Cybersim MCP Server

Cybersecurity training, simulation, and incident response MCP server

Local serverstdioTypeScript

What is the Cybersim MCP server?

Connect Cybersim to Claude, Cursor or any other MCP client and it stops being a tab you switch to. Cybersecurity training, simulation, and incident response MCP server. The cybersim mcp server is what makes that connection.

What the server does

CyberSim Pro is a professional-grade Model Context Protocol (MCP) server purpose-built for cybersecurity training, purple-team collaboration, and executive readiness. It equips AI assistants and automation pipelines with structured tools to generate scenarios, simulate adversaries, analyse telemetry, investigate incidents, perform forensics, and publish board-ready reports—all while recording an immutable audit trail.

Installation

Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client. The configuration blocks on this page cover the common clients.

Available tools

The toolset is worth reading before you wire it up, because it tells you what the integration is really for:

  • CYBERSIM_API_KEY — require Authorization: Bearer header
  • CYBERSIM_IP_ALLOW — comma-separated list (127.0.0.1,::1,local,203.0.113.10)
  • CYBERSIM_APPROVAL_TOKEN — shared secret required for restricted tools (simulate_attack, stop_simulation, replay_telemetry)
  • CYBERSIM_RBAC_CONFIG — optional path to a JSON role policy (see Role-Based Access & Approvals)

Credentials and setup notes

Configuration is passed through the environment: CYBERSIM_API_KEY, CYBERSIM_APPROVAL_TOKEN, CYBERSIM_AUDIT_HMAC_KEY, CYBERSIM_AUDIT_CHAIN_ID, CYBERSIM_AUDIT_SEAL_KEY, CYBERSIM_SCIM_TOKEN. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Where it fits

Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Cybersim's toolset — CYBERSIM_API_KEY, CYBERSIM_IP_ALLOW, CYBERSIM_APPROVAL_TOKEN and 1 more — is a fair guide to whether it matches your workflow. It is maintained by kayembahamid; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Available tools

ToolWhat it does
CYBERSIM_API_KEYrequire Authorization: Bearer <key> header
CYBERSIM_IP_ALLOWcomma-separated list (127.0.0.1,::1,local,203.0.113.10)
CYBERSIM_APPROVAL_TOKENshared secret required for restricted tools (simulate_attack, stop_simulation, replay_telemetry)
CYBERSIM_RBAC_CONFIGoptional path to a JSON role policy (see [Role-Based Access & Approvals](#role-based-access--approvals))

How to install the Cybersim MCP server

For Docker-backed execution:
```json
{
  "mcpServers": {
    "cybersim-pro-docker": {
      "command": "docker",
      "args": ["run", "--rm", "-i", "cybersim-pro-mcp"]
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

VariableDescriptionRequired
CYBERSIM_API_KEYCredential the server authenticates with.Yes
CYBERSIM_APPROVAL_TOKENCredential the server authenticates with.Yes
CYBERSIM_AUDIT_HMAC_KEYCredential the server authenticates with.Yes
CYBERSIM_AUDIT_CHAIN_IDConfiguration value read at startup.Optional
CYBERSIM_AUDIT_SEAL_KEYCredential the server authenticates with.Yes
CYBERSIM_SCIM_TOKENCredential the server authenticates with.Yes

Example prompts to try

  • Use Cybersim to CYBERSIM API KEY.
  • Use Cybersim to CYBERSIM IP ALLOW.
  • Use Cybersim to CYBERSIM APPROVAL TOKEN.

Frequently asked questions

It connects Cybersim to MCP-compatible AI assistants such as Claude and Cursor, exposing 4 tools (CYBERSIM_API_KEY, CYBERSIM_IP_ALLOW, CYBERSIM_APPROVAL_TOKEN, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Cybersim directly.