Query runZero and diff a local attack surface snapshot over time.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "runZero MCP" yet — see the docs or source repo.
Compare the two most recent runZero asset snapshots and list newly open ports, newly discovered hosts, and high-risk services, then summarize them by risk level.
A risk-ranked diff report with new assets, port changes, and priority findings.
Using the local SQLite attack surface data, find devices that repeatedly appeared in the last 30 days but lack standard naming or owner tags, grouped by subnet.
A list of unmanaged devices showing recurrence, subnet, and suggested remediation priority.
Analyze attack surface trends over the last 90 days, including changes in host count, service count, and exposed protocols, and highlight anomalous spikes.
A trend analysis summary with key metrics, anomaly dates, and possible causes.
Sync your Datto BCDR fleet into SQLite for per-appliance analysis.
Read Xero data and a local SQLite ledger for aging and reconciliation.
Query and update ThreatLocker Portal data to automate security operations.
Automate HaloPSA ticket triage, SLA risk alerts, and cross-client service analytics.
Triage backups, detect stale snapshots, and analyze backup health across engines.
Access Autotask entities by CLI and analyze ticket aging locally.
Auto-generates SQLite CRUD tools and safe query prompts.
Review fleet-wide vulnerability and PII scan findings with natural language.
Integrate multiple security tools for AI-assisted pentesting and vulnerability validation.
Run AI-assisted penetration testing through safety-hardened MCP security tool endpoints.
Safely manage Runn API resources through MCP with read, write, and dry-run tools.
Scan MCP servers for runtime, static, config, dependency, and compliance risks.