Gives Claude direct access to the WinstonRedGuard security platform's 60+ tools without leaving the agent context. You get secret scanning via devguard_scan, ransomware lookups, Sigma rule generation from AI code patterns, OSINT username probes across 3000+ sites via Maigret, and a full threat intel stack with MITRE ATT&CK mappings. Runs over stdio for Claude Desktop and Cursor. Core install works standalone with local tools and research APIs; full feature set needs the WRG monorepo. Reach for this if you're doing detection engineering, incident response, or secure-by-default workflows where you want the agent to scan for leaked credentials or query threat actor infrastructure inline.
WRG_REPO_ROOT*Absolute path to the WinstonRedGuard monorepo checkout. Required when the package is installed outside the repo (the server auto-detects when run from inside the repo).
WRG_MCP_ALLOW_MUTATIONSdefault: 0Set to '1' to permit state-changing tools (memory_set, pipeline_run). Default '0' = read-only.
WRG_SITE_BASE_URLBase URL of the optional company-site API (enables site_* tools). Requires the `[remote]` extra.
WRG_SITE_TOKENsecretBearer token for the company-site API.
WRG_PULSEBOARD_BASE_URLBase URL of the optional PulseBoard dashboard API (enables pulseboard_* tools). Requires the `[remote]` extra.
WRG_PULSEBOARD_TOKENsecretBearer token for the PulseBoard API.
io.github.ericm1018/skillfm-llm-cost-optimizer-openai-anthropic-usage
io.github.mikerawsonnz/llm-orchestration-agent
io.github.mikerawsonnz/authenticated-llm-agent
labforgedev/copilot-memory-mcp
csoai-org/agent-prompt-injection-firewall-mcp
io.github.mikerawsonnz/authenticated-multi-llm-agent