No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by mwnickerson · MCP Server · ★ 121
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is bloodhound_mcp safe to install? View the security audit →
BloodHound MCP A Model Context Protocol (MCP) server that connects LLMs to BloodHound Community Edition. Ask questions in natural language, get attack path analysis, run Cypher queries, and explore Active Directory, Azure/Entra ID, and OpenGraph environments — all from your AI assistant. Demo Watch the demonstration video (updated demo coming soon) How It Works The server exposes BloodHound CE's REST API and Neo4j graph through a set of 11 composite MCP tools, 10 reference resources, and a system prompt tuned for offensive security analysis. Composite Tools Each tool uses an parameter to select what data is returned, keeping the tool surface small and token-efficient: , , ,
| Stars | 121 |
| Forks | 28 |
| Language | Python |
| Category | MCP Server |
| License | GPL-3.0 |
| Quality Score | 76.7728001594068/100 |
| Last Updated | 2026-08-19 |
| Created | 2025-03-22 |
| Platforms | mcp, python |
| Est. Tokens | ~15k |
These tools work well together with bloodhound_mcp for enhanced workflows:
Explore other popular mcp server tools:
bloodhound_mcp is A Model Context Protocol (MCP) server to converse with data in Bloodhound. It is categorized as a MCP Server with 121 GitHub stars.
bloodhound_mcp is primarily written in Python.
You can find installation instructions and usage details in the bloodhound_mcp GitHub repository at github.com/mwnickerson/bloodhound_mcp. The project has 121 stars and 28 forks, indicating an active community.
bloodhound_mcp is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: