black-duck_get_project_version | Get details of a specific project version including its risk profile (vulnerability counts broken down by CRITICAL, HIGH, MEDIUM, LOW severity). | required project_id, version_id |
black-duck_get_project_vulnerability_digest | Get per-project vulnerability digest showing severity breakdown. Available in Black Duck 2025.10 and later. Returns each project’s vulnerability counts by severity. | optional limit, offset |
black-duck_get_vulnerability_digest_summary | Get an org-wide summary of vulnerability counts broken down by severity (CRITICAL, HIGH, MEDIUM, LOW). Available in Black Duck 2025.10 and later. Useful for a quick health overview across all projects. | — |
black-duck_get_vulnerability_remediation | Get the remediation details for a specific vulnerability on a BOM component in a project version. Returns current remediation status, CVSS v3 scores (CVSS v4 fields require Black Duck 2025.1+), fix guidance, and comments. | required project_id, version_id, component_id, component_version_id, vulnerability_id |
black-duck_list_bom_components | List all bill-of-materials (BOM) components for a project version. Returns open-source components with their license info and policy status. | required project_id, version_idoptional limit, offset |
black-duck_list_policy_rules | List all Black Duck policy rules. Policy rules define conditions (e.g., CRITICAL severity, specific licenses) that flag BOM components as policy violations. | optional limit, offset |
black-duck_list_project_versions | List all versions (scans) for a Black Duck project. Each version has a risk profile showing vulnerability counts by severity. | required project_idoptional limit, offset |
black-duck_list_projects | List Black Duck SCA projects. Optionally filter by name substring. Returns project IDs, names, descriptions, and creation metadata. | optional limit, name, offset |
black-duck_list_reports | List generated reports for a project version. Returns report IDs, types, formats, and status (REQUESTED, IN_PROGRESS, COMPLETED). | required project_id, version_idoptional limit, offset |
black-duck_list_vulnerable_bom_components | List only the vulnerable open-source components in a project version’s BOM. Each result includes CVSS scores, severity, and current remediation status. Filter by severity or remediation status to focus the results. | required project_id, version_idoptional limit, offset, remediation_status, severity |
black-duck_update_vulnerability_remediation | Update the remediation status for a specific vulnerability on a BOM component. Use to mark vulnerabilities as AFFECTED, NOT_AFFECTED, REMEDIATED, IGNORED, etc. | required project_id, version_id, component_id, component_version_id, vulnerability_id, remediation_statusoptional comment |
Burp Suite DAST
Section titled “Burp Suite DAST”15 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
burp-suite_cancel_scan | Cancel a running or queued Burp Suite DAST scan. This is irreversible — the scan cannot be resumed and any incomplete results are discarded. Returns the scan’s id and updated status so the caller can verify cancellation. | required scan_id |
burp-suite_create_site | Register a new target site in Burp Suite DAST with scope URLs and optional scan configuration. Returns the created site’s id, name, parent_id, scope (included_urls, excluded_urls), and scan_configuration_ids. | required name, included_urlsoptional excluded_urls, parent_id, scan_configuration_ids |
burp-suite_get_compliance_report | Get a compliance report for a Burp Suite DAST scan. Supported report types: ‘PCI DSS v4.0.1’ or ‘OWASP Top 10 2025’. Returns the plain-text report content describing each requirement’s status. | required scan_id, report_type |
burp-suite_get_issue | Get full details of a specific vulnerability from a Burp Suite DAST scan, including plain-text description, remediation guidance, evidence, vulnerability classifications, and references. | required scan_id, serial_number |
burp-suite_get_scan | Get full details of a Burp Suite DAST scan by ID, including status, site_id, site_name, start/end time, scan_configuration_ids, issue counts by severity, and delta vs. the previous scan. | required scan_id |
burp-suite_get_scan_event_log | Get the event timeline for a Burp Suite DAST scan. Each entry includes an event type, message, and timestamp. Useful for diagnosing stuck, failed, or unexpectedly short scans. Use limit to cap the number of entries returned. | required scan_idoptional event_type, limit |
burp-suite_get_site | Get details of a specific Burp Suite DAST site by ID, including scope (included/excluded URLs and protocol options), assigned scan configurations, agent pool assignment, and configured application logins. | required site_id |
burp-suite_list_agents | List all scanning agents registered in Burp Suite DAST, with their enabled/active status, max concurrent scans, agent pool assignment, and machine endpoints (ip/port). Useful for checking scanning capacity before scheduling large scans. | — |
burp-suite_list_issues | List vulnerabilities found in a Burp Suite DAST scan. Returns issue type, name, path, severity, confidence, and triage status. Supports pagination via start (0-based offset) and count (max 500). | required scan_idoptional count, start |
burp-suite_list_scan_configurations | List all available scan configurations in Burp Suite DAST — both PortSwigger built-in configurations and custom configurations. Returns ID and name for each configuration. | — |
burp-suite_list_scans | List scans in Burp Suite DAST with optional filtering by site, sort order, and result limit. Returns scan status, timing, issue counts by severity, and delta vs. the previous scan per row. | optional limit, site_id, sort_column, sort_order |
burp-suite_list_sites | List all sites and folders in the Burp Suite DAST site tree. Returns an object with two keys: ‘folders’ (list of folder records with id, name, parent_id) and ‘sites’ (list of site records with id, name, parent_id). | — |
burp-suite_run_pre_scan_check | Verify that a Burp Suite DAST site is reachable before scheduling a scan. Returns the reachability check state and any failure message. Run this before schedule_scan to avoid wasted scan capacity. | required site_id |
burp-suite_schedule_scan | Schedule a new scan for a Burp Suite DAST site. Supports one-time scans and recurring scans via an iCalendar RRULE string. | required site_id, initial_run_timeoptional rrule, scan_configuration_id |
burp-suite_update_issue | Triage a Burp Suite DAST vulnerability: mark it as a false positive, mark it as accepted risk, or adjust its severity. At least one of false_positive, accepted_risk, or severity must be provided. | required scan_id, serial_numberoptional accepted_risk, false_positive, severity |
Cyberhaven
Section titled “Cyberhaven”39 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
cyberhaven__body_action_tool | — | required resource_id, body |
cyberhaven__create_tool | — | required body |
cyberhaven__delete_tool | — | required resource_id |
cyberhaven__get_list_tool | — | optional filters |
cyberhaven__get_tool | — | required resource_id |
cyberhaven__post_list_tool | — | optional filters, limit, next_id |
cyberhaven__update_tool | — | required resource_id, body |
cyberhaven__upsert_tool | — | required bodyoptional resource_id |
cyberhaven_add_list_items | Add one or more items to a Cyberhaven list. | required list_id, items |
cyberhaven_add_risk_group_user | Add a user to a manual Cyberhaven user risk group by alias. | required risk_group_id, user_alias |
cyberhaven_build_incident_filter_template | Build a local Cyberhaven incident-filter template without making an API call. | optional date_from, date_to, policy, severity, status, user |
cyberhaven_bulk_add_risk_group_users | Add multiple users to a manual Cyberhaven user risk group in a single workflow. Used by the IRM workflow to flag contractors, departing employees, or watchlisted users. | required risk_group_id, user_aliases |
cyberhaven_bulk_assign_incidents | Find incidents matching filters, then assign them to a Cyberhaven analyst or owner using per-incident PATCH calls. Individual PATCH failures do not abort the batch. | required filters, assigneeoptional max_updates, note |
cyberhaven_bulk_close_incidents | Find incidents matching filters, then close them in a batch workflow using per-incident PATCH calls. Individual PATCH failures do not abort the batch. | required filtersoptional max_updates, note |
cyberhaven_check_risk_group_user | Quick lookup to check if a user is part of a specific risk group. | required risk_group_id, user_alias |
cyberhaven_compare_periods | Return side-by-side Cyberhaven incident metrics for two explicit filter periods. | required current_filters, previous_filtersoptional max_results |
cyberhaven_correlate_user_activity | Correlate Cyberhaven incidents and IRM activity for a user-centric investigation. Resolves the user via IRM search and uses their canonical identifier (email/alias/id) for the incident filter. | required useroptional incident_filters, max_incidents |
cyberhaven_format_report_data | Format arbitrary data as markdown or return it unchanged as JSON without making an API call. | required title, dataoptional output_format |
cyberhaven_generate_report | Generate a compact Cyberhaven report from incident, policy, or user-focused workflows. Returns a markdown string when output_format is MARKDOWN (default), or the raw report dict when output_format is JSON. | required report_typeoptional filters, output_format |
cyberhaven_get_activity_timeline | Build a simple chronological activity timeline for a Cyberhaven user investigation. Returns an empty list when no IRM user matches the query — this tool will not silently operate on an arbitrary user. | required user |
cyberhaven_get_event_details | Get full Cyberhaven event details for one or more event identifiers. Use this to enrich incident investigations with raw event context. | required event_ids |
cyberhaven_get_event_lineage | Get Cyberhaven event lineage or chain-of-custody context between two events. Useful when tracking how data moved across users, endpoints, or applications. | required start_event_id, end_event_id |
cyberhaven_get_incident | Get a single Cyberhaven incident by ID. Cyberhaven does not expose a direct GET endpoint, so this filters /v2/incidents/list by ID and returns the matching incident. Returns an empty object if not found. | required resource_id |
cyberhaven_get_irm_user | Get a single Cyberhaven IRM user (including risk-profile fields) by alias. Cyberhaven does not expose a direct GET endpoint, so this filters /v2/irm/users by alias and returns the matching user. | required resource_id |
cyberhaven_get_list_items | Get paginated items of a Cyberhaven list. | required list_idoptional page_id, page_size |
cyberhaven_get_streaming_profile_connection_log | Get streaming profile connection log entries. Use this when a forwarding target is failing or dropping events. | required profile_idoptional end_time, error_filter, page_id, page_size, start_time |
cyberhaven_get_user_activity | Get a consolidated Cyberhaven activity view for a user, including incidents and risky dataflows. Returns empty incidents/dataflows when no IRM user matches the query — this tool will not silently operate on an arbitrary user. | required user |
cyberhaven_investigate_user | Run a focused user investigation using IRM user search, risky dataflows, and matching incidents. User matching is an exact match on id/email/alias and a substring match on name. | required useroptional incident_filters, max_incidents |
cyberhaven_list_irm_user_risky_dataflows | List risky dataflows associated with a Cyberhaven IRM user. | required user_idoptional events_time_from, events_time_to, limit |
cyberhaven_list_risk_group_users | List user aliases in a Cyberhaven user risk group. | required risk_group_id |
cyberhaven_merge_filter_sets | Merge two local Cyberhaven filter objects without making an API call. | required base_filters, override_filters |
cyberhaven_policy_effectiveness | Grade policies by correlating Cyberhaven policy resources with incident volume. | optional incident_filters, max_incidents, policy_filters |
cyberhaven_remove_list_items | Remove one or more items from a Cyberhaven list. | required list_id, items |
cyberhaven_remove_risk_group_user | Remove a user from a manual Cyberhaven user risk group by alias. | required risk_group_id, user_alias |
cyberhaven_replace_risk_group_users | DESTRUCTIVE: full replacement — overwrites the complete user membership of a manual Cyberhaven user risk group with the supplied list. | required risk_group_id, user_aliases |
cyberhaven_reset_irm_user_risk_scores | Reset Cyberhaven IRM risk scores for one or more users. | required user_ids |
cyberhaven_search_irm_users | Search Cyberhaven IRM users by free-text query. Matches against display name, alias, title, department, and hostname fields on the IRM user record. For an exact alias lookup use get_irm_user. | required queryoptional filters, limit |
cyberhaven_summarize_incidents | Summarize Cyberhaven incidents for the supplied filter window. Returns counts grouped by status and severity, with a truncated flag indicating whether the per-period cap was hit. | required current_filtersoptional max_results, previous_filters |
cyberhaven_update_incident | Patch an incident to change ownership, workflow status, severity, or attach additional Cyberhaven fields. Use this for single-incident response actions. | required resource_idoptional assignee, fields, note, severity, status |
5 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
cyera_get_datastore_objects | List the data objects (tables, buckets, files) within a single Cyera data store by ID, including object type, location, and classification summary. Supports pagination. | required datastore_idoptional limit, offset |
