mcpserver.lol
registry/aribot-mcp
Connection check verified live · 20h ago

aribot-mcp

Threat modeling, code, API & cloud security, shadow-AI & compliance governance.

Tools 16
GitHub stars
Installs / wk
Licence
Transport streamable-http, sse
Last checked 20h ago

Tools & capabilities

16 tools

Read from the running server on 20h ago.

apply_remediation can modify data rule_id*threat_id*resource_context
Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy re…
code_review_scan scan_id*
Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceabil…
compliance_scan sourcescan_type*account_iddiagram_idframeworksseverity_filter +1
Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.
compliance_status read-only scan_iddiagram_id
Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceability company rollup.
discover_shadow_ai limitscan_id
Shadow-AI posture (part of Code Security): unsanctioned / unknown AI-service usage discovered in code — totals, risk score, provider/type breakdown, hardcoded-key count, and top di…
generate_threat_model nameedgesnodes*
Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns…
get_api_security limitscan_id
API security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Company-wide or one s…
get_billing request_plantopup_amountcheckout_request_id
Billing status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasable plans, and any app…
get_cloud_compliance account_id
Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a…
get_diagram_summary read-only diagram_id*
The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.
get_framework_coverage read-only frameworkdiagram_id*include_graph
Compliance-framework coverage for a diagram (real, ControlCodeMap-backed), optionally for one framework, plus an optional crossmap relationship graph. Wraps derive_framework_covera…
get_insights read-only diagram_id*
Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.
get_remediation read-only rule_id*threat_id*resource_context
Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the…
get_traceability read-only scan_id*
Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.
onboard_agents agentscohortagent_cardsauto_suspend_threshold
Bulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cards` (name/url/prov…
verify_threats_in_code read-only async_scan_id*threat_idcode_contentrepository_id
Verify whether threats are mitigated in a scan's uploaded code. With `threat_id`, verifies one threat synchronously and returns the verdict; without it, verifies every diagram thre…