RAD Security
About
Interact with the RAD Security platform which provides AI-powered security insights for Kubernetes and cloud environments.
Details
- License
- MIT license
Explore
- Account inventory and cluster details
- Security findings analysis
- Runtime security and process behavior
- Network security monitoring
- Kubernetes object and misconfiguration policies
- CVE listing and vulnerability details
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
RAD SecurityCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Install via npm: npm install @rad-security/mcp-server. Requires Node.js 20.x or higher. Set three environment variables (RAD_SECURITY_ACCESS_KEY_ID, RAD_SECURITY_SECRET_KEY, RAD_SECURITY_ACCOUNT_ID) for full functionality. The server can be run directly, configured in Cursor IDE or Claude Desktop, or deployed as a Docker container using either Streamable HTTP (recommended) or SSE (deprecated) transport.
list_containers
List containers secured by RAD Security with optional filtering by image name, image digest, namespace, cluster_id, or free text search
get_container_details
Get detailed information about a container secured by RAD Security
list_clusters
List Kubernetes clusters managed by RAD Security
get_cluster_details
Get detailed information about a specific Kubernetes cluster managed by RAD Security
who_shelled_into_pod
Get k8s audit logs with information about users who shelled into a pod
list_images
List container images with optional filtering by page, page size, sort, and search query
list_image_vulnerabilities
List vulnerabilities in a container image with optional filtering by severity
get_top_vulnerable_images
Get the most vulnerable images from your account
get_image_sbom
Get the SBOM of a container image
ignore_cve
Ignore a CVE for this account so it no longer appears in vulnerability reporting. Use for confirmed false positives, accepted risks, or won't-fix decisions. Do NOT use for remediated CVEs — those drop off automatically on the next scan.
unignore_cve
Remove an account-wide CVE disposition, restoring the CVE to vulnerability reporting.
list_cve_dispositions
List active CVE dispositions (ignored / false positive) for this account, with reason and author.
get_k8s_resource_details
Get the latest manifest of a Kubernetes resource
list_k8s_resources
List Kubernetes resources with optional filtering by namespace, resource types, and cluster
get_containers_process_trees
Get process trees for multiple containers
get_containers_baselines
Get runtime baselines for multiple containers
get_container_llm_analysis
Get LLM analysis of a container's process tree
list_security_findings
List security findings with optional filtering by types, severities, sources, and status
update_security_finding_status
Update the status of a security finding
mark_inbox_item_as_false_positive
Mark an inbox item as a false positive with a reason
list_inbox_items
List inbox items with optional filtering by any field. Multiple filters can be combined eg. 'search:cve-2024-12345 and severity:high'
get_inbox_item_details
Get detailed information about a specific inbox item
list_workflows
List all workflows
get_workflow
Get detailed information about a specific workflow by ID. It contains the workflow definition, default arguments, and schema how to run the workflow
list_workflow_runs
List workflow runs with optional filtering by workflow ID
get_workflow_run
Get detailed information about a specific workflow run
run_workflow
Run a workflow with optional argument overrides
list_workflow_schedules
List workflow schedules with optional filtering by workflow ID
create_custom_workflow
Create a new automation (a Windmill workflow) from a YAML definition. Pass the YAML document itself as a string, not a file path. It is validated server-side before deployment; on failure nothing is deployed and the errors are returned. Returns the new automation WITHOUT echoing the definition back — use `id` from the result when referring to it, and `get_workflow` if you need to read the definition.
update_custom_workflow
Update an existing automation with new YAML. Only automations created via create_custom_workflow can be updated. Returns the updated automation without echoing the definition back.
add_workflow_schedule
Add a cron-based schedule to an automation so it runs automatically at the specified times.
search_knowledge_base
Search your organization's knowledge base to find relevant uploaded documents, procedures, reports, and other content using natural language queries
list_knowledge_base_collections
List all collections in your organization's knowledge base. Collections are used to organize and categorize documents
list_knowledge_base_documents
List documents in your organization's knowledge base with optional filtering by collections, file type, or status
query_knowledge_base_document
Query a CSV document from the knowledge base using natural language. IMPORTANT: This tool ONLY works with CSV documents. Use list_knowledge_base_documents with filters='file_type:csv' to find CSV document IDs (search_knowledge_base results also contain document IDs). Results are returned as a markdown table
get_knowledge_base_document_content
Get the FULL text content of a knowledge base document (extracted text for PDF/DOCX, the raw file for markdown/plaintext/CSV). Use this to read or analyze a whole document rather than the excerpts search_knowledge_base returns. Find document IDs via list_knowledge_base_documents or search_knowledge_base results
get_knowledge_base_document_download_url
Get a time-limited download URL for the ORIGINAL document file (any format, including PDF/DOCX binaries). Use when you need the original file itself — e.g. to fetch it into a sandbox for structural parsing (tables, layout), or when get_knowledge_base_document_content reports no text available. For reading text, prefer get_knowledge_base_document_content
radql_list_data_types
List all available RadQL data types (discovery). ALWAYS call this FIRST before using other RadQL tools to discover what data is available to query. Returns data types like 'containers', 'kubernetes_resources', 'inbox_items', 'cloud_resources', 'cloud_benchmarks', 'cloud_benchmark_summaries', etc. with descriptions.
radql_get_type_metadata
Get schema/metadata for a specific RadQL data type. Shows available fields, data types, which fields can be filtered/searched, and provides query examples. Call this AFTER radql_list_data_types to understand how to query a specific data type.
radql_list_filter_values
List possible values for a filter field (e.g., namespace list, cluster list, severity values). Useful for building dynamic filters when you need to know available enum-like values. Call this when constructing filters that need specific values.
radql_query
Execute RadQL queries for security investigations. Supports: list (filter/search), get_by_id (single item), stats (aggregations). WORKFLOW: radql_list_data_types -> radql_get_type_metadata -> radql_query COMMON FIELDS BY DATA TYPE: containers: name, image_name, image_repo, owner_kind, cluster_id, created_at Example: image_name:*nginx* AND owner_kind:Pod finding_groups: type, source_kind, source_name, rule_title, severity, event_timestamp Types: k8s_misconfiguration, k8s_audit_logs_anomaly Example: type:k8s_misconfiguration AND severity:critical inbox_items: severity (High|Medium|Low), type, title, archived, false_positive, created_at Example: severity:High AND archived:false kubernetes_resources: kind, name, namespace, cluster_id, owner_kind, created_at Example: kind:Deployment AND namespace:production CLOUD RESOURCES & COMPLIANCE (use these RadQL data types instead of dedicated cloud tools): cloud_resources: cloud_provider, cloud_account_id, resource_type, resource_name, resource_id, resource_json, last_seen_at Example: cloud_provider:aws AND resource_type:aws_iam_policy cloud_benchmark_summaries: cloud_provider, cloud_account_id, benchmark_id, title, description, fail_count, pass_count, total_count, last_seen_at Example: cloud_provider:aws AND fail_count>0 cloud_benchmarks: cloud_provider, cloud_account_id, benchmark_id, control_id, control_title, severity, status, reason, resource_id, last_seen_at Example: status:fail AND benchmark_id:*cis* CRITICAL QUOTING RULES: MUST quote when value contains: - Dates/timestamps: created_at>"2024-01-01" (NOT created_at>2024-01-01) - Hyphens: cluster_id:"abc-123-def", name:"kube-system" - UUIDs: id:"550e8400-e29b-41d4-a716-446655440000" - Spaces: title:"my alert" - Special chars: :, =, <, >, !, (, ) - Wildcards with hyphens: name:"kube-*" OK to leave unquoted: - Simple strings: status:active, kind:Pod - Numbers: count:123 - Booleans: archived:true - Simple wildcards: name:nginx* For complete schema: call radql_get_type_metadata with target data_type
radql_query_builder
Helper tool to build RadQL queries programmatically from structured conditions. Useful when you need to construct complex filter or stats queries from structured inputs.
radql_batch_query
Execute multiple RadQL queries in parallel for efficiency. Useful for fetching related data from different data types simultaneously (e.g., container details + vulnerabilities + network connections).
list_widget_templates
List widget templates with optional filtering by visualization type and category
get_widget_template
Get detailed information about a specific widget template
list_dashboard_templates
List dashboard templates with optional filtering by category
get_dashboard_template
Get detailed information about a specific dashboard template
list_dashboards
List dashboards for the account
get_dashboard
Get detailed information about a specific dashboard
create_dashboard
Create a dashboard for the account. Build `rows` from the widget templates (list_widget_templates / get_widget_template) so the visualization and query shapes are valid.
update_dashboard
Update an existing dashboard. Omitted fields are left unchanged, so a small edit (a title, one row) does not require resending the whole dashboard.
list_external_integrations
List external integrations configured for the tenant (e.g., Slack, AWS CloudTrail, Okta). Returns integration details including capabilities, configuration, mcp support and sync status.
- list_containers: List containers secured by RAD Security with optional filtering by image name, image digest, namespace, cluster_id, or free text search
- get_container_details: Get detailed information about a container secured by RAD Security
- list_clusters: List Kubernetes clusters managed by RAD Security
- get_cluster_details: Get detailed information about a specific Kubernetes cluster managed by RAD Security
- who_shelled_into_pod: Get k8s audit logs with information about users who shelled into a pod
- list_images: List container images with optional filtering by page, page size, sort, and search query
- list_image_vulnerabilities: List vulnerabilities in a container image with optional filtering by severity
- get_top_vulnerable_images: Get the most vulnerable images from your account
- get_image_sbom: Get the SBOM of a container image
- ignore_cve: Ignore a CVE for this account so it no longer appears in vulnerability reporting. Use for confirmed false positives, accepted risks, or won't-fix decisions. Do NOT use for remediated CVEs — those drop off automatically on the next scan.
- unignore_cve: Remove an account-wide CVE disposition, restoring the CVE to vulnerability reporting.
- list_cve_dispositions: List active CVE dispositions (ignored / false positive) for this account, with reason and author.
- get_k8s_resource_details: Get the latest manifest of a Kubernetes resource
- list_k8s_resources: List Kubernetes resources with optional filtering by namespace, resource types, and cluster
- get_containers_process_trees: Get process trees for multiple containers
- get_containers_baselines: Get runtime baselines for multiple containers
- get_container_llm_analysis: Get LLM analysis of a container's process tree
- list_security_findings: List security findings with optional filtering by types, severities, sources, and status
- update_security_finding_status: Update the status of a security finding
- mark_inbox_item_as_false_positive: Mark an inbox item as a false positive with a reason
- list_inbox_items: List inbox items with optional filtering by any field. Multiple filters can be combined eg. 'search:cve-2024-12345 and severity:high'
- get_inbox_item_details: Get detailed information about a specific inbox item
- list_workflows: List all workflows
- get_workflow: Get detailed information about a specific workflow by ID. It contains the workflow definition, default arguments, and schema how to run the workflow
- list_workflow_runs: List workflow runs with optional filtering by workflow ID
- get_workflow_run: Get detailed information about a specific workflow run
- run_workflow: Run a workflow with optional argument overrides
- list_workflow_schedules: List workflow schedules with optional filtering by workflow ID
- create_custom_workflow: Create a new automation (a Windmill workflow) from a YAML definition. Pass the YAML document itself as a string, not a file path. It is validated server-side before deployment; on failure nothing is deployed and the errors are returned. Returns the new automation WITHOUT echoing the definition back — use id from the result when referring to it, and get_workflow if you need to read the definition.
- update_custom_workflow: Update an existing automation with new YAML. Only automations created via create_custom_workflow can be updated. Returns the updated automation without echoing the definition back.
- add_workflow_schedule: Add a cron-based schedule to an automation so it runs automatically at the specified times.
- search_knowledge_base: Search your organization's knowledge base to find relevant uploaded documents, procedures, reports, and other content using natural language queries
- list_knowledge_base_collections: List all collections in your organization's knowledge base. Collections are used to organize and categorize documents
- list_knowledge_base_documents: List documents in your organization's knowledge base with optional filtering by collections, file type, or status
- query_knowledge_base_document: Query a CSV document from the knowledge base using natural language. IMPORTANT: This tool ONLY works with CSV documents. Use list_knowledge_base_documents with filters='file_type:csv' to find CSV document IDs (search_knowledge_base results also contain document IDs). Results are returned as a markdown table
- get_knowledge_base_document_content: Get the FULL text content of a knowledge base document (extracted text for PDF/DOCX, the raw file for markdown/plaintext/CSV). Use this to read or analyze a whole document rather than the excerpts search_knowledge_base returns. Find document IDs via list_knowledge_base_documents or search_knowledge_base results
- get_knowledge_base_document_download_url: Get a time-limited download URL for the ORIGINAL document file (any format, including PDF/DOCX binaries). Use when you need the original file itself — e.g. to fetch it into a sandbox for structural parsing (tables, layout), or when get_knowledge_base_document_content reports no text available. For reading text, prefer get_knowledge_base_document_content
- radql_list_data_types: List all available RadQL data types (discovery). ALWAYS call this FIRST before using other RadQL tools to discover what data is available to query. Returns data types like 'containers', 'kubernetes_resources', 'inbox_items', 'cloud_resources', 'cloud_benchmarks', 'cloud_benchmark_summaries', etc. with descriptions.
- radql_get_type_metadata: Get schema/metadata for a specific RadQL data type. Shows available fields, data types, which fields can be filtered/searched, and provides query examples. Call this AFTER radql_list_data_types to understand how to query a specific data type.
- radql_list_filter_values: List possible values for a filter field (e.g., namespace list, cluster list, severity values). Useful for building dynamic filters when you need to know available enum-like values. Call this when constructing filters that need specific values.
- radql_query: Execute RadQL queries for security investigations. Supports: list (filter/search), get_by_id (single item), stats (aggregations).
WORKFLOW: radql_list_data_types -> radql_get_type_metadata -> radql_query
COMMON FIELDS BY DATA TYPE:
containers: name, image_name, image_repo, owner_kind, cluster_id, created_at
Example: image_name:nginx AND owner_kind:Pod
finding_groups: type, source_kind, source_name, rule_title, severity, event_timestamp
Types: k8s_misconfiguration, k8s_audit_logs_anomaly
Example: type:k8s_misconfiguration AND severity:critical
inbox_items: severity (High|Medium|Low), type, title, archived, false_positive, created_at
Example: severity:High AND archived:false
kubernetes_resources: kind, name, namespace, cluster_id, owner_kind, created_at
Example: kind:Deployment AND namespace:production
CLOUD RESOURCES & COMPLIANCE (use these RadQL data types instead of dedicated cloud tools):
cloud_resources: cloud_provider, cloud_account_id, resource_type, resource_name, resource_id, resource_json, last_seen_at
Example: cloud_provider:aws AND resource_type:aws_iam_policy
cloud_benchmark_summaries: cloud_provider, cloud_account_id, benchmark_id, title, description, fail_count, pass_count, total_count, last_seen_at
Example: cloud_provider:aws AND fail_count>0
cloud_benchmarks: cloud_provider, cloud_account_id, benchmark_id, control_id, control_title, severity, status, reason, resource_id, last_seen_at
Example: status:fail AND benchmark_id:cis
CRITICAL QUOTING RULES:
MUST quote when value contains:
- Dates/timestamps: created_at>"2024-01-01" (NOT created_at>2024-01-01)
- Hyphens: cluster_id:"abc-123-def", name:"kube-system"
- UUIDs: id:"550e8400-e29b-41d4-a716-446655440000"
- Spaces: title:"my alert"
- Special chars: :, =, <, >, !, (, )
- Wildcards with hyphens: name:"kube-"
OK to leave unquoted:
- Simple strings: status:active, kind:Pod
- Numbers: count:123
- Booleans: archived:true
- Simple wildcards: name:nginx
For complete schema: call radql_get_type_metadata with target data_type
- radql_query_builder: Helper tool to build RadQL queries programmatically from structured conditions. Useful when you need to construct complex filter or stats queries from structured inputs.
- radql_batch_query: Execute multiple RadQL queries in parallel for efficiency. Useful for fetching related data from different data types simultaneously (e.g., container details + vulnerabilities + network connections).
- list_widget_templates: List widget templates with optional filtering by visualization type and category
- get_widget_template: Get detailed information about a specific widget template
- list_dashboard_templates: List dashboard templates with optional filtering by category
- get_dashboard_template: Get detailed information about a specific dashboard template
- list_dashboards: List dashboards for the account
- get_dashboard: Get detailed information about a specific dashboard
- create_dashboard: Create a dashboard for the account. Build rows from the widget templates (list_widget_templates / get_widget_template) so the visualization and query shapes are valid.
- update_dashboard: Update an existing dashboard. Omitted fields are left unchanged, so a small edit (a title, one row) does not require resending the whole dashboard.
- list_external_integrations: List external integrations configured for the tenant (e.g., Slack, AWS CloudTrail, Okta). Returns integration details including capabilities, configuration, mcp support and sync status.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"rad security": {
"rad-security_mcp-server": {
"command": "docker",
"args": [
"build",
"-t",
"rad-security/mcp-server",
"."
]
}
}
}
}
McpServers
{
"rad-security_mcp-server": {
"command": "docker",
"args": [
"build",
"-t",
"rad-security/mcp-server",
"."
]
}
}
- List security findings— Ask your assistant to list and analyze security findings across your Kubernetes and cloud environments.
- Investigate runtime behavior— Get process trees, runtime baselines, and process behavior analysis for running containers.
- Query images and vulnerabilities— Retrieve SBOMs, list top vulnerable images, and manage CVE dispositions like ignoring or unignoring CVEs.
- Manage automations— List, create, update, and run automations (workflows) with cron schedules directly from chat.
- Search the knowledge base— Search collections and documents, and run structured queries against specific documents.
- Execute RadQL queries— Run advanced queries with filtering, searching, and aggregations across data types like containers and findings.
A Model Context Protocol (MCP) server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments.
RAD Security runs the MCP server for you, so most users don't need to install or host anything. Point your MCP client at the hosted endpoint and authenticate with your RAD Security credentials.
-
Endpoint:https://api.rad.security/mcp/— note thetrailing slash.
Authentication:send your credential in theAuthorizationheader:
Authorization: Bearer <access_key_id>:<secret_key>:<account_id>
<access_key_id>and<secret_key>are a RAD Security API access key (create one in the RAD Security console);<account_id>is your account ID. The server authenticates every request against the RAD Security API — no credentials are stored server-side.
A short-lived formBearer ory_st_<session_token>:<account_id>also works, but session tokens expire — prefer an access key for anything long-lived (e.g. Slack / Claude Tag).
claude mcp add --transport http rad-security https://api.rad.security/mcp/ \ --header "Authorization: Bearer <access_key_id>:<secret_key>:<account_id>"
[mcp_servers.rad-security] url = "https://api.rad.security/mcp/" http_headers = { "Authorization" = "Bearer <access_key_id>:<secret_key>:<account_id>" }
Or via the CLI, keeping the secret in an env var (export RAD_MCP_TOKEN=<access_key_id>:<secret_key>:<account_id>):
codex mcp add rad-security --url https://api.rad.security/mcp/ --bearer-token-env-var RAD_MCP_TOKEN
{ "mcpServers": { "rad-security": { "type": "http", "url": "https://api.rad.security/mcp/", "headers": { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" } } } }
.vscode/mcp.json— note the wrapper key isservers, notmcpServers:
{ "servers": { "rad-security": { "type": "http", "url": "https://api.rad.security/mcp/", "headers": { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" } } } }
~/.gemini/settings.json— note the URL field ishttpUrl(noturl):
{ "mcpServers": { "rad-security": { "httpUrl": "https://api.rad.security/mcp/", "headers": { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" } } } }
cline_mcp_settings.json— notetypemust be exactlystreamableHttp(camelCase):
{ "mcpServers": { "rad-security": { "type": "streamableHttp", "url": "https://api.rad.security/mcp/", "headers": { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" } } } }
~/.codeium/windsurf/mcp_config.json— note the URL field isserverUrl:
{ "mcpServers": { "rad-security": { "serverUrl": "https://api.rad.security/mcp/", "headers": { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" } } } }
Most MCP clients accept a remote Streamable HTTP server with a URL and anAuthorizationheader — only the field names differ. Keep thetrailing slashon the URL in every case.
Claude.ai / Claude Desktop / Claude Tag (Slack)
These surfaces add remote MCP servers asconnectors, which use their own credential settings rather than a raw request header. Addhttps://api.rad.security/mcp/as a custom connector, then supply the bearer credential through the connector's settings:
- Claude Tag (Slack):attach the server as a plugin whose.mcp.jsonpoints at the endpoint, and add the bearer credential on the Access bundle'sCredentialstab. SeeClaude Tag — connect a custom MCP server.
- Claude.ai / Desktop:add it under Settings → Connectors; seecustom connectors.
npx @modelcontextprotocol/inspector # Transport: Streamable HTTP # URL: https://api.rad.security/mcp/ (trailing slash) # Custom headers: { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" }
curl -H "authorization: Bearer <access_key_id>:<secret_key>:<account_id>" \ -H "content-type: application/json" \ -H "accept: application/json, text/event-stream" \ -X POST https://api.rad.security/mcp/ \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"curl","version":"1"}}}'
By default a connection gets every toolkit. To give an agent a smaller set — less context/token overhead, and least privilege — add a scoping header to that connection alongsideAuthorization. The subset is enforced: an out-of-scope tool is hidden fromtools/listandrejected if called.
Toolkits:containers,clusters,audit,images,kubeobject,runtime,findings,inbox,workflows,knowledge_base,radql,dashboards,integrations. All are enabled by default — narrow with the headers above, and useX-Rad-Readonlywhen you want to exclude every write tool.
Example — a read-only findings/images agent (any client that supports headers; Cursor shown):
{ "mcpServers": { "rad-security-findings": { "type": "http", "url": "https://api.rad.security/mcp/", "headers": { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>", "X-Rad-Toolkits": "findings, images", "X-Rad-Readonly": "true" } } } }
In Claude Code, pass an extra--header:
claude mcp add --transport http rad-security https://api.rad.security/mcp/ \ --header "Authorization: Bearer <access_key_id>:<secret_key>:<account_id>" \ --header "X-Rad-Toolkits: findings, images"
All tools require authentication and an account in RAD Security. The hosted endpoint exposes every toolkit below by default; scope a client down withX-Rad-Toolkits/X-Rad-Exclude-Toolkits, or drop all write tools withX-Rad-Readonly: true.
- List and analyze security findings
- Update the status of a security finding
- Get process trees of running containers
- Get runtime baselines of running containers
- Analyze process behavior of running containers
- Get SBOMs
- List images and their vulnerabilities
- Get top vulnerable images
- Ignore / unignore CVEs and list active CVE dispositions
- Get details of a specific Kubernetes resource
- List Kubernetes resources
- List inbox items and their details
- Mark an inbox item as a false positive
- List automations, runs and schedules
- Get automation and run details
- Run an automation
- Create and update automations, and add cron schedules
"Automation" is the product name users see; "workflow" is the underlying Windmill object the API and tool names use. They are the same thing.
- Search the knowledge base
- List collections and documents
- Run structured queries against a document
- List dashboards and get their details
- List and get dashboard and widget templates
- Create a dashboard, and update one in place (omitted fields are left unchanged, so a small edit does not require resending the whole dashboard)
- List available data types for querying (containers, findings, kubernetes_resources, etc.)
- Get schema/metadata for specific data types
- List possible values for filter fields
- Execute RadQL queries with filtering, searching, and aggregations
- Build queries programmatically from structured conditions
- Execute multiple queries in parallel
Prefer to run the server yourself — for example an air-gapped environment, data-residency requirements, or if you don't want to route through the hosted gateway? It's published to npm and as a container image.
