No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by gensecaihq · MCP Server · ★ 232
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is Wazuh-MCP-Server safe to install? View the security audit →
Wazuh MCP Server Talk to your SIEM. Query alerts, hunt threats, check vulnerabilities, and trigger active responses across your entire Wazuh deployment — through natural conversation with any AI assistant. v4.2.1 Changelog What This Does Your Wazuh SIEM generates thousands of alerts, vulnerability findings, and agent events daily. Investigating them means juggling dashboards, writing API queries, and manually correlating data across tools. This MCP server turns that workflow into a conversation: You: "Show me critical alerts from the last hour" AI: [calls getwazuhalerts] Found 3 critical alerts: SSH brute force from 10.0.1.45 → agent-003 (Rule 5712, Level 10) Rootkit detection on agent-007 (Rule 510, Level 12) FIM change /etc/shadow on agent-001 (Rule 550, Level 10) You: "Block that source IP on agent-003" AI: [calls wazuhblockip] Blocked 10.0.1.45 via firewall-drop on agent-003. You: "Which agents have u
| Stars | 232 |
| Forks | 63 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 78.3128085945785/100 |
| Open Issues | 9 |
| Last Updated | 2026-09-15 |
| Created | 2025-03-13 |
| Platforms | claude-code, mcp, python |
| Est. Tokens | ~17k |
Looking for a Wazuh-MCP-Server alternative? If you're comparing Wazuh-MCP-Server with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red tea
🔥🔥🔥 AI security automation platform. Build visual workflows, deploy autonomous agents, and automate threat
See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate
MCP server for YouTube — search videos, get transcripts, channels, and playlists. Works with Claude, Cursor &
Wazuh MCP Server: AI-Driven SOC Automation
Official remote MCP server for Atlassian. Securely connect Jira, Confluence, Jira Service Management, Bitbucke
Explore other popular mcp server tools:
Wazuh-MCP-Server is Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response. C. It is categorized as a MCP Server with 232 GitHub stars.
Wazuh-MCP-Server is primarily written in Python. It covers topics such as active-response, ai, claude.
You can find installation instructions and usage details in the Wazuh-MCP-Server GitHub repository at github.com/gensecaihq/Wazuh-MCP-Server. The project has 232 stars and 63 forks, indicating an active community.
Wazuh-MCP-Server is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to Wazuh-MCP-Server on Agent Skills Hub include ai_for_the_win, allama, mcp-audit. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: