mcpbeat Sign in

Security Recipes MCP Server

by stevologic Your server? Claim it
answering

Security Recipes is answering right now. Last checked 5 min ago. It exposes 75 tools. Last commit 17 Sep 2026.

Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.

Uptime history 23 days of history · worst day 66%
23 days agonow
100.0%
Uptime 24h
92 of 92 checks
75
Tools
read from the server
685 ms
Response time
average over 24h
1
Stars
last commit 17 Sep 2026

What the code does

We read the source, 19 h ago · tools taken from the live server · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

Builds a file path from a variable lib/homepage-metrics.js:36
    return JSON.parse(fs.readFileSync(path.join(ROOT, relativePath), "utf8"));
Reads files and sends them to the network actions/security-health/main.mjs:8
import { appendFileSync, readFileSync, readdirSync, statSync } from 'node:fs';

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 5 min ago.

run in your terminal
claude mcp add security-recipes --transport http https://security-recipes.ai/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "security-recipes": {
      "url": "https://security-recipes.ai/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.security-recipes]
url = "https://security-recipes.ai/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "security-recipes": {
      "url": "https://security-recipes.ai/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "security-recipes": {
      "url": "https://security-recipes.ai/mcp"
    }
  }
}

Available tools 75

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

recipes
recipes_a2a_agent_card_trust_profile
Return A2A Agent Card intake profiles, trust controls, and sample decisions.
recipes_agent_capability_risk_register
Return capability-based residual risk scores for agentic workflows.
recipes_agent_handoff_boundary_pack
Return agent handoff boundary profiles, protocol controls, and workflow maps.
recipes_agent_identity_ledger
Return agent non-human identity, delegation, scope, and audit contracts.
recipes_agent_memory_boundary_pack
Return agent memory classes, workflow profiles, TTLs, and persistence decisions.
recipes_agent_skill_supply_chain_pack
Return agent skill provenance, permission, isolation, and supply-chain decisions.
recipes_agent_trust_fabric_pack
Return Agent Trust Fabric dimensions, workflow tiers, source evidence, and buyer proof.
recipes_agentic_action_runtime_pack
Return action classes, workflow action envelopes, runtime policy, and evidence.
recipes_agentic_aivss_risk_scoring_pack
Return AIVSS-aligned agentic risk scores, SLAs, evidence, and hosted MCP wedges.
recipes_agentic_app_intake_pack
Return generated agentic app launch-review profiles and decisions.
recipes_agentic_approval_receipt_pack
Return scope-bound approval receipt profiles, workflow requirements, and evidence.
recipes_agentic_assurance_pack
Return enterprise assurance controls, workflow evidence, and AI/Agent BOM seed.
recipes_agentic_catastrophic_risk_annex
Return the severe-risk annex for high-impact agentic AI runtime decisions.
recipes_agentic_control_plane_blueprint
Return the acquisition-ready agentic control plane architecture and buyer evidence map.
recipes_agentic_entitlement_review_pack
Return expiring agent entitlement leases, access reviews, and scope evidence.
recipes_agentic_exposure_graph
Return risk-ranked agentic exposure paths across context, identities, MCP tools, and evidence.
recipes_agentic_incident_response_pack
Return agentic incident response classes, phases, workflow matrix, and evidence.
recipes_agentic_measurement_probe_pack
Return measurement probes for agentic workflow traceability and readiness.
recipes_agentic_posture_snapshot
Return the generated enterprise posture snapshot for agentic AI and MCP operations.
recipes_agentic_protocol_conformance_pack
Return MCP/A2A protocol conformance evidence and buyer-ready drift controls.
recipes_agentic_readiness_scorecard
Return generated scale, pilot, gate, or block decisions for agentic workflows.
recipes_agentic_red_team_drill_pack
Return adversarial drills for agentic remediation workflows and MCP controls.
recipes_agentic_red_team_replay_harness
Return replay fixtures, expected decisions, and evidence gates for red-team drills.
recipes_agentic_run_receipt_pack
Return agent run receipt templates for identity, context, tools, egress, approval, and evidence.
recipes_agentic_soc_detection_pack
Return SIEM-ready detections for agentic AI and MCP telemetry.
recipes_agentic_source_freshness_watch
Return source-freshness and standards-drift evidence for SecurityRecipes.
recipes_agentic_standards_crosswalk
Return standards-to-evidence mappings for agentic AI, MCP, and prompt-injection guidance.
recipes_agentic_system_bom
Return the Agentic System BOM for workflows, agents, identities, MCP tools, and evidence.
recipes_agentic_telemetry_contract
Return the OpenTelemetry-aligned agentic telemetry and redaction contract.
recipes_agentic_threat_radar
Return current source-backed agentic AI threat signals and product priorities.
recipes_browser_agent_boundary_pack
Return browser-agent workspace classes, task profiles, controls, and evidence.
recipes_context_egress_boundary_pack
Return context egress data classes, destination classes, and workflow boundary policy.
recipes_context_poisoning_guard_pack
Return context-poisoning scan results for registered secure-context sources.
recipes_critical_infrastructure_secure_context_pack
Return the generated critical-infrastructure secure-context profile.
recipes_cve_catalog_info
Return the complete Medium/High/Critical CVE catalog scope, coverage, provenance, and counts.
recipes_cve_get
Get evidence, recipe authority, and a bounded code/config/file change plan for one exact CVE.
recipes_cve_search
Search every in-scope Medium/High/Critical CVE; use recipes_cve_get for complete details.
recipes_design_partner_pilot_pack
Return the design partner pilot motion for buyer proof and hosted MCP validation.
recipes_enterprise_trust_center_export
Return the bundled enterprise trust-center export for buyer and platform diligence.
recipes_get
Get a full recipe record by slug or path.
recipes_hosted_mcp_readiness_pack
Return the hosted MCP readiness plan for enterprise product rollout.
recipes_list
List recipes with optional metadata filtering.
recipes_match_finding
Heuristic matcher that suggests best-fit recipes for a security finding.
recipes_mcp_authorization_conformance_pack
Return MCP authorization conformance, scope-drift, and token-boundary evidence.
recipes_mcp_connector_intake_pack
Return MCP connector intake decisions, risk findings, gaps, and promotion plans.
recipes_mcp_connector_trust_pack
Return MCP connector trust tiers, controls, evidence, and workflow namespace coverage.
recipes_mcp_elicitation_boundary_pack
Return MCP form-mode and URL-mode elicitation boundary evidence.
recipes_mcp_gateway_policy
Return generated MCP gateway policy for scoped tool access and runtime controls.
recipes_mcp_risk_coverage_pack
Return OWASP MCP and agentic-skill risk coverage mapped to generated evidence.
recipes_mcp_server_get
Return one publicly documented MCP server with official setup and safety guidance.
recipes_mcp_servers_list
Search the bundled catalog of publicly documented MCP servers and ecosystems.
recipes_mcp_stdio_launch_boundary_pack
Return MCP STDIO launch boundaries, profiles, decisions, and evidence.
recipes_mcp_tool_risk_contract
Return MCP tool annotation, trust, and session-combination risk evidence.
recipes_mcp_tool_surface_drift_pack
Return pinned MCP tool descriptions, schemas, annotations, and drift evidence.
recipes_mcp_upstream_call
Call an allowed read-only tool on a configured upstream MCP server.
recipes_mcp_upstream_context
Collect bounded context from configured upstream MCP servers for a remediation query.
recipes_mcp_upstream_servers
List optional upstream MCP servers configured for this Security Recipes server.
recipes_mcp_upstream_tools
List tools exposed by a configured upstream MCP server and show local allow decisions.
recipes_model_provider_routing_pack
Return model-provider route profiles, workflow mappings, and required evidence.
recipes_playbook_get
Get one complete remediation workflow, evidence, output, and Python contract.
recipes_playbook_plan
Build a deterministic, read-only phase, gate, and evidence checklist for a finding.
recipes_playbooks_list
List concise remediation playbook records, optionally filtered by query or category.
recipes_quality_report
Summarize recipe quality tiers and list recipes missing world-class signals.
recipes_refresh
Refresh the in-memory copy of recipes-index.json.
recipes_search
Full-text search over security-recipes documents.
recipes_secure_context_attestation_pack
Return secure-context attestation subjects, verification policy, and recertification state.
recipes_secure_context_buyer_diligence_brief
Return buyer and acquirer diligence evidence for the secure context layer.
recipes_secure_context_customer_proof_pack
Return the customer proof contract for design partner and acquisition evidence.
recipes_secure_context_eval_pack
Return scenario-backed secure-context evals for retrieval, attestation, egress, and handoffs.
recipes_secure_context_evidence_contract
Return the secure context evidence API and release contract.
recipes_secure_context_lineage_ledger
Return context lineage, reuse policy, stage requirements, hashes, and workflow envelopes.
recipes_secure_context_trust_pack
Return context provenance, retrieval policy, source hashes, and workflow context packages.
recipes_secure_context_value_model
Return the secure context value model for buyer, ROI, and acquisition diligence.
recipes_server_info
Return MCP server metadata and source-index configuration.
recipes_workflow_control_plane
Return workflow control-plane policy for agents, reviewers, and MCP gateways.

