MCP server for Blackpoint Cyber MDR — alerts, threats, and operations.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"io-github-wyre-technology-blackpoint-mcp": {
"command": "<see-readme>",
"args": []
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
MCP server for Blackpoint Cyber MDR — alerts, threats, and operations.
No automated test available for this server. Check the GitHub README for setup instructions.
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
No package registry to scan.
This server is missing a description. Tools and install config are also missing.If you've used it, help the community.
Add informationBe the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in security
An evil MCP server used for redteam testing
Proof primitive for AI agents on MultiversX. Anchor file hashes on-chain as verifiable proofs.
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
mcpki-server is the backend infrastructure for https://www.mcpki.org, enabling secure public key management and autonomous certificate handling for large language models (LLMs).
MCP Security Weekly
Get CVE alerts and security updates for io.github.wyre-technology/blackpoint-mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
Model Context Protocol (MCP) server for Blackpoint Cyber CompassOne - Managed Detection and Response (MDR) platform.
This MCP server provides access to CompassOne's security capabilities through a decision-tree navigation interface:
The server uses decision-tree navigation to organize tools:
blackpoint_navigate, blackpoint_status)blackpoint_back to return to navigationAll tools follow the pattern: blackpoint_{domain}_{action}
Examples:
blackpoint_assets_list - List assets by classblackpoint_detections_list - List security detectionsblackpoint_vulnerabilities_scans_list - List vulnerability scansnpm install blackpoint-mcp
| Variable | Description | Required |
|---|---|---|
BLACKPOINT_API_TOKEN | CompassOne API token | Yes |
BLACKPOINT_BASE_URL | API base URL (may vary by region/partner) | No |
MCP_TRANSPORT | Transport mode: stdio or http | No (default: stdio) |
MCP_HTTP_PORT | HTTP port for gateway mode | No (default: 8080) |
AUTH_MODE | Set to gateway for header-based auth | No |
LOG_LEVEL | Logging level: debug, info, warn, error | No (default: info) |
When AUTH_MODE=gateway, the server reads credentials from HTTP headers:
X-Blackpoint-API-Token → BLACKPOINT_API_TOKENThis enables per-request authentication for multi-tenant gateways.
# Set credentials
export BLACKPOINT_API_TOKEN="your-api-token"
# Run the server
blackpoint-mcp
export AUTH_MODE=gateway
export MCP_TRANSPORT=http
export MCP_HTTP_PORT=8080
blackpoint-mcp
// Start by checking available domains
await tools.call("blackpoint_status");
// Navigate to assets domain
await tools.call("blackpoint_navigate", { domain: "assets" });
// List endpoint assets
await tools.call("blackpoint_assets_list", {
class: "endpoint",
pageSize: 10
});
// Get specific asset details
await tools.call("blackpoint_assets_get", {
id: "asset_12345"
});
// Return to navigation
await tools.call("blackpoint_back");
| Domain | Tools | Description |
|---|---|---|
| tenants | list, get | Customer tenant management |
| assets | list, get, relationships, search | Asset inventory and relationships |
| detections | list, get | Security detections and telemetry |
| vulnerabilities | list, scans_list, darkweb_list, external_list | Vuln management, dark web, external exposure |
| Domain | Status | Notes |
|---|---|---|
| partners | SDK ready | Account management - ready to implement |
| alerts | Models only | API handlers not available in CompassOne wrapper |
| tickets | Models only | API handlers not available in CompassOne wrapper |
| cloud_security | SDK ready | M365/Google/Cisco onboarding - ready to implement |
| notifications | SDK ready | Contact groups and channels - ready to implement |
CompassOne uses hierarchical scoping: Partner → Tenants → Assets
tenantId parameters to avoid c