csw-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CSW_API_KEY | Yes | API key (hex) from CSW UI → API Keys | |
| CSW_API_URL | Yes | Cluster base URL, no trailing slash | |
| CSW_MCP_ENV | No | Explicit path to an alternate env file | |
| CSW_API_SECRET | Yes | HMAC signing secret paired with the key | |
| CSW_VERIFY_SSL | No | Set `false` only behind a TLS-inspecting proxy | |
| CSW_POV_TEMPLATE | No | Path to a CSW_POV_Template checkout (enables snapshot/report resources) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_scopesA | List the CSW scopes (the hierarchy that organizes workloads and policy). Returns a count and the raw scope records from |
| list_sensorsA | List the agents/sensors registered on the cluster (summarized). Each entry includes uuid, hostname, agent_type (ENFORCER / VISIBILITY / …),
platform, and the host's IPs. |
| search_inventoryA | Search cluster inventory for workloads matching a field/value filter. Args: value: The value to match (e.g. an IP, hostname fragment, OS string). field: The inventory dimension to filter on (default "ip"). Common fields: "ip", "hostname", "os", "user_annotations". match: CSW filter operator — "eq" (exact), "contains", "subnet", etc. Defaults to "eq". limit: Max results to return (1–1000). Runs a read-only |
| get_workloadA | Fetch the inventory record for a single workload by IP address. Looks up the workload via a read-only inventory search for the exact IP. Returns the full record if found, or a graceful not-found message. Use this to inspect one host's annotations, scopes, and attributes. |
| summarize_cluster_postureA | Summarize the cluster's security posture at a glance. Returns headline KPIs for a security-leadership audience: total agents, how many are enforcing policy vs. visibility-only, the enforcement coverage percentage, and a breakdown of agents by type. This is the fastest way to gauge blast-radius exposure. |
| list_workspacesA | List application workspaces (policy folders / ADM scopes). Returns the workspaces from |
| get_workspace_policiesA | List the policies defined in a workspace. Args:
app_id: The workspace/application id (from Returns the policy records from
|
| list_policies_for_workloadA | List the policies that currently apply to a single workload. Args:
uuid: The workload/sensor UUID (from Returns the policies from |
| search_flowsA | Search network flows over a recent time window. Args: filter_json: A CSW flow filter as a JSON string, e.g. '{"type":"eq","field":"dst_port","value":3389}'. Pass an empty string for no filter (all flows in the window). hours: Look-back window in hours (1–720, default 24). limit: Max flow records to return (1–1000). Runs a read-only |
| get_conversationsA | List ADM conversations (observed talker pairs) for a workspace. Args:
app_id: The workspace/application id (from Reads |
| top_risky_flowsA | Rank risky-service exposure by counting recent flows to sensitive ports. Scans the last Args: hours: Look-back window in hours (1–720, default 24). limit: Max flow samples to inspect per port (1–1000). |
| get_workload_cvesA | List CVEs / vulnerabilities detected on a single workload. Args:
uuid: The workload/sensor UUID (from Returns records from |
| get_workload_packagesA | List installed software packages on a single workload. Args:
uuid: The workload/sensor UUID (from Returns records from |
| top_vulnerable_hostsA | Rank the most vulnerable hosts in the cluster by CVE severity. Iterates sensors, pulls each host's vulnerabilities, and scores them as
(critical * 10 + high). Returns the top Args: limit: Number of top hosts to return (1–1000). |
| list_forensic_profilesB | List configured forensic profiles (behavioral rule sets for agents). Returns records from |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| csw/triage-blast-radius | Guided workflow to assess and shrink a cluster's blast radius. |
| csw/weekly-posture-review | Monday-standup posture review, diffing against last week's snapshot. |
| csw/pov-closeout | Draft a full proof-of-value closeout narrative + next-30-days plan. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| cluster_info | Basic identity + reachability info for the configured cluster. Reports the configured cluster URL, whether credentials are present, and — if reachable — quick counts of scopes and agents. Safe to read first to confirm the server is wired up correctly. |
| scopes_resource | The cluster scope hierarchy (cached for ~60s). Same data as the `list_scopes` tool, exposed as a resource for clients that prefer to attach it as context. Cached briefly to avoid re-querying on every read. |
| latest_snapshot | The most recent cluster snapshot JSON, if one is available locally. Reads the newest `snapshots/snapshot-*.json` under $CSW_POV_TEMPLATE (set the env var to point at your generic template checkout). Returns a not-found message if no snapshot or template directory is configured. |
| latest_executive_report | The most recent executive-summary markdown report, if available locally. Reads the newest `reports/executive-summary-*.md` under $CSW_POV_TEMPLATE. Returns a short not-found message when nothing is available. |
TDQS
Scored across 15 tools
Each tool targets a distinct resource or action, with clear separation between inventory, policy, flow, and vulnerability queries. Minor overlap exists between get_workload and search_inventory for single-host lookup, and between list_scopes and list_workspaces as hierarchical grouping concepts, but descriptions clarify their boundaries.
All tool names use snake_case and generally follow a verb_noun pattern (list_, get_, search_, summarize_). The ranking tools top_risky_flows and top_vulnerable_hosts deviate slightly with a top_ prefix, but remain readable and consistent with each other.
Fifteen tools is within the well-scoped range and each covers a distinct facet of the CSW domain: inventory, sensors, scopes, policies, flows, vulnerabilities, and forensic profiles. No tool appears redundant or unnecessary for the breadth of surface presented.
The surface is entirely read-only, offering broad coverage for analysis and posture assessment but no create/update/delete operations for policies, workspaces, scopes, sensors, or forensic profiles. This is a notable lifecycle gap that will prevent agents from performing management actions through this MCP.