Skip to content

Connectors / Security

Security MCP connectors for Claude, ChatGPT and Cursor

10+ Security connectors in the catalog, each behind the same governed MCP endpoint as everything else in Elaichi.

https://api.elaichi.ai/mcp The same for every user.
  • Their own access. An agent never gets more than the person it acts for.

  • One connection, every client. Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent.

The connectors

Security connectors in the catalog

Connect one and your whole team reaches it, each inside the access they already have, without anyone handling a credential.

14 connectors

Browse all 600+ connectors →

In practice

What teams do with Security connectors

Drawn from the connector pages in this category, so every line describes something one of these connectors actually does.

Security

  • Add new vendors to the right portfolio

    After a contract is signed, add the vendor to the correct SecurityScorecard portfolio, tag it by business unit and criticality, and move on without opening a spreadsheet.

  • Review every app connection in one pass

    Ask for a list of the 1Password, Auth0, and AWS app connections in Infisical, who they belong to, and which ones look unused, without clicking through each one.

  • Check which cards are active right now

    Ask for every active Kisi card and who it is assigned to, then spot the contractor badge that should have been switched off weeks ago.

Compliance

  • Report open issues by severity

    Search Semgrep issues across a deployment and summarize how many are open, how old they are and which repositories carry the most, ready to paste into an audit response.

  • Check coverage across cloud accounts

    List every connected AWS and GCP account in Orca Security, see which are scanned, and spot the ones with outstanding remediation before an audit.

  • Show what was fixed this quarter

    Pull the Intruder occurrences marked fixed in a date range and turn them into the evidence an auditor asks for, without exporting anything by hand.

IT

  • Move a whole team to phone entry

    Batch assign touch passes to a department's UniFi On Prem users in one go instead of handling each person individually.

  • Fix a locked out teammate fast

    Find the deactivated access key behind a failing login and reactivate it, or update the user role that is missing, while the person is still on the call.

  • Wiz

    Review who has access to Wiz

    List Wiz users and recent audit log entries to confirm that the right people hold access and to spot accounts that should have been removed.

Engineering

  • Redact and detokenize traffic through a proxy

    Set up a Strac proxy so incoming webhooks and outgoing requests are redacted or detokenized on the way through, with a function to shape the payload. No service on either side ever handles the raw values.

  • Check a package before adding it

    Ask for the dependency score of a package and version you are about to install, and hear what pulls the score down before it reaches a pull request.

  • Bootstrap a fresh Infisical instance

    Run the admin bootstrap for a new self-hosted Infisical instance and confirm the first app connections are in place before the rest of the team signs in.

Once it is connected

Things to ask

Each of these is answered against the access the person asking already has, in the Security account you connected.

  • Show new Censys hosts added in the last week.

    Censys

  • Which users have open Herd Security enrollments this month?

    Herd Security

  • List app connections created in Infisical this month.

    Infisical

  • Which Intruder issues are still open on our production targets?

    Intruder

  • Which Kisi cards are still active for contractors who left in March?

    Kisi

  • Show high severity Orca Security alerts opened this week.

    Orca Security

  • List the lowest scoring companies in our vendor portfolio.

    SecurityScorecard

  • List open Semgrep findings for the platform deployment.

    Semgrep

The tools

What an agent can call in Security

Connectors
10+

in the Security catalog

Tools
1,674

callable the moment you connect

Hosted sign-in
1

connect with nothing to register

Of those 1,674 tools, 8% delete something. Restricting an agent to reads is not a promise here, it is 744 tools admitted and the rest left out — and a restricted tool is never advertised to the model at all.

Read 44%
744 tools · list, get, search
Write 24%
407 tools · create, update, send
Delete 8%
140 tools · delete, remove, archive
Other 23%
383 tools · vendor-specific verbs

One endpoint

https://api.elaichi.ai/mcp

Every connector above answers here.

Every Security connector, by depth

Tool counts are what the connector exposes today; the split is what those tools do.

Hosted sign-in takes a partnership with each vendor, and more are in progress. Until one lands, Your own app means the connector works today — you register an OAuth app once and connect. API key and App credentials mean an admin pastes them once, with nothing to register.

Security connectors with tool counts split by read, write and delete
Connector Tools Read · write · delete Sign-in
SecurityScorecard 404 API key
Infisical 343 API key
Kisi 229 API key
Semgrep 208 API key
VirusTotal 150 API key
UniFi On Prem 109 API key
The Auth API 57 API key
Censys 47 API key
Orca Security 40 API key
Intruder 31 API key
Strac 27 API key
Wiz 18 App credentials
Socket 7 Hosted
Herd Security 4 API key

FAQ

Frequently asked questions

How many Security connectors does Elaichi have?

10+ Security connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.

Can Claude, ChatGPT and Cursor all use Security connectors?

Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor or any MCP client connects to that same address with OAuth, while the Elaichi Agent reaches the same tools inside the app. Connecting a Security account once makes it reachable from every one of them.

Do Security connectors work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Security connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.

Do Security connectors need me to bring my own OAuth app?

No. 1 of the Security connectors uses Elaichi's hosted sign-in, with nothing to register. 13 connect with an API key or app credentials that an admin pastes once, with no app to register. Nothing in this category asks you to register an OAuth app before you start.

Can I stop an agent from writing to Security tools?

Yes. Tool restrictions apply at role and individual level, and a restricted tool is left out of the model's tool list and cannot be called. Read-only access to a Security connector is a matter of allowing the reads and leaving the writes out.

Whose access does an agent get on a shared Security connection?

The access of the person the agent is acting for, resolved against their current role on every call — not the access of whoever connected the account. A colleague can use a connection without ever seeing its credential.

Nearby

Teams that connect Security usually connect these too

Put Security connectors in front of your team

14 days on Gold, no credit card. Connect one and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.