# Aikido Security MCP for AI Agents AI Agent Connect

> Aikido Security connects your security posture to your AI agent. Use it to query vulnerabilities, check repository scanning status, monitor cloud assets across AWS, GCP, and Azure, and track ISO 27001 or SOC2 compliance directly through natural conversation.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_wRZpjFqCAWKWhWyj3hhqpI2p8l2TdRgNe6wu318O/ai-agent-connect
- **Tags:** code-security, vulnerability-management, sast, cloud-security, compliance-monitoring, security-dashboard

## Description

Managing security posture usually means jumping between a dozen different tabs and dashboards. You have to check your cloud infrastructure for misconfigurations, look for leaked secrets in GitHub, and then somehow track if you're actually meeting your compliance goals. This Connector changes that by bringing all that data into your AI client. Instead of manual hunting, you can just ask your agent what's wrong. You can pull a list of high-priority CVEs, check if your web apps have firewall protection, or see which teams own specific repositories. It turns your AI into a dedicated security analyst that knows your environment inside out. You can find this in the Vinkius catalog to get started. It's about getting answers in seconds so you can spend your time fixing problems instead of finding them.

## Tools

### export_all_issues
Download a full snapshot of your security posture. Use this for compliance reporting or bulk analysis.

### get_iso_compliance
Get an overview of your ISO 27001 controls. See what's passing and what needs attention for your audit.

### get_issue_group
Get detailed info on a specific group of related vulnerabilities. Use this to deep-dive into a specific finding.

### get_soc2_compliance
Get your SOC2 compliance overview. Check which trust service criteria are met and which need work.

### get_workspace
Get your workspace configuration. Use this to verify your setup and check for any configuration errors.

### list_apps
List all web applications protected by the firewall. Verify that your apps are secured against common attacks.

### list_cloud_assets
List all cloud infrastructure assets. Use this to identify misconfigurations in your AWS, GCP, or Azure accounts.

### list_code_repositories
List all active code repositories. See which repos from GitHub, GitLab, or Bitbucket are being monitored.

### list_connected_clouds
List all cloud accounts connected to Aikido. Use this to verify your cloud integrations are properly configured.

### list_containers
List all container images and registries. Use this to identify vulnerable base images or dependencies.

### list_custom_rules
List all custom SAST scanning rules. Use this to audit your custom rules and ensure your policies are enforced.

### list_open_issues
List all open security issues. Filter by type, team, or repository to prioritize your remediation efforts.

### list_teams
List all teams in your organization. Use this to understand how your company structures its security responsibilities.

### list_users
List all users in your organization. Use this to audit user roles and ensure proper security team membership.

### list_virtual_machines
List all virtual machines monitored by Aikido. Use this to understand your VM attack surface and security gaps.

### list_webhooks
See all configured webhooks for Slack or Jira. Use this to check if your security alerts are actually sending.

## Prompt Examples

**Prompt:** 
```
What's our current ISO 27001 status and what's failing?
```

**Response:** 
```
Your ISO 27001 compliance overview shows **89% of controls passing** (142/160).

**Areas needing attention:**
* **A.8.25 (Secure Development Lifecycle)** — 3 failing checks
* **A.8.28 (Secure Coding)** — 2 failing checks

All other control categories are passing. You're well-positioned for your next audit.
```

**Prompt:** 
```
Show me all the high priority issues in our production cloud assets.
```

**Response:** 
```
I've found the following high-priority misconfigurations in your production cloud assets:

| Asset Type | Region | Issue | Priority |
| :--- | :--- | :--- | :--- |
| S3 Bucket | us-east-1 | Publicly accessible | HIGH |
| IAM Role | us-west-2 | Over-permissive permissions | HIGH |
| RDS Instance | us-east-1 | Unencrypted storage | HIGH |

Would you like me to get more details on any of these?
```

**Prompt:** 
```
Which repositories are we not currently scanning?
```

**Response:** 
```
I've checked your connected repositories. Here are the active ones currently being monitored:

* **frontend-app** (GitHub)
* **api-gateway** (GitLab)
* **auth-service** (Bitbucket)

If you have other repositories that aren't listed here, they aren't currently connected to Aikido for security scanning.
```

## Capabilities

### Query open vulnerabilities
Get a filtered list of security issues like CVEs or leaked secrets ordered by priority.

### Monitor cloud infrastructure
See your AWS, GCP, and Azure assets to identify misconfigurations or exposed resources.

### Track compliance status
Pull overviews for ISO 27001 and SOC2 to see which controls are passing or failing.

### Audit repository scanning
Check the status of code repositories connected via GitHub, GitLab, and Bitbucket.

### Manage web application security
List all web apps protected by the firewall and check their current configuration status.

### Export security reports
Bulk export all findings for use in audit preparation or executive reporting.

## Use Cases

### The Audit Rush
A compliance officer needs to know the ISO 27001 status. They ask the agent for the overview and get a list of failing controls instantly.

### The Morning Triage
A security engineer wants to know if there are any new critical issues. They ask the agent to list all open issues filtered by severity.

### Cloud Risk Cleanup
A DevOps lead wants to find all public buckets. They ask the agent to list cloud assets and identify misconfigurations in AWS.

### Repo Scanning Audit
An engineering manager wants to see which repositories aren't being scanned. They ask the agent to list all connected code repositories.

## Benefits

- Stop manual dashboard hopping by using list_open_issues to get a status update on vulnerabilities instantly.
- Prep for audits faster with get_iso_compliance and get_soc2_compliance to see your current standing in seconds.
- Identify cloud risks quickly by using list_cloud_assets to find exposed S3 buckets or over-permissive IAM roles.
- Keep your team informed by using list_webhooks to ensure security alerts are actually hitting your Slack or Jira channels.
- Simplify reporting by using export_all_issues to get a full snapshot of your security posture for your manager.
- Audit your own security team using list_users and list_teams to verify who has access to your security tools.

## How It Works

The bottom line is you get a security analyst that lives inside your chat interface instead of a bunch of open tabs.

1. Subscribe to the Aikido Security MCP and grab your personal access token from your Aikido user settings.
2. Enter the token into your AI client configuration to link your security data.
3. Ask your agent to list open issues, check compliance, or audit your cloud assets.

## Frequently Asked Questions

**Can I use the Aikido Security MCP to see my cloud vulnerabilities?**
Yes, it pulls data from AWS, GCP, and Azure to show you misconfigurations and security gaps in your cloud infrastructure.

**Does the Aikido Security MCP help with SOC2 audits?**
Yes, it provides a direct overview of your SOC2 trust service criteria, showing you what is met and what needs remediation.

**How do I see my security teams with this Connector?**
You can simply ask your agent to list all teams. It will show you how your organization is structured into security groups.

**Can this Connector check my GitHub repos?**
Yes, it lists all repositories connected to Aikido from GitHub, GitLab, and Bitbucket so you can see what's being monitored.

**Does the Aikido Security MCP work with Cursor or Claude?**
Yes, it works with any MCP-compatible client, including Claude, Cursor, Windsurf, and VS Code.

**Can I export my security findings for a report?**
Yes, you can ask the agent to export all issues, which gives you a full snapshot of your security posture for audit prep or reporting.

**How do I get an Aikido API token and where do I find it?**
Log in to your Aikido dashboard, click on **User Settings** in the header, then navigate to **Personal Access Tokens**. Click to create a new token and copy it immediately — you'll only see it once. The token typically starts with `aik_`. Paste it into the API token field below.

**What types of security issues can Aikido detect?**
Aikido detects a wide range of security issues including: open source vulnerabilities (CVEs in dependencies), leaked secrets and API keys, cloud misconfigurations (AWS, GCP, Azure), SAST findings (code-level vulnerabilities), IaC issues (Terraform, CloudFormation), container vulnerabilities, DAST findings, malware detection, end-of-life dependencies, SCM security issues, and license compliance. You can filter issues by type when querying.

**Can I check my compliance status for ISO 27001 and SOC2?**
Yes! Use the `get_iso_compliance` tool for ISO 27001 and `get_soc2_compliance` for SOC2. These endpoints provide a complete compliance overview showing which controls or criteria are passing, failing, or need attention. Both are available on all paid Aikido plans and are perfect for audit preparation and ongoing compliance monitoring.

**How does Aikido prioritize security issues?**
Aikido automatically prioritizes open issue groups by priority (descending). The prioritization considers factors like severity (critical, high, medium, low), exploitability, whether the vulnerability is actively exploited in the wild, and the context of the affected resource. This means you always see the most dangerous and actionable vulnerabilities first, helping your team focus on what matters most.