# UpGuard MCP for AI Agents AI Agent Connect

> UpGuard MCP connects your security posture to your AI agent. It lets you query vendor risk scores, track active infrastructure vulnerabilities, and monitor employee identity breaches in real-time. You can quickly audit your attack surface and SaaS footprint through natural conversation instead of digging through multiple dashboards.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_aO2BztAEVzc5wBNs1ZVhFNkwmjCOCN31991r7XLZ/ai-agent-connect
- **Tags:** attack-surface, vendor-risk, cybersecurity, compliance, security-scanning, risk-assessment

## Description

UpGuard MCP connects your security posture to your AI agent. Instead of jumping between different dashboards to see who is actually at risk, you can just ask questions about your current security status. You can pull up a list of every vendor you are currently monitoring to see who is falling behind on security standards, or check for active threats on your own IP ranges and domains. It is about getting a clear picture of your attack surface without the manual heavy lifting of filtering through logs. If you are looking for a way to manage multiple integrations in one spot, Vinkius makes it easy to plug this into your existing workflow. You can quickly audit user-related risk data to see if any employee accounts are showing signs of identity theft or if a third-party vendor has a glaring vulnerability that needs immediate attention. It moves the work from finding the data to making a decision based on that data.

## Tools

### get_vendor
Pull detailed metadata and security scores for a specific vendor. Use this to get a deep dive into a single company's risk.

### list_saas_apps
View all the SaaS applications you currently monitor for security risks. This helps you keep track of your software footprint.

### list_identity_breaches
See a list of identity breaches that are currently affecting your workforce. Use this to spot targeted credential theft.

### list_monitored_domains
Get a list of all the domains you have set up for monitoring. It helps you verify your organization's online presence.

### list_user_risks
Get a breakdown of risk data for specific users and employees. This helps you identify which accounts need extra protection.

### list_vendor_risks
See the specific active risks for a particular vendor. Use this to see exactly what needs remediation for a partner.

### list_vendors
Get a full list of every vendor you are currently monitoring. This is your starting point for vendor risk audits.

### list_monitored_ips
View a list of all monitored IP addresses across your network. This is useful for checking infrastructure coverage.

### list_account_risks
See all the active security risks currently flagged on your account. Use this to find the most urgent issues to fix.

## Prompt Examples

**Prompt:** 
```
Show me the top 3 vendors with the lowest security scores.
```

**Response:** 
```
I've checked your vendor list. Here are the three with the lowest security scores:

| Vendor | Score | Risk Level |
| :--- | :--- | :--- |
| **Legacy Systems Inc** | 310/950 | Critical |
| **DataFlow Corp** | 420/950 | High |
| **WebHost Plus** | 510/950 | Medium |

Would you like me to pull the specific active risks for **Legacy Systems Inc**?
```

**Prompt:** 
```
Are there any active risks on our IP ranges right now?
```

**Response:** 
```
I've scanned your monitored infrastructure. I found **4 active risks** on your IP ranges:

*   **Unencrypted Traffic:** Detected on 2 IPs in your primary range.
*   **Outdated TLS:** 2 IPs are still supporting TLS 1.0.

I can provide the specific IP addresses for these if you need them.
```

**Prompt:** 
```
List the identity breaches affecting our employees this week.
```

**Response:** 
```
I found **2 identity breaches** affecting your workforce in the last 7 days:

*   **Credential Stuffing:** 3 employees affected via a third-party login site.
*   **Phishing Attack:** 1 employee account flagged for suspicious activity.

Would you like to see the specific user risk data for these accounts?
```

## Capabilities

### Pull vendor security scores
Get real-time security ratings for all the third-party vendors you monitor.

### Track infrastructure risks
Identify active vulnerabilities across your IP ranges and domains.

### Monitor identity breaches
See which employee accounts are currently affected by identity theft.

### Audit digital assets
List your monitored SaaS applications and domain footprint in one place.

### Check employee risk data
Retrieve risk profiles for specific users to prioritize security actions.

## Use Cases

### Vendor Risk Auditing
A procurement officer wants to know if a new vendor is safe. They ask the agent to list vendors and check the security score of a specific one using get_vendor.

### Incident Triage
A security analyst needs to find out why an alert fired. They ask the agent to list all active account risks and filter for the most recent ones.

### Infrastructure Inventory
An IT manager wants to see if they are missing any domains. They ask the agent to list all monitored domains and compare it to their records.

### Employee Breach Response
A CISO wants a summary of employee risks. They ask the agent to find identity breaches and list the affected users.

## Benefits

- Quickly assess vendor health by using list_vendors to see who is on your list and get_vendor to see their specific scores.
- Identify infrastructure gaps by using list_monitored_ips and list_monitored_domains to see exactly what is exposed.
- Stop identity theft in its tracks by using list_identity_breaches to see which employees are currently targeted.
- Prioritize your daily tasks by using list_account_risks to see what needs fixing right now.
- Audit your SaaS footprint using list_saas_apps to ensure no shadow IT is slipping through the cracks.
- Protect your staff by using list_user_risks to pinpoint which accounts need a password reset or MFA check.

## How It Works

The bottom line is that you get a conversational way to query your UpGuard data without leaving your AI client.

1. Subscribe to the Connector and grab your API key from your UpGuard account settings.
2. Plug that key into your AI client configuration.
3. Ask your agent to list risks, check vendors, or audit your domain footprint.

## Frequently Asked Questions

**How does the UpGuard MCP help with vendor risk?**
It lets you query your vendor security scores and risk levels through a conversation. You can quickly identify which partners are falling behind on security standards without manually clicking through the UpGuard dashboard.

**Can I use the UpGuard MCP to see my own security risks?**
Yes. You can ask your agent to list all active risks on your account, including infrastructure vulnerabilities and identity breaches, to get a real-time view of your security posture.

**How do I find out which employees are affected by breaches?**
The Connector can retrieve data on identity breaches affecting your workforce. You can ask your agent to list these breaches and see which specific users are impacted so you can take action.

**Can the UpGuard MCP list my monitored domains?**
Yes, it can pull a full list of the domains you have set up for monitoring. This helps you maintain visibility over your organization's digital footprint and attack surface.

**Is the UpGuard MCP good for procurement teams?**
It is ideal for procurement. It allows teams to quickly verify the security scores of new software vendors and monitor the risk profiles of existing third-party partners during the contract process.

**What happens when I ask about my attack surface?**
Your agent will query the Connector to pull data on your monitored IP ranges, domains, and SaaS applications. It then summarizes this information to show you exactly what parts of your infrastructure are currently visible.

**How do I check the security score of a specific vendor?**
Use the `get_vendor` tool and provide the Vendor ID. Your agent will retrieve the complete security profile, including the overall score and metadata for that vendor.

**Can I see all active risks across my entire account?**
Yes! Use the `list_account_risks` query. This retrieves all active security risks detected across your own digital infrastructure (BreachSight).

**Is it possible to monitor data breaches affecting our employees?**
Absolutely. Use the `list_identity_breaches` query to retrieve data on identity breaches affecting your workforce, helping you take proactive security measures.