cyera_list_classifications | List Cyera classification results — the sensitive-data findings (e.g., PII, PCI, PHI) detected across data stores. Supports pagination and optional datastore filtering. | optional datastore_id, limit, offset |
cyera_list_datastores | List data stores discovered by Cyera, including cloud provider, type, classification summary, and risk posture. Supports pagination and optional provider/type filtering. | optional datastore_type, limit, offset, provider |
cyera_list_events | List Cyera events (audit/activity records such as discovery, classification, and issue changes) with optional time-range filtering and pagination. | optional end_date, limit, offset, start_date |
cyera_list_issues | List Cyera security issues (data-risk findings) with optional filtering by severity and status. Returns issue summaries including title, severity, affected datastore, and status. | optional limit, offset, severity, status |
Horizon3 NodeZero
Section titled “Horizon3 NodeZero”13 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
horizon3-nodezero_cancel_pentest | Cancel a running NodeZero pentest by its operation ID. | required op_id |
horizon3-nodezero_get_pentest | Get detailed information about a specific NodeZero pentest by its operation ID. | required op_id |
horizon3-nodezero_get_pentest_report_url | Get a download URL for a pentest’s reports ZIP file. | required op_id |
horizon3-nodezero_get_runner | Get detailed information about a specific NodeZero Runner (agent) by its UUID or name. Runners automate deployment of the NodeZero Docker container for internal pentests. Provide either uuid or name to identify the runner. | optional name, uuid |
horizon3-nodezero_get_weakness | Get detailed information about a specific weakness found in a pentest. | required op_id, weakness_id |
horizon3-nodezero_list_action_logs | List MITRE ATT&CK-mapped action logs for a specific pentest. Shows what NodeZero did during the pentest. | required op_idoptional page, page_size |
horizon3-nodezero_list_attack_paths | List attack paths discovered during a specific pentest. Shows how NodeZero chained vulnerabilities. | required op_idoptional page, page_size |
horizon3-nodezero_list_credentials | List credentials discovered during a specific pentest. | required op_idoptional page, page_size |
horizon3-nodezero_list_hosts | List hosts discovered during a specific pentest. | required op_idoptional page, page_size |
horizon3-nodezero_list_pentests | List all NodeZero pentests with pagination. Returns pentest IDs, names, states, and summary counts. | optional page, page_size, text_search |
horizon3-nodezero_list_runners | List all NodeZero Runners (agents) configured in the account with pagination. | optional page, page_size, text_search |
horizon3-nodezero_list_weaknesses | List weaknesses (vulnerabilities/findings) discovered in a specific pentest. | required op_idoptional page, page_size, text_search |
horizon3-nodezero_run_pentest | Schedule and launch a new NodeZero pentest. Returns the operation ID and runner script URL. | required nameoptional op_type |
Microsoft Defender for Cloud
Section titled “Microsoft Defender for Cloud”9 tools. Available as 2 connections: Microsoft Defender for Cloud (OAuth 2.0), Microsoft Defender for Cloud (Government) (OAuth 2.0).
| Tool | Description | Arguments |
|---|---|---|
microsoft-defender-for-cloud_get_alert | Get detailed information for a specific Defender for Cloud security alert. Returns full alert properties including severity, entities, attack tactics, remediation steps, and timeline. | required alert_name, location |
microsoft-defender-for-cloud_get_compliance_overview | Get regulatory compliance status for a specific standard (e.g. Azure CIS, NIST, PCI-DSS, SOC 2). Shows which controls are passing/failing and their assessment counts. Use list_security_coverage first to see available standards. | required standard_name |
microsoft-defender-for-cloud_get_recommendation | Get detailed information for a specific security recommendation (assessment). Returns the recommendation status, severity, affected resource details, and remediation guidance. | required assessment_nameoptional resource_id |
microsoft-defender-for-cloud_get_secure_score | Get the subscription’s secure score with a breakdown by security controls. The secure score (0-100%) measures overall security posture. Each control groups related recommendations and contributes weighted points. | — |
microsoft-defender-for-cloud_list_alerts | List Microsoft Defender for Cloud security alerts for the subscription. Alerts represent detected threats from enabled Defender plans (Defender for Servers, Storage, SQL, etc.). | optional severity, status, top |
microsoft-defender-for-cloud_list_recommendation_findings | List sub-assessments (individual findings) for a recommendation. Shows which specific resources are affected and their individual status. For example, a recommendation ‘Enable disk encryption’ would show each VM that is missing encryption. | required assessment_nameoptional resource_id, top |
microsoft-defender-for-cloud_list_recommendations | List Defender for Cloud security recommendations (assessments) for the subscription. Recommendations identify misconfigurations and security gaps. Available in both free CSPM and paid plans. | optional status, top |
microsoft-defender-for-cloud_list_security_coverage | List enabled Defender plans (pricing tiers) and available compliance standards. Helps understand what protection is active: free tier gives recommendations only, paid plans (Servers, Storage, SQL, Containers, etc.) add threat alerts. | — |
microsoft-defender-for-cloud_update_alert | Update the status of a Defender for Cloud security alert. Use ‘Dismissed’ for false positives, ‘Resolved’ for handled threats, ‘InProgress’ for alerts under investigation, ‘Active’ to reactivate. | required alert_name, location, status |
5 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
nvd_get_cpe | Get detailed information about a specific CPE (Common Platform Enumeration) entry | required cpeIdentifier |
nvd_get_cve | Get detailed information about a specific CVE by its ID | required cveId |
nvd_search_cpes | Search for CPE (Common Platform Enumeration) entries to identify specific products and versions | optional cpeMatchString, cpeNameId, keywordExactMatch, keywordSearch, lastModEndDate, lastModStartDate, matchCriteriaId, resultsPerPage, startIndex |
nvd_search_cves | Search for CVE vulnerabilities with various filters including keywords, dates, severity levels, and more | optional cpeName, cvssV2Severity, cvssV3Severity, cweId, hasCertAlerts, hasCertNotes, hasKev, hasOval, isVulnerable, keyword, keywordExactMatch, lastModEndDate, lastModStartDate, noRejected, pubEndDate, pubStartDate, resultsPerPage, sourceIdentifier, startIndex |
