RAD Security
OfficialThe RAD Security MCP Server provides AI-powered security insights and management for Kubernetes and cloud environments.
Core Capabilities:
Container Security: List and search containers with filtering, analyze process trees and runtime behavior, get runtime baselines, and perform LLM-powered analysis of container behavior
Kubernetes Management: List clusters and resources (pods, deployments, services, etc.), inspect resource manifests, and detect misconfigurations with policy listings
Identity & Access Management: List identities (service accounts, users, groups) across clusters, get identity details, and audit pod shell access logs
Cloud Security: Inventory cloud resources across AWS, GCP, Azure, and Linode with compliance monitoring and filtering by type, account, and status
Image Security: List container images, retrieve SBOMs, analyze vulnerabilities filtered by severity, and identify top vulnerable images
Network Security: Monitor HTTP requests with PII detection, track network connections between workloads, and analyze connection patterns
Threat Detection: List and analyze threat vectors with filtering by namespace, cluster, resource, severity, type, and status
Security Findings Management: List findings (misconfigurations, threats, runtime alerts, audit anomalies) and update their status (open, closed, ignored)
CVE Database: Search CVEs by vendor/product, view detailed CVE information, list vendors and products, and access the latest 30 CVEs with CAPEC, CWE, and CPE expansions
Inbox Management: List inbox items with flexible filtering, get item details, and mark items as false positives with reasons
Customization: Filter toolkits using INCLUDE_TOOLKITS or EXCLUDE_TOOLKITS environment variables across 15 toolkit categories, with multiple deployment options (npm, Docker with Streamable HTTP or SSE).
Note: Authentication with RAD_SECURITY credentials is required for most operations, except CVE database access and misconfiguration policy listing.
Enables runtime security analysis of containers, including process behavior monitoring, baselines, and container inventory management.
Provides security insights for Kubernetes environments, including cluster inventory, container details, Kubernetes resource monitoring, and identifying security vulnerabilities in Kubernetes objects.
Required runtime environment for the MCP server, with version 20.x or higher needed for operation.
Used for package installation and management of the MCP server.
Provides audit capabilities to track and monitor shell access to pods.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@RAD Securityshow me the latest security findings for my production cluster"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
RAD Security MCP Server
A Model Context Protocol (MCP) server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments.
Connect (hosted — recommended)
RAD Security runs the MCP server for you, so most users don't need to install or host anything. Point your MCP client at the hosted endpoint and authenticate with your RAD Security credentials.
Endpoint:
https://api.rad.security/mcp/— note the trailing slash.Transport: Streamable HTTP.
Authentication: send your credential in the
Authorizationheader:Authorization: Bearer <access_key_id>:<secret_key>:<account_id><access_key_id>and<secret_key>are a RAD Security API access key (create one in the RAD Security console);<account_id>is your account ID. The server authenticates every request against the RAD Security API — no credentials are stored server-side.
A short-lived form
Bearer ory_st_<session_token>:<account_id>also works, but session tokens expire — prefer an access key for anything long-lived (e.g. Slack / Claude Tag).
Claude Code
claude mcp add --transport http rad-security https://api.rad.security/mcp/ \
--header "Authorization: Bearer <access_key_id>:<secret_key>:<account_id>"OpenAI Codex CLI
~/.codex/config.toml:
[mcp_servers.rad-security]
url = "https://api.rad.security/mcp/"
http_headers = { "Authorization" = "Bearer <access_key_id>:<secret_key>:<account_id>" }Or via the CLI, keeping the secret in an env var (export RAD_MCP_TOKEN=<access_key_id>:<secret_key>:<account_id>):
codex mcp add rad-security --url https://api.rad.security/mcp/ --bearer-token-env-var RAD_MCP_TOKENCursor
.cursor/mcp.json:
{
"mcpServers": {
"rad-security": {
"type": "http",
"url": "https://api.rad.security/mcp/",
"headers": {
"Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>"
}
}
}
}VS Code (GitHub Copilot)
.vscode/mcp.json — note the wrapper key is servers, not mcpServers:
{
"servers": {
"rad-security": {
"type": "http",
"url": "https://api.rad.security/mcp/",
"headers": {
"Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>"
}
}
}
}Gemini CLI
~/.gemini/settings.json — note the URL field is httpUrl (not url):
{
"mcpServers": {
"rad-security": {
"httpUrl": "https://api.rad.security/mcp/",
"headers": {
"Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>"
}
}
}
}Cline
cline_mcp_settings.json — note type must be exactly streamableHttp (camelCase):
{
"mcpServers": {
"rad-security": {
"type": "streamableHttp",
"url": "https://api.rad.security/mcp/",
"headers": {
"Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>"
}
}
}
}Windsurf
~/.codeium/windsurf/mcp_config.json — note the URL field is serverUrl:
{
"mcpServers": {
"rad-security": {
"serverUrl": "https://api.rad.security/mcp/",
"headers": {
"Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>"
}
}
}
}Other clients
Most MCP clients accept a remote Streamable HTTP server with a URL and an Authorization header — only the field names differ. Keep the trailing slash on the URL in every case.
