truss-agent-mcp

truss-agent-mcp

An MCP server that provides Truss threat intelligence capabilities, enabling natural language search, FilterQL filtering, and querying of threat data, along with STIX export and detection rule generation.

Category
访问服务器

README

truss-agent-mcp

Truss threat intelligence via Model Context Protocol and a terminal assistant — one binary: truss-mcp.

Two surfaces

Surface Use for Auth
Remote (recommended) Cursor, Claude Desktop, MCP registries OAuth → https://api.truss-security.com/mcp
Local stdio (legacy) Air-gap / BYO-key / FilterQL REPL tools TRUSS_API_KEY → REST

Hosted MCP (OAuth, Growth+ gate, five tools) is served by the Truss API. This package ships configs, validate-remote / doctor --remote, CLI search, and optional local stdio. Community accounts cannot consent to hosted MCP.

Not on npm yet. Install from this repo (npm install -g .). After publish: npm install -g @truss-security/truss-agent-mcp.

Quick start

cd truss-agent-mcp
npm install && npm run build
npm install -g .
truss-mcp doctor --remote --strict-oauth   # OAuth path hosts use
truss-mcp init                            # for CLI search / legacy stdio
truss-mcp search

Node.js 18+. Binary name truss-mcp avoids conflict with @truss-security/truss-sdk's truss command.

What you can run

Command What it does
truss-mcp search Guided REPL with live MCP tools (local stdio or remote OAuth token)
truss-mcp mcp Local stdio MCP server (legacy / air-gap)
truss-mcp init Interactive .env setup
truss-mcp doctor Validate keys and API access; --remote runs hosted OAuth doctor
truss-mcp validate-remote <url> OAuth + MCP doctor (discovery, DCR, PKCE, tools)
truss-mcp help Usage summary

Guided search workflow

One REPL with MCP tools always connected. The assistant classifies your intent and asks before querying Truss API:

  1. Knowledge — Truss platform, cyber security context, threat background
  2. Build filter — draft FilterQL, validate, confirm
  3. Query — run executes confirmed filter (default 7 days)
  4. Format — stix for STIX export; JSON summaries in-thread
  5. Detection rules — detect splunk, detect falcon, detect cortex from search results

The assistant offers next steps explicitly: build a filter, refine it, query Truss API, export JSON/STIX, or generate SIEM/EDR hunting queries.

  • Wider windows (run 30, days 30) may use more API quota
  • Context-only follow-ups (IOC dedupe, reformat) use thread history without re-querying

Full REPL reference: guides/truss-cli.md

Terminal display (REPL)

truss-mcp search uses color-coded, ASCII-bordered output:

  • You — your message
  • MCP — live tool trace (→ search_threats on remote, or → search_products on stdio)
  • Results — structured product table before the assistant summary
  • Truss — assistant reply (cyan), guided offers (yellow), FilterQL blocks (magenta)

Controls: color / color on / color off / color auto · env TRUSS_MCP_COLOR · standard NO_COLOR=1

MCP host (Cursor / Claude) — remote OAuth (recommended)

No API key in host config. Growth+ Truss account; browser OAuth consent.

{
  "mcpServers": {
    "truss-mcp": {
      "url": "https://api.truss-security.com/mcp"
    }
  }
}

Samples: config/cursor.mcp.json · config/claude_desktop_config.json · guides/client-setup-cursor.md.

Legacy stdio (air-gap)

{
  "mcpServers": {
    "truss-mcp": {
      "command": "truss-mcp",
      "args": ["mcp"],
      "env": { "TRUSS_API_KEY": "YOUR_KEY" }
    }
  }
}

See config/cursor.mcp.stdio.json and guides/getting-started.md.

Remote MCP OAuth validation (registry gate)

Use as the OAuth + MCP doctor before registry publish or release. After OAuth it requires search_threats to return at least one Truss product (id + title). The access token stays in memory for that process only unless you pass --save-token.

truss-mcp doctor --remote --strict-oauth
# or:
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth

After token exchange it prints an OAuth compatibility checklist (resource URI, redirects, PKCE S256, issuer match, audience vs MCP resource, truss_role), then proves MCP access with real Truss data.

Options:

truss-mcp validate-remote https://api.truss-security.com/mcp --verbose
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth
truss-mcp validate-remote https://api.truss-security.com/mcp --save-token /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --token-file /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --port 9877
truss-mcp validate-remote https://api.truss-security.com/mcp --no-open
  • --verbose — HTTP statuses, key headers, truncated bodies (tokens redacted)
  • --strict-oauth — exit 2 if the OAuth checklist has WARN/FAIL (even when Truss MCP calls succeed)
  • --save-token PATH — write the access token for local replay (mode 0600; delete after debugging)
  • --token-file PATH — skip browser OAuth; reuse a saved token to re-check MCP access + Truss data

Optional automated OAuth data tests (saved token + TRUSS_RUN_MCP_OAUTH=1) are documented in guides/publishing.md.

Official listing: server.json (com.truss-security/truss-mcp) · Tracker: guides/registry-submission.md · Internal metadata: config/mcp-registry.json · Architecture: docs/05-hosted-mcp-oauth-architecture.md

Configuration

Env load order (shell vars win): ~/.config/truss/env → ~/.truss/.env → ./.env

Variable Required for Notes
TRUSS_API_KEY local mcp / stdio search From Truss dashboard (legacy air-gap only)
TRUSS_MCP_URL remote search / doctor Default https://api.truss-security.com/mcp
TRUSS_MCP_OAUTH_TOKEN_FILE remote search Bearer token from validate-remote --save-token
LLM_PROVIDER search anthropic or openai — set via init
LLM_MODEL search Set via init
ANTHROPIC_API_KEY / OPENAI_API_KEY search Per provider

Full list: env.example

Documentation

Guides — install, REPL, MCP clients, FilterQL examples

Reference — API contract, tools, architecture (docs/README.md — docs 01–06)

Development

npm install && npm run build
npm test
npm run truss:search    # from source without global install

Contributors / AI agents: see AGENTS.md for repo operations and conventions.

Publish: guides/publishing.md · Changes: CHANGELOG.md

Related

MIT

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选