nvd_search_vulnerabilities_by_cpe | Find vulnerabilities that affect a specific CPE (Common Platform Enumeration) | required cpeNameoptional resultsPerPage, startIndex |
Prisma Cloud
Section titled “Prisma Cloud”14 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
prisma-cloud_dismiss_alerts | Dismiss or snooze one or more Prisma Cloud alerts. Provide a snooze duration to temporarily snooze instead of permanently dismissing. | required alert_ids, dismissal_noteoptional snooze_amount, snooze_unit |
prisma-cloud_get_alert | Get detailed information for a specific Prisma Cloud alert by ID | required alert_idoptional detailed |
prisma-cloud_get_alert_remediation | Get remediation CLI commands for a specific Prisma Cloud alert. Returns actionable commands to fix the security issue. | required alert_id |
prisma-cloud_get_asset | Get detailed information for a specific cloud asset by its RRN or ID | required asset_id |
prisma-cloud_get_compliance_posture | Get compliance posture summary for a specific compliance standard, showing pass/fail statistics across requirements | required compliance_idoptional cloud_account, cloud_type |
prisma-cloud_get_policy | Get detailed information for a specific Prisma Cloud policy by ID | required policy_id |
prisma-cloud_list_alert_rules | List configured alert rules in Prisma Cloud | — |
prisma-cloud_list_alerts | List Prisma Cloud security alerts with filtering by status, severity, cloud type, account, and policy name. Returns paginated results. | optional account_name, cloud_type, detailed, limit, offset, policy_name, severity, status, time_amount, time_unit |
prisma-cloud_list_asset_inventory | List cloud asset inventory with filtering by cloud type, account, resource type, and region. Provides a breakdown of pass/fail statistics. | optional account_name, cloud_type, group_by, region, resource_type, time_amount, time_unit |
prisma-cloud_list_compliance_standards | List all compliance standards and frameworks available in Prisma Cloud | — |
prisma-cloud_list_policies | List Prisma Cloud security policies with filtering by severity, cloud type, policy type, compliance standard, and enabled status | optional cloud_type, compliance_standard, enabled, policy_type, severity |
prisma-cloud_reopen_alerts | Reopen previously dismissed or snoozed Prisma Cloud alerts | required alert_ids |
prisma-cloud_search_config | Search cloud resources using Prisma Cloud RQL (Resource Query Language) config queries. Example: “config from cloud.resource where cloud.type = ‘aws’ AND resource.type = ‘aws_s3_bucket‘“ | required queryoptional limit, time_amount, time_unit |
prisma-cloud_update_policy_status | Enable or disable a Prisma Cloud security policy | required policy_id, enabled |
Qualys
Section titled “Qualys”58 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
qualys_activate_agent | Activate one or more Qualys modules (e.g. AGENT_VM, AGENT_PC) for a single asset’s Cloud Agent. Additive and reversible via deactivate_agents. | required asset_id, modulesoptional base_url, pod |
qualys_add_excluded_hosts | Exclude IPs from vulnerability scanning. Excluded hosts will be skipped in future scans. | required ipsoptional comment |
qualys_count_agents | Count Cloud Agent host assets matching a tag filter (default tag ‘Cloud Agent’) plus optional QPS criteria. Cheap first call: use it before list_agents or any bulk action to gauge fleet size and blast radius. Uses the Qualys QPS REST API. | optional base_url, criteria, pod, tag_name |
qualys_create_asset_group | Create a new asset group with a title and optional IP set. | required titleoptional comments, ips |
qualys_create_tag | Create a new asset tag. | required nameoptional color, parent_tag_id |
qualys_csam_assets_by_tag | Search CSAM/Global AssetView inventory for assets carrying a specific tag (tags.name filter). Convenience wrapper over csam_search_assets; returns the raw JSON response with lastSeenAssetId cursor pagination. | required tag_nameoptional base_url, last_seen_asset_id, page_size, pod |
qualys_csam_assign_asset_business_metadata | Assign business metadata (environment, ownership, businessAppIds, assignedLocation, etc.) to a CSAM asset. WRITE operation: dry-runs by default, returning the payload it would send; set confirm=True to execute. | required qualys_asset_id, metadataoptional base_url, confirm, pod |
qualys_csam_count_assets | Count assets in the CSAM/Global AssetView inventory matching filter criteria (GAV/CSAM QQL field tokens). Uses the Qualys Gateway API. Optionally target a specific Qualys POD or override the gateway base URL. | optional asset_last_updated, base_url, filters, last_seen_asset_id, pod |
qualys_csam_get_asset | Get full CSAM/Global AssetView details for a specific asset by its asset ID. Uses the Qualys Gateway API. | required asset_idoptional base_url, pod |
qualys_csam_list_business_apps | List distinct business applications associated with assets in the CSAM inventory, derived from asset businessAppListData. Returns hasMore/lastSeenAssetId so additional asset pages can be swept for more apps. | optional base_url, filters, last_seen_asset_id, page_size, pod |
qualys_csam_search_assets | Search the CSAM/Global AssetView asset inventory with filter criteria (GAV/CSAM QQL field tokens). Returns the raw JSON response including assetListData, hasMore, and lastSeenAssetId; pass lastSeenAssetId back to page through results. | optional asset_last_updated, base_url, exclude_fields, filters, include_fields, last_seen_asset_id, page_size, pod |
qualys_csam_upsert_business_app | Create or update (upsert) a business application’s metadata in CSAM. WRITE operation: dry-runs by default, returning the payload it would send; set confirm=True to execute. | required business_app_id, nameoptional base_url, confirm, created_epoch_millis, fields, last_updated_epoch_millis, pod |
qualys_deactivate_agents | Deactivate Qualys modules across a set of Cloud Agents (stops data collection for those modules). DESTRUCTIVE but reversible via activate_agent. Target by exactly one of asset_ids or tag_name. | required modulesoptional asset_ids, base_url, confirm, expected_count, pod, tag_name |
qualys_delete_asset_group | Delete an asset group by ID. DESTRUCTIVE AND IRREVERSIBLE. | required group_idoptional confirm |
qualys_delete_tag | Delete an asset tag by ID. DESTRUCTIVE AND IRREVERSIBLE. Dry-runs by default, returning the tag’s name and child-tag count for review; you MUST ask the user for explicit confirmation before re-calling with confirm=True to execute. | required tag_idoptional confirm |
qualys_export_compliance_policy | Export a compliance policy definition by ID. | required policy_idoptional response_format |
qualys_export_option_profile | Export one option profile’s full configuration (scan settings, ports, search lists, performance) for VM (user), PC (compliance), or PCI profiles. Select by exactly one of profile_id or title (title must match exactly). | optional profile_id, profile_type, response_format, title |
qualys_fo_request | Escape hatch: call any Qualys FO classic API endpoint under /api/2.0/fo/ when no dedicated tool covers it. | required pathoptional base_url, body, extra_headers, method, pod, query_params |
qualys_gateway_request | Escape hatch: call any Qualys Gateway API endpoint under /rest/2.0/ (GAV/CSAM) or /csapi/ (Container Security) (JSON) when no dedicated tool covers it. | required pathoptional base_url, body, extra_headers, method, pod, query_params |
qualys_get_host | Get detailed information about a specific host by ID or IP address. | optional host_id, ip |
qualys_get_host_detection_count | Get a count of vulnerability detections matching filters. Quick summary without full detection data. | optional ag_ids, ips, severities, status |
qualys_get_scanner_appliance | Get detailed information about a specific scanner appliance by ID. | required appliance_id |
qualys_get_vulnerability | Get detailed information about a specific vulnerability by its QID (Qualys ID). Returns description, solution, CVSS score, and CVE mappings. | required qid |
qualys_ignore_vulnerability | Ignore a vulnerability (by QID) on specific hosts so it won’t appear in reports. Specify hosts by IPs, asset group IDs, or tag names. Up to 10 QIDs per request. | required qidsoptional ag_ids, comments, ips, tag_set_by, tag_set_include |
qualys_launch_report | Launch a report generation with specified template, output format (PDF/HTML/XML/CSV/DOCX), and target scope. | required template_idoptional asset_group_ids, ips, output_format, report_title |
qualys_launch_scan | Launch a vulnerability scan against target IPs, asset groups, or tags with a specified scan title and option profile. | required scan_titleoptional asset_group_ids, ip, option_id, option_title, priority, scanner_name |
qualys_list_activation_keys | List Cloud Agent activation keys (provisioning inputs for agent installs). Uses the Qualys QPS REST API. Paginate while has_more is true by passing the previous response’s last_id; stop when has_more is false. | optional base_url, criteria, last_id, limit, pod, title_contains |
qualys_list_agents | List Cloud Agents with lifecycle state (version, status, last check-in, activation key, modules, OS). Filters by tag (default ‘Cloud Agent’) plus optional QPS criteria — prefer narrowing criteria over raising limit. | optional base_url, criteria, last_id, limit, pod, tag_name |
qualys_list_asset_group_scanners | List scanner appliances assigned to an asset group. | required group_id |
qualys_list_asset_groups | List asset groups with filtering by ID and title. Returns group definitions with IP sets and member info. | optional id_min, ids, limit, title, truncation_limit |
qualys_list_auth_records | List authentication records by type. Defaults to ‘windows’ if no record_type is specified. Use record_type to query unix, ms_sql, or cisco records. | optional details, id_max, id_min, ids, limit, record_type |
qualys_list_compliance_exceptions | List compliance exceptions (approved deviations from policy controls). | optional id_max, id_min, limit, policy_id, status |
qualys_list_compliance_policies | List policy compliance policies with filtering. | optional details, id_max, id_min, ids, limit, updated_after_datetime |
qualys_list_compliance_scans | List policy compliance scans with filtering by state and date range. | optional launched_after_datetime, launched_before_datetime, limit, scan_ref, state |
qualys_list_excluded_hosts | List IPs currently excluded from scanning. | optional limit |
qualys_list_host_detections | List vulnerability detections across hosts with filtering by IP, asset group, severity, QID, status (New/Active/Fixed/Re-Opened), and date range. Returns host records with their detected vulnerabilities. | optional ag_ids, ag_titles, detection_updated_before, detection_updated_since, id_min, ids, ips, limit, qids, severities, show_qds, show_results, status, truncation_limit, vm_scan_date_after |
qualys_list_hosts | List host assets with filtering by IP, asset group, OS, tags, and scan dates. Returns host inventory with IPs, OS, DNS, and last scan info. | optional ag_ids, ag_titles, details, id_min, ids, ips, limit, no_vm_scan_since, os_pattern, show_asset_id, show_tags, truncation_limit, use_tags, vm_scan_since |
qualys_list_ignored_vulns | List currently-ignored vulnerability detections (the audit counterpart to ignore_vulnerability/restore_vulnerability). | optional ag_ids, id_min, ips, limit, qids, severities, truncation_limit |
qualys_list_pc_option_profiles | List Policy Compliance scan option profiles. Returns profile names, IDs, and configuration. | optional limit, profile_id, title |
qualys_list_pc_scan_schedules | List scheduled Policy Compliance scan tasks. | optional active, limit, schedule_id |
qualys_list_reports | List available reports with filtering by state (Running/Finished/Canceled/Errors). | optional expires_before_datetime, limit, report_id, state |
qualys_list_scanner_appliances | List all scanner appliances in the subscription with status and configuration details. | optional limit, output_mode |
qualys_list_scans | List vulnerability scans with filtering by state (Running/Finished/Error), type (On-Demand/Scheduled/API), target, and date range. | optional launched_after_datetime, launched_before_datetime, limit, scan_ref, scan_type, show_ags, show_status, state, target |
qualys_list_tags | List asset tags using the Qualys QPS REST API. Returns tag definitions with IDs and names. | optional limit, name |
qualys_list_vm_option_profiles | List VM scan option profiles. Returns profile names, IDs, and configuration. | optional limit, profile_id, title |
qualys_list_vm_scan_schedules | List scheduled VM scan tasks. | optional active, limit, schedule_id, show_cloud_details, show_notifications |
qualys_manage_asset_group_ips | Add, remove, or set the IP addresses of an existing asset group. action=add/remove edit the set incrementally and apply immediately. | required group_id, action, ipsoptional confirm |
qualys_manage_asset_group_scanners | Add, remove, or set scanner appliances for an asset group. | required group_idoptional add_appliance_ids, remove_appliance_ids, set_appliance_ids |
qualys_manage_compliance_policy_groups | Add, remove, or set asset groups associated with a compliance policy. | required policy_id, action, group_ids |
qualys_manage_compliance_policy_tags | Add, remove, or set asset tags associated with a compliance policy. Tags control which assets are evaluated against the policy. | required policy_id, action, tag_set_includeoptional tag_set_by |
qualys_manage_scan | Cancel, pause, or resume an in-progress vulnerability scan by its scan reference. | required scan_ref, action |
qualys_purge_host_data | Purge scan data for specified hosts. WARNING: This is DESTRUCTIVE AND IRREVERSIBLE. Vulnerability data, scan history, and optionally compliance data will be permanently deleted. | required ipsoptional compliance_purge, confirm |
qualys_qps_request | Escape hatch: call any Qualys QPS REST API endpoint under /qps/rest/ (JSON) when no dedicated tool covers it. | required pathoptional base_url, body, extra_headers, method, pod, query_params |
qualys_remove_excluded_hosts | Remove IPs from the scan exclusion list, re-enabling them for scanning. | required ipsoptional comment |
qualys_restore_vulnerability | Restore (un-ignore) a previously ignored vulnerability on specific hosts, re-enabling it in reports. | required qidsoptional ag_ids, comments, ips, tag_set_by, tag_set_include |
qualys_search_knowledge_base | Search the Qualys vulnerability Knowledge Base by QID, CVE, or date range. | optional cve, details, discovery_method, id_max, id_min, ids, is_patchable, last_modified_after, limit, published_after |
qualys_tag_asset | Add or remove a tag on a host asset by asset ID. Returns a trimmed acknowledgement, not the full asset record. | required asset_id, tag_id, action |
qualys_uninstall_agents | Uninstall the Cloud Agent from one or more hosts by explicit asset ID. DESTRUCTIVE AND IRREVERSIBLE: the agent software is removed and reinstall requires re-deployment; uninstall completes asynchronously on each agent’s next check-in. | required asset_idsoptional base_url, confirm, pod |
Rapid7 InsightAppSec
Section titled “Rapid7 InsightAppSec”12 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
rapid7-insightappsec_create_app | Create a new InsightAppSec application to group scan targets | required nameoptional description |
rapid7-insightappsec_get_app | Get a single InsightAppSec application by its UUID | required app_id |
rapid7-insightappsec_get_scan | Get details of a single scan by ID, including status and progress | required scan_id |
rapid7-insightappsec_get_scan_config | Get a single scan configuration by its UUID | required scan_config_id |
rapid7-insightappsec_get_vulnerability | Get full details for a single vulnerability by its UUID | required vulnerability_id |
rapid7-insightappsec_list_apps | List InsightAppSec applications with optional name search and pagination | optional index, name, size |
rapid7-insightappsec_list_attack_templates | List available attack templates that can be used in scan configurations | optional index, size |
rapid7-insightappsec_list_scan_configs | List scan configurations, optionally filtered by application ID | optional app_id, index, size |
rapid7-insightappsec_list_scans | List scans with optional filtering by application ID or status | optional app_id, index, size, status |
rapid7-insightappsec_search_vulnerabilities | Search for vulnerabilities found by InsightAppSec scans. Use the query parameter with InsightAppSec search syntax, e.g. “vulnerability.scans.id=‘<scan-uuid>’” to filter by scan, or “vulnerability.severity=‘HIGH’” to filter by severity. | optional app_id, index, query, scan_id, severity, size |
rapid7-insightappsec_start_scan | Start a new DAST scan using an existing scan configuration | required scan_config_id |
rapid7-insightappsec_stop_scan | Submit a control action (stop, pause, or resume) to a scan | required scan_idoptional action |
Rapid7 InsightCloudSec
Section titled “Rapid7 InsightCloudSec”12 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
rapid7-insightcloudsec_get_clouds_summary | Get a summary report across all connected cloud accounts: total cloud count, breakdown by cloud provider (AWS/Azure/GCP/etc.), and resource counts by resource type per cloud. | — |
rapid7-insightcloudsec_get_insight | Get the full definition of a single Insight, including its filters, applicable resource types, severity, and metadata. | required insight_idoptional insight_source |
rapid7-insightcloudsec_get_resource | Get full details for a single InsightCloudSec resource by its resource ID, including normalized properties, tags, dependencies (VPCs, subnets, encryption keys), and noncompliance status. | required resource_id |
rapid7-insightcloudsec_get_resource_sources | Get the raw cloud provider source documents that InsightCloudSec harvested for a resource (e.g. the original AWS DescribeInstances response). | required resource_id |
rapid7-insightcloudsec_list_applications | List Applications — user-defined groupings of cloud resources used for scoping (e.g. by business unit, environment, or criticality). Returns each Application’s name, category, resource count, account count, and cloud providers. | optional order_by, page, page_size, search |
rapid7-insightcloudsec_list_cloud_findings | List Insight findings (policy violations) for an entire cloud account. Use to check the compliance posture of a specific cloud. Use ‘cursor’ from the previous response for pagination. | required organization_service_idoptional cursor |
rapid7-insightcloudsec_list_clouds | List all cloud accounts (AWS, Azure, GCP, OCI, Alibaba, etc.) configured in InsightCloudSec, including their connection status, account IDs, harvesting strategy, and resource counts. | — |
rapid7-insightcloudsec_list_filter_registry | List every query filter available for use with search_resources. Returns each filter’s name and the shape of its config object — use this to discover what filters can be applied when searching resources. | — |
rapid7-insightcloudsec_list_insight_packs | List Insight Packs — collections of Insights grouped by compliance framework (CIS, PCI DSS, NIST, SOC 2, HIPAA, etc.) or by Rapid7-curated categories. Use to discover available compliance frameworks and their pack IDs. | — |
rapid7-insightcloudsec_list_insights | List all available Insights (compliance checks and security policies) in InsightCloudSec. Optionally filter by labels (e.g. ‘cis controls’), Insight packs, or resource types. | optional detail, labels, pack_ids, resource_types |
rapid7-insightcloudsec_list_resource_violations | List all Insight findings (policy violations) for a single resource. Returns each matching Insight with its severity, description, and the date it was identified. | required resource_id |
rapid7-insightcloudsec_search_resources | Search InsightCloudSec’s normalized resource inventory across all connected cloud accounts. | optional badge_filter_operator, badges, cursor, filters, insight, limit, offset, scopes, selected_resource_type, tags |
Rapid7 InsightVM
Section titled “Rapid7 InsightVM”18 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
rapid7-insightvm_control_scan | Send a control action to a scan: ‘pause’ (running -> paused), ‘resume’ (paused -> running), ‘stop’ (running or paused -> stopped; non-reversible). | required scan_id, action |
rapid7-insightvm_generate_report | Trigger generation of a new report instance from an existing report config. | required report_idoptional report_format |
rapid7-insightvm_get_asset | Get a single asset’s full detail by ID: hostnames, IPs, OS, MAC addresses, installed software, configurations, services, user accounts, risk score, and vulnerability counts by severity. | required asset_id |
rapid7-insightvm_get_scan | Get a single scan’s status: state (e.g. running, finished, paused, stopped, aborted), vulnerability counts (critical/severe/moderate), discovered asset count, duration, and engine. | required scan_id |
rapid7-insightvm_get_site | Get a single site’s detail by ID. | required site_id |
rapid7-insightvm_get_vulnerability | Get full detail for a single vulnerability: CVSS v2/v3 vectors, PCI severity, CVE references, exploit and malware-kit data, categorical tags, and human-readable description. | required vulnerability_id |
rapid7-insightvm_list_asset_groups | List asset groups defined on the console (static or dynamic): group ID, name, type, asset count, and risk-score aggregate. | optional page, size |
rapid7-insightvm_list_asset_vulnerabilities | List vulnerabilities affecting a specific asset. Returns the vulnerability ID, first/most-recent observation, port/protocol context, exception status, and proof string. | required asset_idoptional page, size |
rapid7-insightvm_list_assets | List all assets known to the InsightVM console with paginated results. Returns asset summaries including hostnames, IPs, OS fingerprint, risk score, and last-scanned timestamp. | optional page, size, sort |
rapid7-insightvm_list_reports | List all report configurations defined on the console: report ID, name, format, template, owner, and scope. Use generate_report with one of these IDs to trigger a fresh report instance. | optional page, size |
rapid7-insightvm_list_scans | List scans across the console with optional active-only filter. Returns scan ID, site, status, start/end times, duration, engine, and discovered-vulnerability counts. | optional active_only, page, size |
rapid7-insightvm_list_sites | List all scan sites configured on the InsightVM console: site names, scan template, scan engine, target asset count, and last-scan summary. | optional page, size |
rapid7-insightvm_list_tags | List tags configured on the console (custom, location, owner, criticality, etc.). Tags drive dynamic asset-group membership and reporting scope. | optional page, size |
rapid7-insightvm_list_vulnerabilities | List vulnerabilities in the InsightVM vulnerability catalog. Optional severity filter narrows results to Critical / Severe / Moderate. Returns paged summaries with CVSS scores, exploit and malware-kit availability flags. | optional page, severity, size |
rapid7-insightvm_list_vulnerability_exceptions | List vulnerability exceptions (accepted-risk decisions) on the console: exception ID, vulnerability, scope, reason, expiration, submitter, and approval status. | optional page, size |
rapid7-insightvm_list_vulnerability_solutions | List remediation solutions for a vulnerability: patch references, configuration changes, workarounds, and the estimated time / effort required. Use to inform a remediation playbook. | required vulnerability_idoptional page, size |
rapid7-insightvm_search_assets | Search assets using InsightVM filter expressions. Supply a list of {field, operator, value} filters and a match mode (‘all’ for AND, ‘any’ for OR). | required filtersoptional match, page, size |
rapid7-insightvm_start_site_scan | Start a new scan against a site. Optionally override the scan engine, scan template, hosts (IP / hostname list), or assign a human-readable scan name. Returns the new scan ID. | required site_idoptional engine_id, hosts, name, template_id |
Rapid7 InsightVM Cloud
Section titled “Rapid7 InsightVM Cloud”10 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
rapid7-insightvm-cloud_get_asset | Get a single asset’s full detail by ID: hostnames, IPs, OS, MAC addresses, installed software, services, risk score, and vulnerability counts by severity. | required asset_id |
rapid7-insightvm-cloud_get_scan | Get a single scan’s status: state (e.g. running, finished, paused, stopped, aborted), vulnerability counts (critical/severe/moderate), discovered asset count, duration, and engine. | required scan_id |
rapid7-insightvm-cloud_get_site | Get a single site’s detail by ID: name, description, scan template, scan engine, target asset count, vulnerability counts, and last-scan summary. | required site_id |
rapid7-insightvm-cloud_get_vulnerability | Get full detail for a single vulnerability: CVSS v2/v3 vectors, PCI severity, CVE references, exploit and malware-kit data, categorical tags, and human-readable description. | required vulnerability_id |
rapid7-insightvm-cloud_list_asset_vulnerabilities | List vulnerabilities affecting a specific asset. Returns the vulnerability ID, first/most-recent observation, port/protocol context, and proof string. Use get_vulnerability for the full vulnerability description and severity. | required asset_idoptional page, size |
rapid7-insightvm-cloud_list_assets | List assets known to the InsightVM Cloud platform with paginated results. Returns asset summaries including hostnames, IPs, OS fingerprint, risk score, and last-scanned timestamp. | optional page, size, sort |
rapid7-insightvm-cloud_list_scan_engines | List scan engines available to the Cloud platform: engine ID, name, status, address, port, last-refresh time, and engine pool membership. Useful for confirming which engines are online before correlating recent scan results. | optional page, size |
rapid7-insightvm-cloud_list_scans | List scans across the Cloud platform with optional active-only filter. Returns scan ID, site, status, start/end times, duration, engine, and discovered-vulnerability counts. | optional active_only, page, size |
rapid7-insightvm-cloud_list_sites | List all scan sites configured on the InsightVM Cloud platform: site names, scan template, scan engine, target asset count, and last-scan summary. | optional page, size |
rapid7-insightvm-cloud_list_vulnerabilities | List vulnerabilities in the InsightVM Cloud catalog. Optional severity filter narrows results to Critical / Severe / Moderate. Returns paged summaries with CVSS scores, exploit and malware-kit availability flags. | optional page, severity, size |
8 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
snyk_get_api_security_finding | Retrieve a single Snyk API Security finding by id. Note: endpoint shape is best-effort and may need adjustment against real tenant. | required org_id, finding_id |
snyk_get_issue | Retrieve a single Snyk security issue by id. Returns full detail including CWE/CVE classes, problem references, coordinate paths, and risk scoring. | required org_id, issue_id |
snyk_get_organization | Retrieve a single Snyk organization by id. | required org_id |
snyk_get_project | Retrieve a single Snyk project by id within an organization. | required org_id, project_id |
snyk_list_api_security_findings | List Snyk API Security findings in an organization — API risk discoveries from Snyk’s API Security product. Filter by severity or status. Cursor-paginated. | required org_idoptional ending_before, limit, severity, starting_after, status |
snyk_list_issues | List Snyk security issues (vulnerabilities, license issues, code issues) in an organization. Scope to a single project by passing project_id. Filter by severity, status, type, or ignored state. Cursor-paginated. | required org_idoptional effective_severity_levels, ending_before, ignored, limit, project_id, starting_after, statuses, types |
snyk_list_organizations | List Snyk organizations the authenticated token can access. Cursor-paginated via starting_after / ending_before. | optional ending_before, limit, starting_after |
snyk_list_projects | List Snyk projects in an organization. Optional filters: origins (e.g. github, gitlab, cli), types (e.g. npm, maven, docker), target_id. Cursor-paginated. | required org_idoptional ending_before, limit, origins, starting_after, target_id, types |
Tenable Vulnerability Management
Section titled “Tenable Vulnerability Management”16 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
tenable-vulnerability-management_check_asset_export_status | Poll the status of a running asset export job. Indicates completion % or chunk availability for Nessus-scanned assets. | required export_job_id |
tenable-vulnerability-management_check_vuln_export_status | Poll the status of a running vulnerability export job. Indicates completion % or chunk availability for Nessus findings. | required export_job_id |
tenable-vulnerability-management_get_asset_activity_log | Get activity log for a Nessus-scanned asset showing discovery, scans, attribute changes, tagging events, updates, and source information over time. | required asset_uuid |
tenable-vulnerability-management_get_asset_details | Get detailed information for a specific Nessus-scanned asset including vulnerabilities, tags, installed software, cloud metadata (AWS/Azure/GCP), and Lumin metrics. | required asset_uuid |
tenable-vulnerability-management_get_asset_export_chunk | Retrieve a chunk of exported asset data. Each chunk contains Nessus-scanned asset records with details and tags. | required export_job_id, chunk_id |
tenable-vulnerability-management_get_asset_vuln_outputs | Retrieve Nessus plugin outputs (evidence details) for a specific vulnerability on a specific asset. Shows the proof of vulnerability occurrence. | required asset_id, plugin_id |
tenable-vulnerability-management_get_plugin_details | Get detailed Nessus plugin information including description, solution, CVSS scores, VPR, exploit availability, and references. Supports filtering to scope results. | required plugin_idoptional date_range, filter_search_type, filters |
tenable-vulnerability-management_get_vuln_export_chunk | Retrieve a chunk of exported vulnerability data. Once an export is ready, fetch Nessus vulnerabilities. | required export_job_id, chunk_id |
tenable-vulnerability-management_list_asset_filters | List available Nessus asset filters with their names, operators, and validation rules. Use this to discover valid filter names and operators for the list_assets and list_assets_with_vulnerabilities tools. | — |
tenable-vulnerability-management_list_asset_vulnerabilities | List up to 5,000 Nessus-detected vulnerabilities found on a specific asset with summary info (plugin ID, severity, VPR, state). Supports filtering. | required asset_idoptional date_range, filter_search_type, filters |
tenable-vulnerability-management_list_assets | List up to 5,000 Nessus-scanned assets with summary info (IP addresses, OS, agent status, sources). Supports filtering. For larger datasets, use asset export tools. | optional all_fields, date_range, filter_search_type, filters |
tenable-vulnerability-management_list_assets_with_vulnerabilities | List up to 5,000 Nessus-scanned assets that have vulnerabilities, showing each asset with severity counts (info/low/medium/high/critical). | optional date_range, filter_search_type, filters |
tenable-vulnerability-management_list_vulnerabilities | List up to 5,000 Nessus-detected vulnerabilities with summary info (plugin ID, severity, VPR, state). Limited to 450 days of data. For larger exports, use vuln export tools. | optional date_range, filter_search_type, filters |
tenable-vulnerability-management_list_vulnerability_filters | List available Nessus vulnerability filters with their names, operators, and validation rules. Use this to discover valid filter names and operators for the list_vulnerabilities, get_plugin_details, and list_asset_vulnerabilities tools. | — |
tenable-vulnerability-management_start_asset_export | Initiate an export of assets with tags and metadata. Includes assets discovered by Nessus scans. | optional chunk_size, filters, include_open_ports |
tenable-vulnerability-management_start_vuln_export | Initiate an export of vulnerabilities matching criteria. Starts a Tenable vuln export job. Exports Nessus scan findings. | optional chunk_size, filters, since, state |
Traceable
Section titled “Traceable”4 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
traceable_api_spec_conformance_results | Query API spec conformance results — shadow endpoints, orphan endpoints, parameter diffs, and summaries. | required spec_id, query_typeoptional limit, offset |
traceable_entities | Query Traceable entities (API, SERVICE, BACKEND, DOMAIN, ACTOR). Always returns id, type, and labels. Optionally include metrics (provide metric_key), attributes (provide attribute_key), or edges (provide edge_neighbor_type). | optional attribute_key, between, edge_neighbor_scope, edge_neighbor_type, edge_type, entity_type, filter_by, include_inactive, limit, metric_key, offset, order_by, scope, space |
traceable_parameter_insights | Query API parameter insights — names, types, PII classification, and change tracking. | optional aggregation_key, aggregation_type, entity_type, filter_by, group_by, limit, offset, order_by, selection_fields |
traceable_threat_activity | Query threat activity records. Always returns selection fields (default: ID, TYPE, SEVERITY_LEVEL, ACTIVITY_STATUS, IS_BLOCKED, ACTOR_ENTITY_ID, SERVICE_NAME, API_NAME, CATEGORIES, START_TIME_MILLIS, LAST_SEEN_MILLIS, EVENTS_COUNT). | optional aggregation_key, aggregation_type, filter_by, group_by, limit, offset, order_by, selection_fields, unnest |
Wiz (Client Credentials)
Section titled “Wiz (Client Credentials)”1 tool. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
wiz-cc_list_all_vulnerability_findings | Return a COMPLETE, deterministic set of Wiz vulnerability findings by walking the cursor server-side, instead of relying on the model to paginate. Repeated identical queries return identical counts. | optional fields, filters, max_results, order_by_direction, order_by_field, page_size, source_tool |
