healthsec-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CONNECTOR_DATA_ROOT | No | Override the location of the data directory (default is ../data/ relative to the package). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| run_fgsmB | Run a LIME-guided FGSM adversarial attack against a registered model. |
| run_boundary_attackA | Run an iterative decision-boundary attack against a registered model. |
| run_membership_inferenceA | Run a shadow-model membership-inference attack against a registered model. |
| assess_attack_coverageA | Score MITRE ATT&CK-style threat-coverage from per-control test results. |
| check_rbacA | Score RBAC enforcement from already-executed endpoint/role probes. |
| score_audit_completenessA | Score audit-log completeness for non-repudiation. |
| score_complianceA | Score a HIPAA/FHIR compliance checklist. |
| compute_spsB | Compose the Security Posture Score from four dimension inputs. |
| generate_security_reportA | Compose a structured security report from whichever tool outputs you have. |
| get_audit_logA | Return this session's audit trail. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Each tool has a clearly distinct purpose targeting different security assessment areas (attack types, scoring, compliance, audit, reporting). There is no overlap that would confuse an agent.
All tool names follow a consistent snake_case verb_noun pattern (e.g., run_fgsm, score_compliance). The naming is descriptive and predictable.
With 10 tools covering adversarial attacks, scoring, compliance, audit, and reporting, the count is well-scoped for its domain. Each tool earns its place without being excessive.
The tool surface covers core security assessment workflows (attacks, scoring, reports) but lacks explicit model registration tools; models are assumed pre-registered, which is a minor gap.