Skip to main content
Glama
Sentinel-One

Purple AI MCP Server

Official
by Sentinel-One

Related Servers

Alternatives to Purple AI MCP Server

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      D
      maintenance
      Enables read-only access to SentinelOne's platform through MCP, allowing security investigations, threat hunting, and asset inventory queries via natural language.
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables interaction with SentinelOne's security platform, including Purple AI, events, alerts, vulnerabilities, and asset inventory, through MCP.
      MIT
    • F
      license
      Not graded
      quality
      C
      maintenance
      Enables interaction with the AccuKnox cloud security platform through MCP, allowing users to query cloud assets, vulnerabilities, and perform security analysis via natural language or API.
      1
      -
    • F
      license
      A
      quality
      B
      maintenance
      Exposes eSentire Atlas API (Findings, Ticketing, MVS) and Threat Intelligence feeds (IP Watch, Advanced/STIX) as MCP tools, enabling security operations and threat intelligence queries through natural language.
      29
      -

    TDQS

    B3.4/5.0

    Scored across 33 tools

    Disambiguation3/5

    Most tools are clearly separated by list/search/get patterns per domain, and the purple_ai vs powerquery distinction is carefully documented. However, several boundaries are fuzzy: get_vulnerability vs cve_search_by_id, threat_intel_by_hash vs threat_intel_get_file_behavior/relationships, and list_inventory_items vs search_inventory_items overlap in ways that could cause misselection.

    Naming Consistency3/5

    Resource tools mostly follow a consistent get_/ list_/ search_ pattern, and threat_intel_/ cve_ prefixes impose some order. But core tools purple_ai and powerquery are bare nouns, timestamp helpers use two different styles (get_timestamp_range vs iso_to_unix_timestamp), and threat_intel_get_file_* deviates from the by_* pattern.

    Tool Count2/5

    33 tools is well into the too-many range for most MCP servers, even for a broad security domain. Several near-duplicate list/search variants and repeated notes/history triples across alerts, misconfigurations, and vulnerabilities suggest the surface could be consolidated.

    Completeness3/5

    The read-side surface is strong: every finding type has get/list/search plus notes and history, and threat intel + CVE search are well covered. However, there are no write/action tools (update alert status, assign, add notes, remediate), so investigation workflows hit dead ends and the server is effectively read-only for security operations.

    Maintenance

    ActivityMaintained
    ResponsivenessNo issues