Skip to main content
Glama
WYRE-AI

Cork MCP Server

Official
by WYRE-AI

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
AUTH_MODENo`env` (default, reads the var above) or `gateway` (credential arrives per-request via the `X-Cork-Api-Key` header, injected by the Conduit gateway).env
LOG_LEVELNo`debug` | `info` (default) | `warn` | `error`.info
CORK_API_KEYNoBearer API key issued by Cork's Admin UI.
MCP_TRANSPORTNo`stdio` (default) or `http`.stdio
CONDUIT_S2S_SECRETNoWhen set, the HTTP transport requires a valid `X-Gateway-S2S` header (Conduit sidecar auth) on every `/mcp` request.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{}
logging
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
cork_get_clientsA

List clients with their financial protection status (warranty_status), associated integration tenants, and the 10 most recent Cork Cyber Scores (newest first). For older scores or a bounded date range, use cork_get_client_score_history. Client UUIDs from this response are required by cork_get_client_devices, cork_get_client_inboxes, cork_get_client_domains, cork_get_compliance_events, and the vulnerability tools. If the API user is a distributor, pass partner_uuid to scope results to a specific partner.

cork_get_client_devicesA

List devices observed for a client across all connected integrations - hostnames, IP addresses, the integration each device was seen in, whether the device can receive a future install dispatch (can_install_software), normalized OS details, resolved device type, and hardware model. Device UUIDs can be used to filter cork_get_software_vulnerabilities. Requires a client UUID from cork_get_clients.

cork_get_client_domainsA

List email domains observed for a client. Domain UUIDs can be used to filter cork_get_compliance_events. Requires a client UUID from cork_get_clients.

cork_get_client_inboxesA

List email inboxes (users and shared mailboxes) observed for a client, with inbox type, associated domains, and the integration each inbox was sourced from. Requires a client UUID from cork_get_clients.

cork_get_client_score_historyA

List a client's full Cork Cyber Score history, newest first, with the risk points each category (coverage, compliance, vulnerabilities, claims) deducted from that score. Use created_after/created_before to bound a period (both inclusive) for trend reporting - cork_get_clients only carries the 10 most recent scores. Requires a client UUID from cork_get_clients.

cork_get_compliance_eventsA

List policy violations and risk events detected for a client's assets. Filter by event_type (use cork_get_compliance_event_types for valid values), device, inbox, or domain UUID. Use at_risk=true to show only currently active risks. Resolved events are excluded by default; set show_resolved=true to include them.

cork_get_compliance_notification_settingsC

List the notification and alerting rules configured for compliance events on a client's assets - which event types trigger alerts and how they are routed.

cork_get_compliance_event_typesA

List all compliance event types with their descriptions and cure periods. Use to discover valid event_type values before filtering cork_get_compliance_events.

cork_get_software_vulnerabilitiesA

List individual software vulnerabilities with full CVE details including CVSS score, EPSS score, KEV (known exploited) status, and impacted version. Filter by minimum_cvss_score, minimum_epss_score, minimum_priority, or only_known_exploited=true to focus on the highest-risk findings. Scope by client_uuid or device_uuid.

cork_get_software_vulnerability_summaryA

Get a rollup of CVEs grouped by software product, showing number of impacted devices, impacted versions, and highest severity rating. Use client_uuid to scope to a single client. Follow up with cork_get_software_vulnerabilities to drill into specific CVEs for a product.

cork_get_available_integrationsA

List integration types that can be connected to Cork, including required credential fields. Metadata about what CAN be connected, not what IS connected - see cork_get_connected_integrations for that.

cork_get_connected_integrationsA

List integrations connected to Cork - vendor, connection status, and sync details. RMM integrations also carry an installer block describing whether software installs can run through them (capable, requires_manual_setup, authorized, configured_package_managers). Use with cork_get_client_devices to see which integration a device is mapped through. Discovers integration UUIDs needed by cork_get_integration_devices, cork_get_integration_users, and cork_get_integration_tenants.

cork_get_integration_devicesB

List devices observed from an integration - hostnames, IP addresses, device properties, and normalized OS details for devices that have been mapped.

cork_get_integration_tenantsB

List customer tenants observed from an integration.

cork_get_integration_usersB

List users observed from an integration.

cork_get_warrantiesB

List active cyber warranty packages. To identify which clients lack coverage, check the warranty_status field in cork_get_clients results - clients with 'unwarranted' status have no active warranty.

cork_get_invoicesA

List billing invoices. Returns invoice UUIDs required by cork_get_invoice_line_items. If the API user is a distributor, pass partner_uuid to scope results to a specific partner.

cork_get_invoice_line_itemsA

List billed, top-level line items for an invoice (obtained via cork_get_invoices). Only items with a nonzero total billed are returned; discount line items are included and carry a negative total_billed. Sub-items billed as part of a parent line item (e.g. individual licenses within a bundle) are nested under that item's children field, and always carry a total_billed of 0 since their amount is rolled into the parent.

cork_get_partnersA

List partner sub-accounts managed by this distributor. Returns partner UUIDs that can be passed as partner_uuid to cork_get_clients and other tools to scope results to a specific partner. Distributor accounts only.

cork_get_installer_historyA

List past software install attempts (most recent first) with dispatch state, target client/device, package, and any errors. Filter by client_uuid or device_uuid. state is one of queued, running, success, partial, error - 'success' means the RMM accepted the job, not that the on-device install finished.

cork_get_software_packagesA

List software packages available to install across supported package managers (WinGet, Chocolatey). Filter by package_manager_key or search (substring match against name/publisher). Returns package_id values that would be used by a future install dispatch - this connector does not implement software install itself.

cork_get_installer_setupA

Get the one-time setup steps for an RMM vendor that requires manual setup before software installs work - the script to create in the RMM, its exact name, settings to match, and variables to declare. Use when a connected integration shows installer.requires_manual_setup=true (and the package manager is missing from installer.configured_package_managers).

cork_who_am_iA

Get information on the authenticated Cork user (identity, role, and partner/distributor scope). Useful for a quick credential sanity check.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 23 tools

Disambiguation4/5

Each tool maps to a distinct resource or sub-resource, and descriptions consistently call out the required parent UUIDs (client, integration, invoice) that scope related queries. The only real near-overlap is cork_get_client_devices vs. cork_get_integration_devices, but their client-scoped vs. integration-scoped purposes are clearly explained.

Naming Consistency4/5

22 of 23 tools follow the same cork_get_<resource> snake_case pattern, making the naming highly predictable. cork_who_am_i is the single outlier and breaks the verb_noun convention, but it is still recognizable and not confusing.

Tool Count3/5

With 23 tools, this server sits at the heavy end of what an agent can comfortably scan. The breadth is defensible because the domain covers clients, compliance, vulnerabilities, integrations, billing, and installers, but several of these areas could have been consolidated.

Completeness4/5

The read-only surface is well connected: client UUIDs feed devices, inboxes, domains, and compliance; integration UUIDs feed integration subresources; and invoice UUIDs feed line items. Minor gaps exist, such as no claims endpoint despite the score history referencing claims, and no action-oriented tools like software install dispatch, but core query workflows are covered.

Maintenance

ActivityMaintained
ResponsivenessNo issues