truss-agent-mcp
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@truss-agent-mcpsearch for recent phishing campaigns and export indicators as STIX"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
truss-agent-mcp
Truss threat intelligence via Model Context Protocol and a terminal assistant — one binary: truss-mcp.
Two surfaces
Surface | Use for | Auth |
Remote (recommended) | Cursor, Claude Desktop, MCP registries | |
Local stdio (legacy) | Air-gap / BYO-key / FilterQL REPL tools |
|
Hosted MCP (OAuth, Growth+ gate, five tools) is served by the Truss API. This package ships configs, validate-remote / doctor --remote, CLI search, and optional local stdio. Community accounts cannot consent to hosted MCP.
Not on npm yet. Install from this repo (
npm install -g .). After publish:npm install -g @truss-security/truss-agent-mcp.
Related MCP server: misp-mcp
Quick start
cd truss-agent-mcp
npm install && npm run build
npm install -g .
truss-mcp doctor --remote --strict-oauth # OAuth path hosts use
truss-mcp init # for CLI search / legacy stdio
truss-mcp searchNode.js 18+. Binary name truss-mcp avoids conflict with @truss-security/truss-sdk's truss command.
What you can run
Command | What it does |
| Guided REPL with live MCP tools (local stdio or remote OAuth token) |
| Local stdio MCP server (legacy / air-gap) |
| Interactive |
| Validate keys and API access; |
| OAuth + MCP doctor (discovery, DCR, PKCE, tools) |
| Usage summary |
Guided search workflow
One REPL with MCP tools always connected. The assistant classifies your intent and asks before querying Truss API:
Knowledge — Truss platform, cyber security context, threat background
Build filter — draft FilterQL, validate, confirm
Query —
runexecutes confirmed filter (default 7 days)Format —
stixfor STIX export; JSON summaries in-threadDetection rules —
detect splunk,detect falcon,detect cortexfrom search results
The assistant offers next steps explicitly: build a filter, refine it, query Truss API, export JSON/STIX, or generate SIEM/EDR hunting queries.
Wider windows (
run 30,days 30) may use more API quotaContext-only follow-ups (IOC dedupe, reformat) use thread history without re-querying
Full REPL reference: guides/truss-cli.md
Terminal display (REPL)
truss-mcp search uses color-coded, ASCII-bordered output:
You — your message
MCP — live tool trace (
→ search_threatson remote, or→ search_productson stdio)Results — structured product table before the assistant summary
Truss — assistant reply (cyan), guided offers (yellow), FilterQL blocks (magenta)
Controls: color / color on / color off / color auto · env TRUSS_MCP_COLOR · standard NO_COLOR=1
MCP host (Cursor / Claude) — remote OAuth (recommended)
No API key in host config. Growth+ Truss account; browser OAuth consent.
{
"mcpServers": {
"truss-mcp": {
"url": "https://api.truss-security.com/mcp"
}
}
}Samples: config/cursor.mcp.json · config/claude_desktop_config.json · guides/client-setup-cursor.md.
Legacy stdio (air-gap)
{
"mcpServers": {
"truss-mcp": {
"command": "truss-mcp",
"args": ["mcp"],
"env": { "TRUSS_API_KEY": "YOUR_KEY" }
}
}
}See config/cursor.mcp.stdio.json and guides/getting-started.md.
Remote MCP OAuth validation (registry gate)
Use as the OAuth + MCP doctor before registry publish or release. After OAuth it requires search_threats to return at least one Truss product (id + title). The access token stays in memory for that process only unless you pass --save-token.
truss-mcp doctor --remote --strict-oauth
# or:
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauthAfter token exchange it prints an OAuth compatibility checklist (resource URI, redirects, PKCE S256, issuer match, audience vs MCP resource, truss_role), then proves MCP access with real Truss data.
Options:
truss-mcp validate-remote https://api.truss-security.com/mcp --verbose
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth
truss-mcp validate-remote https://api.truss-security.com/mcp --save-token /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --token-file /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --port 9877
truss-mcp validate-remote https://api.truss-security.com/mcp --no-open--verbose— HTTP statuses, key headers, truncated bodies (tokens redacted)--strict-oauth— exit2if the OAuth checklist has WARN/FAIL (even when Truss MCP calls succeed)--save-token PATH— write the access token for local replay (mode0600; delete after debugging)--token-file PATH— skip browser OAuth; reuse a saved token to re-check MCP access + Truss data
Optional automated OAuth data tests (saved token + TRUSS_RUN_MCP_OAUTH=1) are documented in guides/publishing.md.
Official listing: server.json (com.truss-security/truss-mcp) · Tracker: guides/registry-submission.md · Internal metadata: config/mcp-registry.json · Architecture: docs/05-hosted-mcp-oauth-architecture.md
Configuration
Env load order (shell vars win): ~/.config/truss/env → ~/.truss/.env → ./.env
Variable | Required for | Notes |
| local | From Truss dashboard (legacy air-gap only) |
| remote | Default |
| remote | Bearer token from |
| search |
|
| search | Set via |
| search | Per provider |
Full list: env.example
Documentation
Guides — install, REPL, MCP clients, FilterQL examples
Reference — API contract, tools, architecture (docs/README.md — docs 01–06)
Development
npm install && npm run build
npm test
npm run truss:search # from source without global installContributors / AI agents: see AGENTS.md for repo operations and conventions.
Publish: guides/publishing.md · Changes: CHANGELOG.md
Related
@truss-security/truss-sdk — API client
truss-agent — scheduled webhook delivery
Truss docs — public API / SDK documentation
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceAn MCP server that integrates ThreatBook's threat intelligence API, offering 15 specialized tools for security analysis. It enables AI models to perform IP reputation checks, domain investigations, file sandbox analysis, and vulnerability intelligence lookups.Last updated47MIT
- AlicenseAqualityBmaintenanceAn MCP server that enables LLMs to interact with MISP for threat intelligence sharing, IOC lookups, and event management. It provides tools for investigating indicators, discovering correlations, and exporting intelligence in formats like STIX and Suricata.Last updated36572MIT
- Alicense-qualityDmaintenanceAn MCP server that provides 294 malware analysis tools behind an AI-driven interface, enabling natural language investigation of binaries.Last updated37MIT
- Flicense-qualityDmaintenanceA behavioral threat hunting MCP server that focuses on adversary TTPs rather than atomic indicators, with MITRE ATT\&CK integration, advanced cognitive capabilities, and community hunt hypotheses.Last updated17
Related MCP Connectors
Official Microsoft MCP Server to query Microsoft Entra data using natural language
MCP server for AI access to SmartBear tools, including BugSnag, Reflect, Swagger, PactFlow, QTM4J.
MCP server providing access to the Scorecard API to evaluate and optimize LLM systems.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/truss-security/truss-agent-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server