
FlorianBruniaux/claude-code-ultimate-guide6.1kclaude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Security

This repository contains Model Context Protocol (MCP) servers that enable MCP clients (like Claude Desktop or the cline.bot VS Code extension) to access Google's security products and services:
For the new Remote MCP Server, please see the launch announcement and the setup guide.
Each server can be enabled and run separately, allowing flexibility for environments that don't require all capabilities.
Comprehensive documentation is available in the docs folder. You can:
The documentation covers:
To get started with the documentation, see docs/index.md.
The server uses Google's authentication. Make sure you have either:
gcloud auth application-default loginEach MCP server can be installed and used as a standalone package.
You can install the packages using uv tool install (recommended):
# Install packages
uv tool install google-secops-mcp
uv tool install gti-mcp
uv tool install scc-mcp
uv tool install secops-soar-mcp
Alternatively, you can use pip:
pip install google-secops-mcp
pip install gti-mcp
pip install scc-mcp
pip install secops-soar-mcp
After installation, you can run the servers directly using uvx:
# Run SecOps MCP server
uvx --from google-secops-mcp secops_mcp
# Run GTI MCP server
uvx gti_mcp
# Run SCC MCP server
uvx scc_mcp
# Run SecOps SOAR MCP server (with optional integrations)
uvx secops_soar_mcp --integrations CSV,OKTA
With environment variables:
CHRONICLE_PROJECT_ID="your-project-id" \
CHRONICLE_CUSTOMER_ID="01234567-abcd-4321-1234-0123456789ab" \
CHRONICLE_REGION="us" \
uvx secops_mcp
You can configure MCP clients to use the installed packages with uvx. Here's an example configuration:
{
"mcpServers": {
"secops": {
"command": "uvx",
"args": [
"--from",
"google-secops-mcp",
"secops_mcp"
],
"env": {
"CHRONICLE_PROJECT_ID": "your-project-id",
"CHRONICLE_CUSTOMER_ID": "01234567-abcd-4321-1234-0123456789ab",
"CHRONICLE_REGION": "us"
}
},
"gti": {
"command": "uvx",
"args": [
"gti_mcp"
],
"env": {
"VT_APIKEY": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"
}
},
"scc-mcp": {
"command": "uvx",
"args": [
"scc_mcp"
],
"env": {}
},
"secops-soar": {
"command": "uvx",
"args": [
"secops_soar_mcp",
"--integrations",
"CSV,OKTA"
],
"env": {
"SOAR_URL": "https://yours-here.siemplify-soar.com:443",
"SOAR_APP_KEY": "01234567-abcd-4321-1234-0123456789ab"
}
}
}
}
You can also use environment files with uvx:
{
"mcpServers": {
"secops": {
"command": "uvx",
"args": [
"--env-file",
"/path/to/.env",
"secops_mcp"
]
}
}
}
The MCP servers from this repo can be used with the following clients
The configuration for Claude Desktop and Cline is the same (provided below for uv and pip). We use the stdio transport.
The repository includes a prebuilt Autonomous Security Operations Center (SOC) Agent powered by Google ADK v2 and the Model Context Protocol in run-with-google-adk.
It can be run locally via an interactive CLI REPL or launched as a FastAPI service for Google Cloud Run:
cd run-with-google-adk
cp .env.example .env
# Interactive terminal investigation REPL
uv run mcp-security-agent chat
# Web UI and Cloud Run REST API server
uv run mcp-security-agent serve --port 8080
For full setup, architecture details, and Cloud Run deployment guides, see the ADK Agent Guide.
MCP clients all use the same JSON configuration format (see the MCP Server Configuration Reference), but they expect the file in different locations.
| Client Application | Scope | macOS / Linux Location | Windows Location | Notes |
|---|---|---|---|---|
| Gemini CLI | Global | ~/.gemini/settings.json | %USERPROFILE%\.gemini\settings.json | File must include mcpServers. Confirmed in Google Security Ops post. |
| Claude Desktop | Global | ~/Claude/claude_desktop_config.json | %USERPROFILE%\Claude\claude_desktop_config.json | Config accessible via Claude > Settings > Developer > Edit Config. |
| Claude Code | Global | ~/.claude.json | %USERPROFILE%\.claude.json | Primary config file for Claude Code CLI and extensions. |
| Cursor IDE (Global) | Global | ~/.cursor/mcp.json | %USERPROFILE%\.cursor\mcp.json | Enables MCP servers globally across all projects. |
| Cursor IDE (Project) | Project | <project-root>/.cursor/mcp.json | <project-root>/.cursor/mcp.json | Workspace/project-specific config file. |
| VS Code (Workspace) | Workspace | <project-root>/.vscode/mcp.json | <project-root>/.vscode/mcp.json | Workspace-level config used when an MCP extension (like Cline) is installed. Overrides global config if present. |
| Cline (VS Code Ext.) | Global | Inside VS Code extension data | %APPDATA%\Code\User\globalStorage\<extension-id>\settings\cline_mcp_settings.json | Exact path varies by VS Code variant and platform. <extension-id> corresponds to the installed extension folder (e.g., saoudrizwan.claude-dev). |
%USERPROFILE% → C:\Users\<username>%APPDATA% → C:\Users\<username>\AppData\Roaming<project-root> → folder opened in VS Code or IDE for the project<extension-id> → name of the installed extension folder (e.g., saoudrizwan.claude-dev for Claude/Cline)If you use multiple MCP clients, you can maintain a single config file and symlink it into each expected location. This avoids drift and keeps your server definitions consistent.
{
"mcpServers": {
"secops": {
"command": "uv",
"args": [
"--directory",
"/path/to/the/repo/server/secops/secops_mcp",
"run",
"server.py"
],
"env": {
"CHRONICLE_PROJECT_ID": "your-project-id",
"CHRONICLE_CUSTOMER_ID": "01234567-abcd-4321-1234-0123456789ab",
"CHRONICLE_REGION": "us"
}
},
"secops-soar": {
"command": "uv",
"args": [
"--directory",
"/path/to/the/repo/server/secops-soar/secops_soar_mcp",
"run",
"server.py",
"--integrations",
"CSV,OKTA"
],
"env": {
"SOAR_URL": "https://yours-here.siemplify-soar.com:443",
"SOAR_APP_KEY": "01234567-abcd-4321-1234-0123456789ab"
}
},
"gti": {
"command": "uv",
"args": [
"--directory",
"/path/to/the/repo/server/gti/gti_mcp",
"run",
"server.py"
],
"env": {
"VT_APIKEY": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"
}
},
"scc-mcp": {
"command": "uv",
"args": [
"--directory",
"/path/to/the/repo/server/scc",
"run",
"scc_mcp.py"
],
"env": {
}
}
}
}
NOTE: uv also supports passing an .env file like so:
"command": "uv",
"args": [
"--directory",
"/path/to/the/repo/server/...",
"run",
"--env-file",
"/path/to/the/repo/server/.env",
"server.py"
]
SOAR_APP_KEY and VT_APIKEY are good candidates for .env
You can also use pip instead of uv to install and run the MCP servers. This approach uses a bash command to:
{
"mcpServers": {
"secops": {
"command": "/bin/bash",
"args": [
"-c",
"cd /path/to/the/repo/server/secops && pip install -e . && secops_mcp"
],
"env": {
"CHRONICLE_PROJECT_ID": "your-project-id",
"CHRONICLE_CUSTOMER_ID": "01234567-abcd-4321-1234-0123456789ab",
"CHRONICLE_REGION": "us"
},
"alwaysAllow": [
]
},
"gti": {
"command": "/bin/bash",
"args": [
"-c",
"cd /path/to/the/repo/server/gti && pip install -e . && gti_mcp"
],
"env": {
"VT_APIKEY": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"
},
"alwaysAllow": [
]
},
"scc-mcp": {
"command": "/bin/bash",
"args": [
"-c",
"cd /path/to/the/repo/server/scc && pip install -e . && scc_mcp"
],
"env": {
},
"alwaysAllow": []
},
"secops-soar": {
"timeout": 60,
"command": "/bin/bash",
"args": [
"-c",
"cd /path/to/the/repo/server/secops-soar && pip install -e . && python secops_soar_mcp/server.py"
],
"env": {
"SOAR_URL": "https://yours-here.siemplify-soar.com:443",
"SOAR_APP_KEY": "01234567-abcd-4321-1234-0123456789ab"
},
"transportType": "stdio"
}
}
}
UV_ENV_FILEThe --env-file option allows uv to use a .env file for environment variables. You can create this file or use system environment variables as described in the usage guide.
Alternatively, you can set UV_ENV_FILE to your .env file and omit the --env-file portion of the configuration.
Refer to the usage guide for detailed instructions on how to set up these environment variables.
Running the MCP Server from the CLI (and outside of your MCP client) can reveal issues:
uv --verbose \
--directory "/Users/dandye/Projects/google-mcp-security/server/scc" \
run \
--env-file "/Users/dandye/Projects/google-mcp-security/.env" \
scc_mcp.py
Check your PATH(s):
which uv # you may need to restart MCP Client after installing uv
which python || which python3
python --version || python3 --version
To use the MCP servers with Claude Desktop:
claude_desktop_config.json with the configuration (replace paths with your actual paths)cline_mcp_settings.json with the configuration (replace paths with your actual paths)Apache 2.0

FlorianBruniaux/claude-code-ultimate-guide6.1kThe most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Security

duty1g/x64dbg-mcp-server2.4kx64dbg-MCP Server is a native MCP (Model Context Protocol) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Connect any MCP-compatible AI assistant and control x64dbg programmatically: set breakpoints, step through code, read memory, dump registers, and more. Built with Zig — zero dependencies, single-binary output, cros
Security

beenuar/AiSOC2.4kOpen-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue.
Security

OpenOSINT/OpenOSINT1.7kAI-powered OSINT agent with interactive REPL, MCP server, and CLI. 20 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
Security

mukul975/cve-mcp-server1.6kProduction-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
Security

2akouwu/reverify1.3kStop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.
Security