Client | Config location | URL field | Transport marker | Header field |
Claude Code |
| positional arg |
|
|
OpenAI Codex CLI |
|
| inferred |
|
Cursor |
|
|
|
|
VS Code |
|
|
|
|
Gemini CLI |
|
| inferred |
|
Cline |
|
|
|
|
Windsurf |
|
| inferred |
|
Claude.ai / Claude Desktop / Claude Tag (Slack)
These surfaces add remote MCP servers as connectors, which use their own credential settings rather than a raw request header. Add https://api.rad.security/mcp/ as a custom connector, then supply the bearer credential through the connector's settings:
Claude Tag (Slack): attach the server as a plugin whose
.mcp.jsonpoints at the endpoint, and add the bearer credential on the Access bundle's Credentials tab. See Claude Tag — connect a custom MCP server.Claude.ai / Desktop: add it under Settings → Connectors; see custom connectors.
Test it (MCP Inspector or curl)
npx @modelcontextprotocol/inspector
# Transport: Streamable HTTP
# URL: https://api.rad.security/mcp/ (trailing slash)
# Custom headers: { "Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>" }curl -H "authorization: Bearer <access_key_id>:<secret_key>:<account_id>" \
-H "content-type: application/json" \
-H "accept: application/json, text/event-stream" \
-X POST https://api.rad.security/mcp/ \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"curl","version":"1"}}}'Scoping the tools an agent sees
By default a connection gets every toolkit. To give an agent a smaller set — less context/token overhead, and least privilege — add a scoping header to that connection alongside Authorization. The subset is enforced: an out-of-scope tool is hidden from tools/list and rejected if called.
Header | Effect |
| only these toolkits |
| every toolkit except these |
| only read-only tools (drops the write tools) |
Toolkits: containers, clusters, audit, images, kubeobject, runtime, findings, inbox, workflows, knowledge_base, radql, dashboards, integrations (plus custom_workflows, off by default).
Example — a read-only findings/images agent (any client that supports headers; Cursor shown):
{
"mcpServers": {
"rad-security-findings": {
"type": "http",
"url": "https://api.rad.security/mcp/",
"headers": {
"Authorization": "Bearer <access_key_id>:<secret_key>:<account_id>",
"X-Rad-Toolkits": "findings, images",
"X-Rad-Readonly": "true"
}
}
}
}In Claude Code, pass an extra --header:
claude mcp add --transport http rad-security https://api.rad.security/mcp/ \
--header "Authorization: Bearer <access_key_id>:<secret_key>:<account_id>" \
--header "X-Rad-Toolkits: findings, images"Related MCP server: CVE MCP Server
Features
All tools require authentication and an account in RAD Security. The hosted endpoint exposes every toolkit below except custom_workflows (workflow authoring), which is off by default.
Account Inventory
List clusters and their details
Containers Inventory
List containers and their details
Security Findings
List and analyze security findings
Update the status of a security finding
Runtime Security
Get process trees of running containers
Get runtime baselines of running containers
Analyze process behavior of running containers
Audit
List who shelled into a pod
Images and Vulnerabilities
Get SBOMs
List images and their vulnerabilities
Get top vulnerable images
Ignore / unignore CVEs and list active CVE dispositions
Kubernetes Objects
Get details of a specific Kubernetes resource
List Kubernetes resources
Inbox
List inbox items and their details
Mark an inbox item as a false positive
Workflows
List workflows, runs and schedules
Get workflow and workflow run details
Run a workflow
Create and update custom workflows and schedules (via
custom_workflows, disabled by default)
Knowledge Base
Search the knowledge base
List collections and documents
Run structured queries against a document
Dashboards
List dashboards and get their details
List and get dashboard and widget templates
Integrations
List external integrations
RadQL (Advanced Querying)
List available data types for querying (containers, findings, kubernetes_resources, etc.)
Get schema/metadata for specific data types
List possible values for filter fields
Execute RadQL queries with filtering, searching, and aggregations
Build queries programmatically from structured conditions
Execute multiple queries in parallel
Self-hosting
Prefer to run the server yourself — for example an air-gapped environment, data-residency requirements, or if you don't want to route through the hosted gateway? It's published to npm and as a container image.
Prerequisites
Node.js 20.x or higher
Credentials
Provide your RAD Security credentials via environment variables:
RAD_SECURITY_ACCESS_KEY_ID="your_access_key"
RAD_SECURITY_SECRET_KEY="your_secret_key"
RAD_SECURITY_ACCOUNT_ID="your_account_id"
# Optional: fetched automatically from the account if not set
RAD_SECURITY_TENANT_ID="your_tenant_id"npx (stdio) — e.g. Claude Desktop
{
"mcpServers": {
"rad-security": {
"command": "npx",
"args": ["-y", "@rad-security/mcp-server"],
"env": {
"RAD_SECURITY_ACCESS_KEY_ID": "<your-access-key-id>",
"RAD_SECURITY_SECRET_KEY": "<your-secret-key>",
"RAD_SECURITY_ACCOUNT_ID": "<your-account-id>"
}
}
}
}Docker (Streamable HTTP)
docker build -t rad-security/mcp-server .
docker run \
-e TRANSPORT_TYPE=streamable \
-e RAD_SECURITY_ACCESS_KEY_ID=your_access_key \
-e RAD_SECURITY_SECRET_KEY=your_secret_key \
-e RAD_SECURITY_ACCOUNT_ID=your_account_id \
-p 3000:3000 \
rad-security/mcp-serverToolkit filtering
Control which toolkits a self-hosted server exposes:
INCLUDE_TOOLKITS: comma-separated list of toolkits to include (only these are enabled).EXCLUDE_TOOLKITS: comma-separated list of toolkits to exclude (all others are enabled). Ignored ifINCLUDE_TOOLKITSis set.
Available toolkits: containers, clusters, audit, images, kubeobject, runtime, findings, inbox, workflows, custom_workflows (disabled by default), knowledge_base, radql, dashboards, integrations.
# Only the workflows toolkit
INCLUDE_TOOLKITS="workflows"
# Everything except runtime
EXCLUDE_TOOLKITS="runtime"Multi-tenant (per-request auth)
MCP_AUTH_MODE controls how a streamable HTTP deployment authenticates inbound requests — this is what the hosted endpoint uses:
MCP_AUTH_MODE=env(default) — every session uses theRAD_SECURITY_*environment credentials. Single-tenant, and unauthenticated at the HTTP layer, so it must not be reachable from untrusted networks.MCP_AUTH_MODE=header— every request must carry its own credential in theAuthorizationheader (theBearer <access_key_id>:<secret_key>:<account_id>form above); a missing or malformed header is rejected with401. Only supported withTRANSPORT_TYPE=streamable.RAD_SECURITY_API_URLis taken from server config, not the caller.
docker run \
-e TRANSPORT_TYPE=streamable \
-e MCP_AUTH_MODE=header \
-e RAD_SECURITY_API_URL=https://api.rad.security \
-p 3000:3000 \
rad-security/mcp-serverThe SSE transport (
TRANSPORT_TYPE=sse) is deprecated in favor of Streamable HTTP and uses env credentials only.
Development
# Install dependencies
npm install
# Run type checking
npm run type-check
# Run linter
npm run lint
# Build
npm run buildLicense
MIT License - see the LICENSE file for details
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/rad-security/mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server