server_audit
Audit server security with 457 checks across 30 categories. Get a compliance score (0-100), quick wins, and filter by framework or severity.
Instructions
Run a security audit on a server. Scans 30 categories with 457 checks. Returns score (0-100), per-category scores, and quick wins. Formats: 'summary' (compact text), 'json' (full AuditResult), 'score' (number only). Supports compliance filtering (cis-level1, cis-level2, pci-dss, hipaa), category/severity filtering, snapshot save/compare, threshold gate, and profile filtering. Requires SSH access. For health trends use server_doctor instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| server | No | Server name or IP. Auto-selected if only one server exists. | |
| format | No | Output format: summary (default), json (full result), score (number only) | summary |
| framework | No | Compliance framework filter. Returns per-control pass/fail summary alongside audit results. | |
| explain | No | When true, include why + fix explanation for each failing check in summary format output. Capped at 10 checks. | |
| category | No | Filter results to a specific category (e.g. 'SSH', 'Firewall', 'Docker'). | |
| severity | No | Filter checks by severity level. | |
| snapshot | No | Save audit snapshot. true for auto-name, string for custom name. | |
| compare | No | Compare two snapshots: format before:after (e.g. pre-upgrade:latest) | |
| threshold | No | Minimum passing score (1-100). Returns error if score is below threshold. | |
| profile | No | Server profile filter (web-server, database, mail-server). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |