# HackEDU (Security Journey) MCP for AI Agents AI Agent Connect

> HackEDU (Security Journey) lets you manage your entire developer security training program through an AI agent. You can track team progress, sync vulnerability data from bug bounties to trigger adaptive learning, and pull security reports without leaving your chat interface. It turns your AI into a dedicated AppSec Coordinator.

## Overview
- **Category:** developer-tools
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_mFYLpKy0ZZF6v0IY576EZXEePCQlU17GJMa38ror/ai-agent-connect
- **Tags:** security-awareness, secure-coding, vulnerability-training, compliance-training, developer-education

## Description

Managing a security training program usually feels like a chore of jumping between spreadsheets and dashboard tabs. You have to manually check who finished the OWASP modules, look at bug bounty reports, and then figure out which developers need extra help with specific vulnerabilities. This Connector changes that by letting your AI agent do the heavy lifting. Instead of hunting for data, you can just ask your agent for a summary of where your engineering teams stand on security compliance. It connects your HackEDU platform directly to your workflow, so you can push new vulnerability findings into the system to automatically trigger personalized training plans for developers. It's a way to make security education responsive rather than manual. By using this via the Vinkius catalog, you get a hands-off way to manage developer growth and keep your codebases safe without the administrative overhead.

## Tools

### create_issue
Pushes a new vulnerability into HackEDU to trigger a personalized training plan for a team.

### get_team_progress
Shows the current completion status and training stats for a specific team.

### get_user
Pulls the full profile and details for a specific user in your account.

### get_user_progress
Retrieves the specific training milestones and completion data for an individual user.

### list_adaptive_training_plans
Shows the training plans that were automatically generated based on real-world vulnerability findings.

### list_content
Browses all the available security modules and lessons in your HackEDU catalog.

### list_issues
Lists the vulnerability issues synced from external sources like Bugcrowd or HackerOne.

### list_teams
Shows all the teams currently configured within your HackEDU platform.

### list_users
Pulls a full list of every user registered in your HackEDU account.

### list_vulnerabilities
Shows the full taxonomy of vulnerabilities mapped to CWE, CVE, and CAPEC standards.

## Prompt Examples

**Prompt:** 
```
What's the status of the backend team's security training?
```

**Response:** 
```
Checking the progress for the backend team... They are currently at 82% completion.

| Module | Completion |
| :--- | :--- |
| OWASP Top 10 | 90% |
| Secure API Design | 74% |
| SQL Injection Basics | 100% |

12 out of 15 developers have finished all modules. Would you like me to list the names of the 3 who are still pending?
```

**Prompt:** 
```
I found a BOLA vulnerability in our auth service. Can you trigger training for the auth team?
```

**Response:** 
```
I've logged the BOLA vulnerability into HackEDU. This has automatically triggered an adaptive training plan for the Auth Team. They'll see a personalized module focused on Broken Object Level Authorization. I've also synced this with the latest vulnerability taxonomy. Anything else you'd like me to do with this issue?
```

**Prompt:** 
```
Show me all the training modules we have for SQL injection.
```

**Response:** 
```
I've pulled the available content from your HackEDU catalog. Here are the modules related to SQLi:

* **Basics of SQLi** (Introductory)
* **Advanced Blind SQL Injection** (Intermediate)
* **Preventing SQLi in Node.js** (Advanced/Specific)

Would you like me to assign one of these to a specific team or user?
```

## Capabilities

### Track team completion rates
See how many developers have finished specific security modules in real time.

### Sync bug bounty issues to training
Automatically trigger personalized learning plans when a new vulnerability is reported.

### Browse the security lesson catalog
Search through all available security training modules and lessons via your agent.

### Pull user progress reports
Retrieve detailed training milestones for individual developers across the organization.

### Map vulnerabilities to training
Access the full taxonomy of vulnerabilities mapped to CWE, CVE, and CAPEC standards.

### List all account users
Get a full list of everyone registered in your HackEDU account for easy auditing.

## Use Cases

### Closing the bug bounty loop
An AppSec lead sees a spike in SQL injection bugs and asks the agent to use create_issue to push the bug and trigger adaptive training for the backend team.

### Instant team progress checks
An Engineering Manager needs a weekly status update and asks the agent to summarize the get_team_progress for three different squads to see who's finished.

### Onboarding new developers
A new hire joins the team and the manager asks the agent to use list_content to find the best Secure Coding Basics modules for them.

### Audit compliance reporting
A security audit is coming up and the lead uses list_users and get_user_progress to generate a completion report for the whole company.

## Benefits

- Stop manual data entry by using list_users and list_teams to manage your entire organization's security training roster in seconds.
- Close the loop on bug bounties by using create_issue to turn real-world flaws into immediate developer learning opportunities.
- Get instant visibility into team health with get_team_progress, letting you see exactly who is lagging on security milestones.
- Align your training with industry standards by using list_vulnerabilities to map your curriculum to CWE and CVE data.
- Save hours on reporting by asking your agent to summarize progress across all departments using get_user_progress and list_adaptive_training_plans.

## How It Works

The bottom line is you get a dedicated security training manager that lives inside your AI client.

1. Subscribe to the HackEDU MCP on Vinkius.
2. Enter your HackEDU API Key from the Admin Dashboard into your AI client.
3. Ask your agent to pull progress reports or create new training issues.

## Frequently Asked Questions

**Can HackEDU (Security Journey) help me automate developer training?**
Yes, it connects your training platform to your AI agent so you can manage assignments, track progress, and trigger lessons automatically through conversation.

**How does HackEDU (Security Journey) handle bug bounty data?**
You can push vulnerabilities from sources like Bugcrowd or HackerOne into the system to automatically generate personalized training plans for your developers.

**Can I see who hasn't finished their security modules?**
Yes, your agent can pull progress for specific users or teams, allowing you to quickly identify who needs to complete their required training.

**Does HackEDU (Security Journey) support CWE and CVE mappings?**
It does. The Connector can access the vulnerability taxonomy mapped to CWE, CVE, and CAPEC standards to ensure your training stays relevant to real threats.

**Is HackEDU (Security Journey) good for AppSec teams?**
It's specifically designed for AppSec teams who need to bridge the gap between finding bugs and educating the engineers who write the code.

**Can I use HackEDU (Security Journey) to see our full user list?**
Yes, your agent can pull a full list of every user in your HackEDU account whenever you need to perform an audit or manage access.

**How do I find my HackEDU API Key?**
Log in to your HackEDU Admin Dashboard and navigate to the API section. You will be able to generate and copy your unique X-API-Key from there.

**Can I track the training progress of a specific team?**
Yes! Use the `get_team_progress` tool by providing the unique team ID. The agent will return the completion percentage and status for that team.

**What is 'Adaptive Training' in this integration?**
Adaptive Training allows you to push real-world vulnerability findings (via `create_issue`) to HackEDU. The platform then automatically assigns relevant security lessons to developers to help them fix and prevent similar issues.

**Is HackEDU now part of Security Journey?**
Yes, HackEDU was acquired by Security Journey. This integration works with accounts from both brands using the same API infrastructure.