Provide your RAD Security credentials via environment variables:
RAD_SECURITY_ACCESS_KEY_ID="your_access_key" RAD_SECURITY_SECRET_KEY="your_secret_key" RAD_SECURITY_ACCOUNT_ID="your_account_id" # Optional: fetched automatically from the account if not set RAD_SECURITY_TENANT_ID="your_tenant_id"
{ "mcpServers": { "rad-security": { "command": "npx", "args": ["-y", "@rad-security/mcp-server"], "env": { "RAD_SECURITY_ACCESS_KEY_ID": "<your-access-key-id>", "RAD_SECURITY_SECRET_KEY": "<your-secret-key>", "RAD_SECURITY_ACCOUNT_ID": "<your-account-id>" } } } }
docker build -t rad-security/mcp-server . docker run \ -e TRANSPORT_TYPE=streamable \ -e RAD_SECURITY_ACCESS_KEY_ID=your_access_key \ -e RAD_SECURITY_SECRET_KEY=your_secret_key \ -e RAD_SECURITY_ACCOUNT_ID=your_account_id \ -p 3000:3000 \ rad-security/mcp-server
Control which toolkits a self-hosted server exposes:
- INCLUDE_TOOLKITS: comma-separated list of toolkits to include (only these are enabled).
- EXCLUDE_TOOLKITS: comma-separated list of toolkits to exclude (all others are enabled). Ignored ifINCLUDE_TOOLKITSis set.
Available toolkits:containers,clusters,audit,images,kubeobject,runtime,findings,inbox,workflows,knowledge_base,radql,dashboards,integrations. All are enabled by default.
# Only the workflows toolkit INCLUDE_TOOLKITS="workflows" # Everything except runtime EXCLUDE_TOOLKITS="runtime"
MCP_AUTH_MODEcontrols how a streamable HTTP deployment authenticates inbound requests — this is what the hosted endpoint uses:
- MCP_AUTH_MODE=env(default) — every session uses theRAD_SECURITY_*environment credentials. Single-tenant, andunauthenticated at the HTTP layer, so it must not be reachable from untrusted networks.
- MCP_AUTH_MODE=header— every request must carry its own credential in theAuthorizationheader (theBearer <access_key_id>:<secret_key>:<account_id>form above); a missing or malformed header is rejected with401. Only supported withTRANSPORT_TYPE=streamable.RAD_SECURITY_API_URLis taken from server config, not the caller.
docker run \ -e TRANSPORT_TYPE=streamable \ -e MCP_AUTH_MODE=header \ -e RAD_SECURITY_API_URL=https://api.rad.security \ -p 3000:3000 \ rad-security/mcp-server
The SSE transport (TRANSPORT_TYPE=sse) is deprecated in favor of Streamable HTTP and uses env credentials only.
# Install dependencies npm install # Run type checking npm run type-check # Run linter npm run lint # Build npm run build
MIT License - see theLICENSEfile for details
AI health, token usage, LLM cost optimization, BYOK vault, and cleanup audits for MCP agents.
This AWS Labs Model Context Protocol (MCP) server for CloudTrail enables your AI agents to query AWS account activity for security investigations, compliance auditing, and operational troubleshooting.
Query and interact with kubernetes environments monitored by Metoro
Provides a unified interface to AWS services for security investigations and incident response.
A comprehensive Model Context Protocol (MCP) server for the Cloudability API, providing advanced cost management, Kubernetes container analytics, and budget forecasting capabilities.
Provides direct access to CORTEX infrastructure for orchestration, monitoring, AI flow management, model routing, and Docker administration.
Manage Kubernetes applications safely by creating and updating Cyclops Modules for AI agents.
Behavioral trust scoring for MCP servers and AI agents. Live registry tracking 4,500+ servers with trust scores based on interaction history, success rates, and latency.
A server for Kubernetes CLI tools like kubectl, istioctl, helm, and argocd, supporting multi-cluster management via dynamic kubeconfig.
An MCP server for kubectl, enabling AI assistants to interact with Kubernetes clusters through a standardized protocol.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



