Skip to content

5,800+ managed connectors and growing

Vinkius

Rapid7 InsightVM MCP, Ready to Go

Connect your AI agents to Rapid7 InsightVM to query CVEs, list assets, and trigger scans in Claude or Cursor. Get faster security insights.

See All Capabilities

No credit card required. Experience the power of this integration risk-free.

Manage your vulnerability scans and asset inventory from your favorite workspace.

Rapid7 InsightVM MCP for AI Agents

Works with every AI agent you already use

…and any MCP-compatible client

Cursor AI Code EditorClaude Desktop AppOpenAI Agents SDKVisual Studio CodeGitHub Copilot AI AgentGoogle Gemini AILovable AI DevelopmentMistral AI AgentsAmazon AWS Bedrock

How fast is the Rapid7 InsightVM Connector?

948ms Fast
Fast Acceptable Slow

Average time for the server to become ready for requests over the last 14 days, measured until the initialize / tools/list handshake completes. Metrics are updated daily between 00:00 and 04:00 UTC. Create a free account, use this Connector on Vinkius Cloud, and connect it to your AI agent in seconds.

Min 848ms
Average 948ms
Max 1497ms
Trend (improving) ↓ 7%
Daily latency
1497ms 7/12/2026
938ms 7/13/2026
937ms 7/14/2026
984ms 7/15/2026
1121ms 7/16/2026
848ms 7/17/2026
903ms 7/18/2026
983ms 7/19/2026
920ms 7/20/2026
887ms 7/21/2026
901ms 7/22/2026
1072ms 7/23/2026
1050ms 7/24/2026
923ms 7/25/2026
7/12/2026 7/25/2026

Waiting for input…

AI Agent

What AI agents can do with Rapid7 InsightVM 10-Tool Vulnerability Management

Use these 10 tools to query assets, check CVEs, and trigger scans in your Rapid7 InsightVM environment.

Get site

Get the configuration details for a specific network site. This helps you review scanning scopes quickly.

Get vulnerability

Pull the full details and advisories for a specific vulnerability ID. Use this to find remediation steps.

List assets

Get a full list of all computing assets currently discovered on your network. This builds a clear inventory.

List scans

See a chronological list of all assessment scans performed. Use this to track recent activity.

List sites

List all the network scan sites currently configured in your console. This helps you audit your coverage.

List vulnerabilities

View the global definitions for vulnerabilities in your environment. This gives you a broad view of risks.

Trigger scan

Force an immediate vulnerability scan on a specific network site. This validates your recent fixes.

Get asset

Retrieve detailed hardware and OS information for a specific asset. Use this to identify old hardware.

Get asset vulnerabilities

See every vulnerability found on a specific piece of hardware. This helps you prioritize what to fix first.

Get scan

Check the current execution status and results of a specific scan. This lets you know when data is ready.

A Connector is a URL. Vinkius runs it: hosting, security, governance, observability.

You're looking at one of 5,800+ managed Connectors. The real value isn't the catalog. It's the control plane that secures, governs, audits, and manages every interaction between your agents and the tools they use.

01

No Shadow AI

Every agent action is visible, approved, and auditable. Nothing runs outside your governance.

02

Absolute agent control

Fine-grained permissions for every agent, MCP, and tool. Instantly revoke access and audit every execution.

03

Cost control per token

Spend broken down to the token, tool, and agent. Budgets and hard limits. No surprise invoices.

04

Managed & monitored infra

We operate the runtime, authentication, scaling, retries, and monitoring. Your team manages AI, not infrastructure.

05

Data protection, DLP by design

Sensitive data is filtered before reaching the model. Access is governed so agents receive only the information they're allowed to use.

06

Token optimization, real savings

Lower AI costs by delivering the right context instead of unnecessary tools. Better accuracy, faster responses, and fewer wasted tokens.

Rapid7 InsightVM Vulnerability Management for AI Agents

SOC analysts who need to move fast during an incident, DevOps engineers verifying patches, and network admins ensuring scan coverage.

SOC Analyst

Investigating a high-severity alert and pulling CVE details instantly to see if a patch is available.

DevOps Engineer

Verifying that a recent OS update actually closed the security holes on a group of production servers.

Network Engineer

Checking if a new subnet is correctly included in the scanning scope when provisioning new hardware.

Frequently Asked Questions

How can the Rapid7 InsightVM MCP help my security team? +

It lets your team query vulnerabilities and asset data using natural language. Instead of clicking through a complex dashboard, your team can just ask your AI for specific info like 'what's wrong with this server?'

Can I use the Rapid7 InsightVM MCP to start new scans? +

Yes, you can tell your AI agent to trigger a new vulnerability scan on a specific site immediately. This is great for verifying that a patch you just deployed actually worked.

Does the Rapid7 InsightVM MCP work with my existing Nexpose data? +

Yes, it connects directly to your Rapid7 InsightVM platform. It can read your existing asset lists, site configs, and scan histories.

Can the AI agent see which assets are on my network? +

Yes, it can pull a full inventory of all discovered computing assets. It can even show you specific details like hardware info and operating system fingerprints.

Is it possible to get remediation steps for specific flaws? +

Yes, you can ask the agent for details on a specific vulnerability. It will pull the full advisory and remediation guidelines directly from your Rapid7 environment.

How do I connect my Rapid7 InsightVM to my AI client? +

You'll need to provide your Security Console URL and your Basic Auth credentials. Once that's set up, your agent can start querying your security data.

How do I configure my credentials for Rapid7? +

The integration uses Basic Authentication interacting with the Rapid7 Console API. You must configure the RAPID7_HOST (IP or FQDN), RAPID7_PORT (usually 3780), along with a dedicated RAPID7_USER and RAPID7_PASSWORD. We strongly recommend generating a specific service account in your console with restricted scan permissions.

Is the scanning triggered individually per asset? +

By default, the trigger_scan mechanism relies on referencing a defined site_id, scanning the preconfigured scope attached to it rather than blindly scanning one unassociated IP.

Does it report CVSS scores? +

Yes, depending on the response data provided by your installed version of the InsightVM console. Using get_vulnerability or checking asset lists brings standard threat metadata and corresponding CVSS vectors directly into your AI interface context.

Your AI, connected to everything.

No credit card required · Free tier available

Other Connectors in this category

Related Connectors