← Back to search

@konsulto/mcp

konsulto Scanned 22d ago

Konsulto MCP server — drive the Konsulto cybersecurity audit platform from MCP-capable clients (Claude Code, etc.)

C
70.2 / 100

Versions

0.4.0latest
Jun 29, 2026
0.3.0
Jun 28, 2026
0.2.0
May 12, 2026
0.1.4
May 8, 2026
0.1.3
May 8, 2026
+ show 3 moreshow less
0.1.2
May 8, 2026
0.1.1
May 8, 2026
0.1.0
May 8, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 22

konsulto_whoami
annotations: none low

Show who the MCP is acting as, their permissions, the active audit, and

konsulto_list_my_audits
annotations: none low

List audits to find the audit ID you want to work in. By default (scope

limit number
konsulto_set_active_audit
annotations: none low

Pin one audit as the session\

audit string
konsulto_get_audit_context
annotations: none low

One-shot orientation tool — returns the active audit\

audit string
konsulto_audit_summary
annotations: none low

Aggregate finding counts for an audit: total, breakdown by severity

audit string
konsulto_search_templates
annotations: none low

Search the finding-template catalog. Returns a slim shape (id, title,

q string limit number
konsulto_search_findings
annotations: none low

Search findings within an audit. Defaults to the active audit when set.

q string audit string limit number
konsulto_get_finding
annotations: none low

Read a single finding by ID, including its body rendered as markdown

findingId string
konsulto_read_section
annotations: none low

Read just one section of a finding\

section string findingId string
konsulto_compose_finding
annotations: none low

Create a brand-new finding with a fully-formatted body. Author each

audit string title string impact string caption string summary string evidenceId string remediation string
konsulto_get_finding_format
annotations: none low

Return the section structure + markdown authoring rules for composing a

audit string layoutId string
konsulto_list_finding_statuses
annotations: none low

List this tenant\

konsulto_update_finding
annotations: none low

Update scalar fields on an existing finding. Use this for changing

title string status string taxonomy any findingId string
konsulto_bulk_update_status
annotations: none low

Change the status of many findings at once. Use for

dryRun boolean status string
konsulto_attach_evidence
annotations: none low

Upload a file (or inline content) as an attachment in the active audit.

audit string
konsulto_add_evidence_to_finding
annotations: none low

Graft an already-uploaded attachment into an existing finding\

caption string findingId string evidenceId string
konsulto_append_to_section
annotations: none low

Append markdown prose to a named section of a finding. Use this to add

content string section string findingId string
konsulto_replace_section
annotations: none low

Replace the entire prose under a named section. The previous content

content string section string findingId string
konsulto_list_scope
annotations: none low

List the scope elements for an audit — what\

audit string
konsulto_list_assets
annotations: none low

List assets in the audit (or tenant-wide if no audit filter). Returns

q string audit string limit number
konsulto_create_asset
annotations: none low

Create a new asset in the active audit. Use when a scan or evidence

ip string url string cidr string name string audit string hostname string description string cloudResourceId string
konsulto_link_asset
annotations: none low

Attach an asset to a finding. Tries to match an existing asset by name

findingId string

Permissions 2

network medium
Server uses network capabilities via: axios
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 85

