Wazuh-MCP-Server — security grade CAUTION, quality 71/100

Security audit verdict: CAUTION · quality 71/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by INFOKOM-KI · MCP Server · ★ 58

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is Wazuh-MCP-Server safe to install? View the security audit →

About Wazuh-MCP-Server

Blue Team MCP Server (Wazuh SIEM) A defensive MCP server for Claude Desktop / any MCP client — the blue-team counterpart to offensive tooling. Exposes 100+ SOC tools across Wazuh SIEM, multi-provider threat intelligence, alert enrichment, MITRE-driven 3-Sum APT correlation, attack graphing, LangGraph investigation workflows, and host forensics. Read-only by default. Programmer: () Architecture Quick Start bash git clone && cd Wazuh-MCP-Server sudo bash setup.sh # deps, venv, wrapper at /opt/blue-team-mcp configure (edit /opt/blue-team-mcp/config.env) export WAZUHINDEXERURL="https://:9200" export WAZUHINDEXERUSER="admin" export WA

ai-agentsblue-teamllmmcpmcp-serversecurity-automationsecurity-operations-centersecurity-toolssiemsoc

Quick Facts

Stars58
Forks18
LanguagePython
CategoryMCP Server
LicenseBSD-3-Clause
Quality Score71.3179265537516/100
Last Updated2026-09-22
Created2026-07-20
Platformsmcp, python
Est. Tokens~17k

Compatible Skills

These tools work well together with Wazuh-MCP-Server for enhanced workflows:

  • ui-skill-lab — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)

Wazuh-MCP-Server alternative? Top 6 similar tools

Looking for a Wazuh-MCP-Server alternative? If you're comparing Wazuh-MCP-Server with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Wazuh-MCP-Server by gensecaihq · ⭐ 232

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • allama by digitranslab · ⭐ 197

    🔥🔥🔥 AI security automation platform. Build visual workflows, deploy autonomous agents, and automate threat

  • code-pathfinder by shivasurya · ⭐ 140

    Static Code Analysis for security teams with Inter file taint analysis. Built for finding vulnerabilities, adv

  • cybersec-toolkit by 26zl · ⭐ 59

    One command installs 670+ security tools on Linux & Termux. Its authorization-gated MCP server works with Clau

  • pentest-skills by crazyMarky · ⭐ 277

    💬 🚀 告别繁琐命令行,用自然语言驱动专业级渗透测试。 ⚡ 让安全测试从未如此简单、高效。Forget complex command lines. 🛡️ Professional penetration test

  • AutoRedTeam-Orchestrator by Coff0xc · ⭐ 263

    MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is Wazuh-MCP-Server?

Wazuh-MCP-Server is Wazuh MCP Server: AI-Driven SOC Automation. It is categorized as a MCP Server with 58 GitHub stars.

What programming language is Wazuh-MCP-Server written in?

Wazuh-MCP-Server is primarily written in Python. It covers topics such as ai-agents, blue-team, llm.

How do I install or use Wazuh-MCP-Server?

You can find installation instructions and usage details in the Wazuh-MCP-Server GitHub repository at github.com/INFOKOM-KI/Wazuh-MCP-Server. The project has 58 stars and 18 forks, indicating an active community.

What license does Wazuh-MCP-Server use?

Wazuh-MCP-Server is released under the BSD-3-Clause license, making it free to use and modify according to the license terms.

What are the best alternatives to Wazuh-MCP-Server?

The top alternatives to Wazuh-MCP-Server on Agent Skills Hub include Wazuh-MCP-Server, allama, code-pathfinder. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools