Back to Browse

Truss Agent MCP Server

SecurityLow Risk8.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Query Truss threat intelligence via hosted MCP (OAuth). Growth+ plans.

About

Query Truss threat intelligence via hosted MCP (OAuth). Growth+ plans.

Remote endpoints: streamable-http: https://api.truss-security.com/mcp

Security Report

8.0
Low Risk8.0Low Risk

Remote MCP endpoint verified (1394ms response). 3 trust signals: valid MCP protocol, requires auth, registry import. No security issues detected.

Endpoint verified · Requires authentication · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Remote servers are capped at 8.0 because source code is not available for review. The score reflects endpoint verification only.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "com-truss-security-truss-mcp": {
      "url": "https://api.truss-security.com/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

truss-agent-mcp

Truss threat intelligence via Model Context Protocol and a terminal assistant — one binary: truss-mcp.

smithery badge

Truss MCP on Smithery

Two surfaces

SurfaceUse forAuth
Remote (recommended)Cursor, Claude Desktop, MCP registriesOAuth → https://api.truss-security.com/mcp
Local stdio (legacy)Air-gap / BYO-key / FilterQL REPL toolsTRUSS_API_KEY → REST

Hosted MCP (OAuth, Growth+ gate, five tools) is served by the Truss API. This package ships configs, validate-remote / doctor --remote, CLI search, and optional local stdio. Community accounts cannot consent to hosted MCP.

Not on npm yet. Install from this repo (npm install -g .). After publish: npm install -g @truss-security/truss-agent-mcp.

Quick start

cd truss-agent-mcp
npm install && npm run build
npm install -g .
truss-mcp doctor --remote --strict-oauth   # OAuth path hosts use
truss-mcp init                            # for CLI search / legacy stdio
truss-mcp search

Node.js 18+. Binary name truss-mcp avoids conflict with @truss-security/truss-sdk's truss command.

What you can run

CommandWhat it does
truss-mcp searchGuided REPL with live MCP tools (local stdio or remote OAuth token)
truss-mcp mcpLocal stdio MCP server (legacy / air-gap)
truss-mcp initInteractive .env setup
truss-mcp doctorValidate keys and API access; --remote runs hosted OAuth doctor
truss-mcp validate-remote <url>OAuth + MCP doctor (discovery, DCR, PKCE, tools)
truss-mcp helpUsage summary

Guided search workflow

One REPL with MCP tools always connected. The assistant classifies your intent and asks before querying Truss API:

  1. Knowledge — Truss platform, cyber security context, threat background
  2. Build filter — draft FilterQL, validate, confirm
  3. Queryrun executes confirmed filter (default 7 days)
  4. Formatstix for STIX export; JSON summaries in-thread
  5. Detection rulesdetect splunk, detect falcon, detect cortex from search results

The assistant offers next steps explicitly: build a filter, refine it, query Truss API, export JSON/STIX, or generate SIEM/EDR hunting queries.

  • Wider windows (run 30, days 30) may use more API quota
  • Context-only follow-ups (IOC dedupe, reformat) use thread history without re-querying

Full REPL reference: guides/truss-cli.md

Terminal display (REPL)

truss-mcp search uses color-coded, ASCII-bordered output:

  • You — your message
  • MCP — live tool trace (→ search_threats on remote, or → search_products on stdio)
  • Results — structured product table before the assistant summary
  • Truss — assistant reply (cyan), guided offers (yellow), FilterQL blocks (magenta)

Controls: color / color on / color off / color auto · env TRUSS_MCP_COLOR · standard NO_COLOR=1

MCP host (Cursor / Claude) — remote OAuth (recommended)

No API key in host config. Growth+ Truss account; browser OAuth consent.

{
  "mcpServers": {
    "truss-mcp": {
      "url": "https://api.truss-security.com/mcp"
    }
  }
}

Samples: config/cursor.mcp.json · config/claude_desktop_config.json · guides/client-setup-cursor.md.

Legacy stdio (air-gap)

{
  "mcpServers": {
    "truss-mcp": {
      "command": "truss-mcp",
      "args": ["mcp"],
      "env": { "TRUSS_API_KEY": "YOUR_KEY" }
    }
  }
}

See config/cursor.mcp.stdio.json and guides/getting-started.md.

Remote MCP OAuth validation (registry gate)

Use as the OAuth + MCP doctor before registry publish or release. After OAuth it requires search_threats to return at least one Truss product (id + title). The access token stays in memory for that process only unless you pass --save-token.

truss-mcp doctor --remote --strict-oauth
# or:
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth

After token exchange it prints an OAuth compatibility checklist (resource URI, redirects, PKCE S256, issuer match, audience vs MCP resource, truss_role), then proves MCP access with real Truss data.

Options:

truss-mcp validate-remote https://api.truss-security.com/mcp --verbose
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth
truss-mcp validate-remote https://api.truss-security.com/mcp --save-token /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --token-file /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --port 9877
truss-mcp validate-remote https://api.truss-security.com/mcp --no-open
  • --verbose — HTTP statuses, key headers, truncated bodies (tokens redacted)
  • --strict-oauth — exit 2 if the OAuth checklist has WARN/FAIL (even when Truss MCP calls succeed)
  • --save-token PATH — write the access token for local replay (mode 0600; delete after debugging)
  • --token-file PATH — skip browser OAuth; reuse a saved token to re-check MCP access + Truss data

Optional automated OAuth data tests (saved token + TRUSS_RUN_MCP_OAUTH=1) are documented in guides/publishing.md.

Official listing: server.json (com.truss-security/truss-mcp) · Tracker: guides/registry-submission.md · Internal metadata: config/mcp-registry.json · Architecture: docs/05-hosted-mcp-oauth-architecture.md

Configuration

Env load order (shell vars win): ~/.config/truss/env~/.truss/.env./.env

VariableRequired forNotes
TRUSS_API_KEYlocal mcp / stdio searchFrom Truss dashboard (legacy air-gap only)
TRUSS_MCP_URLremote search / doctorDefault https://api.truss-security.com/mcp
TRUSS_MCP_OAUTH_TOKEN_FILEremote searchBearer token from validate-remote --save-token
LLM_PROVIDERsearchanthropic or openai — set via init
LLM_MODELsearchSet via init
ANTHROPIC_API_KEY / OPENAI_API_KEYsearchPer provider

Full list: env.example

Documentation

Guides — install, REPL, MCP clients, FilterQL examples

Reference — API contract, tools, architecture (docs/README.md — docs 01–06)

Development

npm install && npm run build
npm test
npm run truss:search    # from source without global install

Contributors / AI agents: see AGENTS.md for repo operations and conventions.

Publish: guides/publishing.md · Changes: CHANGELOG.md

Related

MIT

Reviews

No reviews yet

Be the first to review this server!