AI-SOC-Agent — security grade CAUTION, quality 74/100

Security audit verdict: CAUTION · quality 74/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by M507 · MCP Server · ★ 51

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is AI-SOC-Agent safe to install? View the security audit →

About AI-SOC-Agent

SamiGPT SamiGPT is an AI-powered security investigation and incident response platform that provides security operations teams with intelligent automation for case management, SIEM analysis, and CTI enrichment through the Model Context Protocol (MCP). Note: This project is currently under active development. Features, APIs, and documentation may change as development progresses. Demo Watch the demo video to see SamiGPT in action: Demo Video For detailed documentation and presentation materials: AI Agents Presentation PDF Quick Start SamiGPT is started from a single entry point. That process serves the web UI and, by default, also starts the MCP server as a separate HTTPS listener with its own settings and health check. Steps: Clone the repository and create a virtual environment (skip if you already have one): Set the UI password in (copied from automatically on first run): is generated automatically if left empty. Add tokens/U

agentic-socai-agentai-agentsai-socai-soc-agentblue-teamdetection-engineeringincident-responsemcpmcp-server

Quick Facts

Stars51
Forks11
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score74.4317898615048/100
Last Updated2026-09-30
Created2025-12-05
Platformsmcp, python
Est. Tokens~17k

Compatible Skills

These tools work well together with AI-SOC-Agent for enhanced workflows:

  • vigil — semantic(0.60)+rare_topics+same_lang+similar_pop+shared_platform (61%)
  • CyberGuard — semantic(0.56)+rare_topics+same_lang+similar_pop+shared_platform (59%)

AI-SOC-Agent alternative? Top 6 similar tools

Looking for a AI-SOC-Agent alternative? If you're comparing AI-SOC-Agent with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Wazuh-MCP-Server by gensecaihq · ⭐ 246

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • adk_runbooks by dandye · ⭐ 83
  • zettelforge by ThreatRecall · ⭐ 63

    Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MC

  • CyberGuard by elsechord · ⭐ 54

    Evidence-driven autonomous SOC team on AgentTeams: hash-bound approvals, HMAC audit chain, rollback and reprod

  • zettelforge by rolandpg · ⭐ 50

    Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MC

  • google-analytics-mcp by surendranb · ⭐ 242

    Google Analytics 4 data to AI agents, agentic workflows, and MCP clients. Give agents analysis-ready access to

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is AI-SOC-Agent?

AI-SOC-Agent is Blackhat 2025 presentation and codebase: AI SOC agent & MCP server for automated security investigation, alert triage, and incident response. Integrates with ELK, IRIS, and other platforms.. It is categorized as a MCP Server with 51 GitHub stars.

What programming language is AI-SOC-Agent written in?

AI-SOC-Agent is primarily written in Python. It covers topics such as agentic-soc, ai-agent, ai-agents.

How do I install or use AI-SOC-Agent?

You can find installation instructions and usage details in the AI-SOC-Agent GitHub repository at github.com/M507/AI-SOC-Agent. The project has 51 stars and 11 forks, indicating an active community.

What license does AI-SOC-Agent use?

AI-SOC-Agent is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to AI-SOC-Agent?

The top alternatives to AI-SOC-Agent on Agent Skills Hub include Wazuh-MCP-Server, adk_runbooks, zettelforge. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools