Compatible with every major AI agent and IDE
What is the Beagle Security MCP Server?
Connect your Beagle Security account to any AI agent and take full control of your automated cybersecurity audits and web application penetration testing through natural conversation.
What you can do
- Pentest Orchestration — Programmatically trigger high-fidelity penetration tests for your configured web applications and APIs directly through your agent
- Real-Time Monitoring — Monitor the progress and status of active security tests and retrieve real-time alerts for identified threats
- Vulnerability Intelligence — Access complete high-fidelity vulnerability reports in JSON format and retrieve detailed metadata for every security session
- Application Architecture — List and manage your directory of security projects and applications to maintain a perfectly coordinated audit infrastructure
- Audit Compliance — Access historical records of all past test results and monitor currently running tests to ensure constant security oversight
How it works
- Subscribe to this server
- Retrieve your Access Token (User Settings) and Application Token (Project Settings) from the Beagle Security dashboard
- Start orchestrating your cybersecurity defenses from Claude, Cursor, or any MCP client
No more manual toggling between security scanners or digging through fragmented audit reports. Your AI acts as your dedicated security engineer and penetration testing coordinator.
Who is this for?
- Security Engineers — instantly trigger regression tests and analyze vulnerability patterns using natural language commands
- DevOps Teams — verify application security after a deployment and monitor API health without leaving your workspace
- CISOs & IT Leads — automate the oversight of organization-wide security posture through simple AI queries
Built-in capabilities (9)
Get details of the current application
List all currently running tests
Get full test result (JSON)
List all test sessions
Get current test status
List all applications
List all security projects
Start a new security test
Stop a running security test
Why Windsurf?
Windsurf's Cascade agent chains multiple Beagle Security tool calls autonomously. query data, analyze results, and generate code in a single agentic session. Paste Vinkius Edge URL, reload, and all 9 tools are immediately available. Real-time tool feedback appears inline, so you see API responses directly in your editor.
- —
Windsurf's Cascade agent autonomously chains multiple tool calls in sequence, solving complex multi-step tasks without manual intervention
- —
Purpose-built for agentic workflows. Cascade understands context across your entire codebase and integrates MCP tools natively
- —
JSON-based configuration means zero code changes: paste a URL, reload, and all 9 tools are immediately available
- —
Real-time tool feedback is displayed inline, so you see API responses directly in your editor without switching contexts
Beagle Security in Windsurf
Beagle Security and 4,000+ other MCP servers. One platform. One governance layer.
Teams that connect Beagle Security to Windsurf through Vinkius don't need to source, host, or maintain individual MCP servers. Every tool call runs inside a hardened runtime with credential isolation, DLP, and a signed audit chain.
Raw MCP | Vinkius | |
|---|---|---|
| Server catalog | Find and host yourself | 4,000+ managed |
| Infrastructure | Self-hosted | Sandboxed V8 isolates |
| Credential handling | Plaintext in config | Vault + runtime injection |
| Data loss prevention | None | Configurable DLP policies |
| Kill switch | None | Global instant shutdown |
| Financial circuit breakers | None | Per-server limits + alerts |
| Audit trail | None | Ed25519 signed logs |
| SIEM log streaming | None | Splunk, Datadog, Webhook |
| Honeytokens | None | Canary alerts on leak |
| Custom domains | Not applicable | DNS challenge verified |
| GDPR compliance | Manual effort | Automated purge + export |
Why teams choose Vinkius for Beagle Security in Windsurf
The Beagle Security MCP Server runs on Vinkius-managed infrastructure inside AWS — a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts. All 9 tools execute in hardened sandboxes optimized for native MCP execution.
Your AI agents in Windsurf only access the data you authorize, with DLP that blocks sensitive information from ever reaching the model, kill switch for instant shutdown, and up to 60% token savings. Enterprise-grade infrastructure, zero maintenance.

* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure
How Vinkius secures
Beagle Security for Windsurf
Every tool call from Windsurf to the Beagle Security MCP Server is protected by DLP redaction, cryptographic audit chains, V8 sandbox isolation, kill switch, and financial circuit breakers.
Frequently asked questions
How do I find my Beagle Access and Application Tokens?
Log in to Beagle Security. find the Access Token in your profile/user settings, and the Application Token in the settings of the specific project you want to test.
Can I stop a running test via AI?
Yes! The stop_test tool allows your agent to immediately terminate an active penetration test for the configured application.
How do I retrieve the vulnerability report?
First use get_test_sessions to identify the test's resultToken, then pass that token to get_test_result to retrieve the high-fidelity JSON report.
How does Windsurf discover MCP tools?
Windsurf reads the mcp_config.json file on startup and connects to each configured server via Streamable HTTP. Tools are listed in the MCP panel and available to Cascade automatically.
Can Cascade chain multiple MCP tool calls?
Yes. Cascade is an agentic system. it can plan and execute multi-step workflows, calling several tools in sequence to accomplish complex tasks without manual prompting between steps.
Does Windsurf support multiple MCP servers?
Yes. Add as many servers as needed in mcp_config.json. Each server's tools appear in the MCP panel and Cascade can use tools from different servers in a single flow.
Server not connecting
Check Settings → MCP for the server status. Try toggling it off and on.
Explore More MCP Servers
View all →
vCard Contacts Parser Extended
1 toolsInstantly convert massive iPhone and Android `.vcf` contact exports into structured JSON. Turn your AI into a hyper-intelligent local address book.

Honeycomb
12 toolsAutomate observability via Honeycomb — manage datasets, queries, and markers directly from any AI agent.

Coder (Remote Dev)
84 toolsManage Coder remote development environments, monitor deployment stats, and interact with AI Bridge sessions directly from your AI agent.

Albacross
8 toolsB2B intent and reveal intelligence — identify anonymous website visitors and manage leads via AI.