Endpoints

URLTransportStateLatencyChecked
https://security-recipes.ai/mcp streamable-http answering 649 ms 5 min ago

Alternatives to Security Recipes

same job, measured the same way
I
AgentSec MCP
by traveljamboree

Security intelligence via x402 on Base. CVE lookup, IP reputation, secret scanning.

3 tools answering
I
VulnHunt Security Intelligence
by owenkingva-web

Read-only smart-contract security intelligence for autonomous agents.

11 tools answering
MCP Gateway Scan
by willianpinho

Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions.

58 installs/wk local only
Dependency Management MCP Server
by sonatype

Sonatype component intelligence: versions, security analysis, and Trust Score recommendations

3 tools answering
Nekzus npm Sentinel MCP
by smithery

Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…

answering
PostgreSQL CVE & Release Intelligence
by meob

PostgreSQL security for AI agents: CVEs, yanked releases, exploits, and upgrade paths

105 installs/wk local only
MCP SSH Manager
by bvisible

SSH server management for agents, with per-server read-only and allowlist security modes

685 installs/wk local only
I
Runsec Io
by runsec-io

RunSec MCP server for workspace security scanning and remediation workflows.

44 installs/wk local only

Security Recipes — questions

Answers built from our own checks of this server.

What can Security Recipes do?
It exposes 75 tools, read directly from the server on our last check. Among them: recipes_a2a_agent_card_trust_profile, recipes_agent_capability_risk_register, recipes_agent_handoff_boundary_pack, recipes_agentic_action_runtime_pack, recipes_agentic_aivss_risk_scoring_pack, recipes_agentic_app_intake_pack and 69 more. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Security Recipes working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 92 of 92 checks got a reply (100.0%), average response time 685 ms. The bar chart above shows every period we have measured.
How do I connect Security Recipes?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Security Recipes need an API key?
No. Security Recipes completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 75 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Security Recipes?
It answers our handshake in 685 ms on average, which is faster than 17% of all working MCP servers we measure. That is on the slow side — worth knowing if the tool sits inside an interactive loop. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is Security Recipes open source?
Yes — it is published under the Apache-2.0 licence, written in Python, 1 stars on GitHub and 3 open issues. The source link is on this page, so you can read exactly what it does with your data before you connect it.