low
Tool 'konsulto_whoami' has no annotations annotation_checker · 100%
low
Tool 'konsulto_list_my_audits' has no annotations annotation_checker · 100%
low
Tool 'konsulto_set_active_audit' has no annotations annotation_checker · 100%
low
Tool 'konsulto_get_audit_context' has no annotations annotation_checker · 100%
low
Tool 'konsulto_audit_summary' has no annotations annotation_checker · 100%
low
Tool 'konsulto_search_templates' has no annotations annotation_checker · 100%
low
Tool 'konsulto_search_findings' has no annotations annotation_checker · 100%
low
Tool 'konsulto_get_finding' has no annotations annotation_checker · 100%
low
Tool 'konsulto_read_section' has no annotations annotation_checker · 100%
low
Tool 'konsulto_compose_finding' has no annotations annotation_checker · 100%
low
Tool 'konsulto_get_finding_format' has no annotations annotation_checker · 100%
low
Tool 'konsulto_list_finding_statuses' has no annotations annotation_checker · 100%
low
Tool 'konsulto_update_finding' has no annotations annotation_checker · 100%
low
Tool 'konsulto_bulk_update_status' has no annotations annotation_checker · 100%
low
Tool 'konsulto_attach_evidence' has no annotations annotation_checker · 100%
low
Tool 'konsulto_add_evidence_to_finding' has no annotations annotation_checker · 100%
low
Tool 'konsulto_append_to_section' has no annotations annotation_checker · 100%
low
Tool 'konsulto_replace_section' has no annotations annotation_checker · 100%
low
Tool 'konsulto_list_scope' has no annotations annotation_checker · 100%
low
Tool 'konsulto_list_assets' has no annotations annotation_checker · 100%
low
Tool 'konsulto_create_asset' has no annotations annotation_checker · 100%
low
Tool 'konsulto_link_asset' has no annotations annotation_checker · 100%
medium
OAuth implementation without PKCE auth_checker · 75%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.0.4 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-35jp-ww65-95wh) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-3g43-6gmg-66jw) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-3p68-rc4w-qgx5) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-3w6x-2g7m-8v23) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-42h9-826w-cgv3) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-43fc-jf86-j433) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-445q-vr5w-6q77) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-5c9x-8gcm-mpgx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-62hf-57xw-28j9) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-6chq-wfr3-2hj9) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-777c-7fjr-54vf) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-7q8q-rj6j-mhjq) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-898c-q2cr-xwhg) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-fvcv-3m26-pcqx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-hfxv-24rg-xrqf) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-j5f8-grm9-p9fc) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-jqh4-m9w3-8hp9) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-m7pr-hjqh-92cm) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-mmx7-hfxf-jppx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-p92q-9vqr-4j8v) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-pf86-5x62-jrwf) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-pmv8-rq9r-6j72) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-pmwg-cvhr-8vh7) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-q8qp-cvcw-x6jj) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-vf2m-468p-8v99) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-w9j2-pvgh-6h63) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-xhjh-pmcv-23jw) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.12.2 (GHSA-xx6v-rp6x-q39c) dependency_analyzer · 95%
medium
Vulnerable dependency: yaml@2.6.1 (GHSA-48c2-rrv3-qjmp) dependency_analyzer · 95%
medium
Buffer.from base64 in konsulto-konsulto-mcp-eb6b6f6/src/server.ts:754 entropy_analyzer · 75%
info
package.json metadata manifest_parser · 100%
info
Tool: konsulto_whoami manifest_parser · 70%
info
Tool: konsulto_list_my_audits manifest_parser · 70%
info
Tool: konsulto_set_active_audit manifest_parser · 70%
info
Tool: konsulto_get_audit_context manifest_parser · 70%
info
Tool: konsulto_audit_summary manifest_parser · 70%
info
Tool: konsulto_search_templates manifest_parser · 70%
info
Tool: konsulto_search_findings manifest_parser · 70%
info
Tool: konsulto_get_finding manifest_parser · 70%
info
Tool: konsulto_read_section manifest_parser · 70%
info
Tool: konsulto_compose_finding manifest_parser · 70%
info
Tool: konsulto_get_finding_format manifest_parser · 70%
info
Tool: konsulto_list_finding_statuses manifest_parser · 70%
info
Tool: konsulto_update_finding manifest_parser · 70%
info
Tool: konsulto_bulk_update_status manifest_parser · 70%
info
Tool: konsulto_attach_evidence manifest_parser · 70%
info
Tool: konsulto_add_evidence_to_finding manifest_parser · 70%
info
Tool: konsulto_append_to_section manifest_parser · 70%
info
Tool: konsulto_replace_section manifest_parser · 70%
info
Tool: konsulto_list_scope manifest_parser · 70%
info
Tool: konsulto_list_assets manifest_parser · 70%
info
Tool: konsulto_create_asset manifest_parser · 70%
info
Tool: konsulto_link_asset manifest_parser · 70%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (4) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 173 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%