A comprehensive collection of **secure** MCP (Model Context Protocol) server implementations for security platform integrations with enterprise-grade
SecurityInfrastructure MCP server is a locally run integration for AI assistants that speak the Model Context Protocol. A comprehensive collection of secure MCP (Model Context Protocol) server implementations for security platform integrations with enterprise-grade security hardening.
Once SecurityInfrastructure is connected, these are the calls the assistant has available:
search-events — Execute sanitized SPL queries with injection preventionsearch-detections — Query detections with FQL validation and whitelistingsearch-attributes — Search IOCs with XSS and injection preventionInstallation — The Installation tool exposed by this serverSetup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client. The configuration blocks on this page cover the common clients.
You will need 5 environment variables: SPLUNK_HOST, SPLUNK_TOKEN, SPLUNK_VERIFY_SSL, REPLACE_WITH_YOUR_SPLUNK_HOST, REPLACE_WITH_YOUR_API_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. SecurityInfrastructure's toolset — search-events, search-detections, search-attributes and 1 more — is a fair guide to whether it matches your workflow. It is maintained by jmstar85; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| search-events | Execute sanitized SPL queries with injection prevention |
| search-detections | Query detections with FQL validation and whitelisting |
| search-attributes | Search IOCs with XSS and injection prevention |
| Installation | The Installation tool exposed by this server. |
{
"mcpServers": {
"security-infrastructure-splunk": {
"command": "python",
"args": ["/FULL/PATH/TO/SecurityInfrastructure/src/splunk_server.py"],
"env": {
"SPLUNK_HOST": "REPLACE_WITH_YOUR_SPLUNK_HOST",
"SPLUNK_TOKEN": "REPLACE_WITH_YOUR_API_TOKEN",
"SPLUNK_VERIFY_SSL": "true"
}
}
}
}Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| SPLUNK_HOST | Endpoint or connection string the server talks to. | Optional |
| SPLUNK_TOKEN | Credential the server authenticates with. | Yes |
| SPLUNK_VERIFY_SSL | Configuration value read at startup. | Optional |
| REPLACE_WITH_YOUR_SPLUNK_HOST | Endpoint or connection string the server talks to. | Optional |
| REPLACE_WITH_YOUR_API_TOKEN | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.