Skip to main content
Glama
WYRE-AI

rocketcyber-mcp

by WYRE-AI

rocketcyber-mcp

MCP (Model Context Protocol) server for the RocketCyber Managed SOC platform. Provides read-only access to RocketCyber security data through 10 tools and 3 resources.

Features

  • 10 read-only tools covering all RocketCyber API resources

  • 3 MCP resources for quick data access

  • Dual transport: stdio (default) and HTTP Streamable

  • Lazy SDK initialization on first tool call

  • Winston logger with all output routed to stderr

  • Connection test tool for validating credentials

Related MCP server: action1-mcp

One-Click Deployment

IMPORTANT

Before you click: this server depends on @wyre-technology/node-rocketcyber, which is hosted on the GitHub Packages npm registry. GitHub Packages has no anonymous access — even though the package is public, every npm install needs a token. The cloud builder runs npm install for you, so you must give it one, or the build fails with npm error 401 Unauthorized ... npm.pkg.github.com.

  1. Create a GitHub Personal Access Token with the read:packages scope (classic token). Any GitHub account works — you do not need to be a member of the wyre-technology org to read its public packages.

  2. Add it as a build variable when prompted by the deploy flow:

    • Cloudflare Workers → set a build variable named NODE_AUTH_TOKEN to your PAT (Workers → Settings → Build → Variables and Secrets).

    • DigitalOcean App Platform → set an encrypted env var named GITHUB_TOKEN with scope Build Time to your PAT (the Dockerfile reads it for the install).

Deploy to DO

Deploy to Cloudflare Workers

Installation

This project depends on @wyre-technology/node-rocketcyber, published to the GitHub Packages npm registry, which requires a token even for public packages. Authenticate once, then install:

# Authenticate npm to GitHub Packages (token needs the read:packages scope)
export NODE_AUTH_TOKEN=$(gh auth token)   # or a PAT with read:packages

npm install
npm run build

The repo's .npmrc already points the @wyre-technology scope at GitHub Packages and reads the token from NODE_AUTH_TOKEN, so no further config is needed.

Configuration

Environment Variable

Required

Default

Description

ROCKETCYBER_API_KEY

Yes

-

RocketCyber API key

ROCKETCYBER_REGION

No

us

API region: us or eu

MCP_TRANSPORT

No

stdio

Transport type: stdio or http

MCP_HTTP_PORT

No

8080

HTTP port (when using http transport)

MCP_HTTP_HOST

No

0.0.0.0

HTTP host (when using http transport)

LOG_LEVEL

No

info

Log level: error, warn, info, debug

LOG_FORMAT

No

simple

Log format: json or simple

Usage

Claude Desktop (stdio)

Add to your Claude Desktop configuration (claude_desktop_config.json):

{
  "mcpServers": {
    "rocketcyber": {
      "command": "node",
      "args": ["/path/to/rocketcyber-mcp/dist/entry.js"],
      "env": {
        "ROCKETCYBER_API_KEY": "your-api-key"
      }
    }
  }
}

HTTP Transport

ROCKETCYBER_API_KEY=your-api-key MCP_TRANSPORT=http npm start

Tools

Tool

Description

rocketcyber_test_connection

Test the connection to RocketCyber API

rocketcyber_get_account

Get account information

rocketcyber_list_agents

List monitored agents/endpoints

rocketcyber_list_incidents

List security incidents

rocketcyber_list_events

List security events

rocketcyber_get_event_summary

Get event summary/statistics

rocketcyber_list_firewalls

List firewall devices

rocketcyber_list_apps

List managed apps

rocketcyber_get_defender

Get Windows Defender status

rocketcyber_get_office

Get Office 365 status

Resources

URI

Description

rocketcyber://account

Account information

rocketcyber://incidents

Security incidents

rocketcyber://agents

Monitored agents/endpoints

Development

# Install dependencies
npm install

# Run in development mode
npm run dev

# Build
npm run build

# Start production server
npm start

License

Apache-2.0

Related MCP Connectors

  • MCP server for querying and analyzing data from ad platforms, analytics tools, and spreadsheets

  • Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.

  • The CustomGPT.ai MCP server is a fully managed, RAG-powered endpoint that connects large language models with private knowledge bases and external data sources. It provides tools for retrieval-augmented generation queries (send_message), data ingestion (upload_file), and source listing, enabling AI agents to query private documents like PDFs with high accuracy and real-time citations.

  • The HubSpot MCP Server acts as a bridge that enables AI assistants and Large Language Models to securely interact with HubSpot CRM data through natural conversation, without requiring users to understand complex API structures. It provides read-only access to standard CRM objects (contacts, companies, deals, tickets, products, invoices, and more) and their associations, secured via OAuth 2.0, allowing AI agents to perform tasks like summarizing deals, fetching company updates, and looking up record changes.

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that provides secure, read-only access to the TrakSYS manufacturing analytics platform through entity-based tools and guided investigation prompts. It enables users to interact with manufacturing databases and perform data analysis via natural language.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server for Action1, a cloud-native RMM platform, enabling remote monitoring, patch management, and endpoint management through Action1's API.
    6
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    An MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.
    Apache 2.0
  • F
    license
    Not graded
    quality
    B
    maintenance
    MCP server that exposes Acronis Cyber Protect Cloud APIs as 14 read-only tools for managing alerts, tasks, agents, resources, policies, and tenants.
    -