Truss Agent
FreeNot checkedAn MCP server that provides Truss threat intelligence capabilities, enabling natural language search, FilterQL filtering, and querying of threat data, along wit
About
An MCP server that provides Truss threat intelligence capabilities, enabling natural language search, FilterQL filtering, and querying of threat data, along with STIX export and detection rule generation.
README
Truss threat intelligence via Model Context Protocol and a terminal assistant — one binary: truss-mcp.
Two surfaces
| Surface | Use for | Auth |
|---|---|---|
| Remote (recommended) | Cursor, Claude Desktop, MCP registries | OAuth → https://api.truss-security.com/mcp |
| Local stdio (legacy) | Air-gap / BYO-key / FilterQL REPL tools | TRUSS_API_KEY → REST |
Hosted MCP (OAuth, Growth+ gate, five tools) is served by the Truss API. This package ships configs, validate-remote / doctor --remote, CLI search, and optional local stdio. Community accounts cannot consent to hosted MCP.
Not on npm yet. Install from this repo (
npm install -g .). After publish:npm install -g @truss-security/truss-agent-mcp.
Quick start
cd truss-agent-mcp
npm install && npm run build
npm install -g .
truss-mcp doctor --remote --strict-oauth # OAuth path hosts use
truss-mcp init # for CLI search / legacy stdio
truss-mcp search
Node.js 18+. Binary name truss-mcp avoids conflict with @truss-security/truss-sdk's truss command.
What you can run
| Command | What it does |
|---|---|
truss-mcp search |
Guided REPL with live MCP tools (local stdio or remote OAuth token) |
truss-mcp mcp |
Local stdio MCP server (legacy / air-gap) |
truss-mcp init |
Interactive .env setup |
truss-mcp doctor |
Validate keys and API access; --remote runs hosted OAuth doctor |
truss-mcp validate-remote <url> |
OAuth + MCP doctor (discovery, DCR, PKCE, tools) |
truss-mcp help |
Usage summary |
Guided search workflow
One REPL with MCP tools always connected. The assistant classifies your intent and asks before querying Truss API:
- Knowledge — Truss platform, cyber security context, threat background
- Build filter — draft FilterQL, validate, confirm
- Query —
runexecutes confirmed filter (default 7 days) - Format —
stixfor STIX export; JSON summaries in-thread - Detection rules —
detect splunk,detect falcon,detect cortexfrom search results
The assistant offers next steps explicitly: build a filter, refine it, query Truss API, export JSON/STIX, or generate SIEM/EDR hunting queries.
- Wider windows (
run 30,days 30) may use more API quota - Context-only follow-ups (IOC dedupe, reformat) use thread history without re-querying
Full REPL reference: guides/truss-cli.md
Terminal display (REPL)
truss-mcp search uses color-coded, ASCII-bordered output:
- You — your message
- MCP — live tool trace (
→ search_threatson remote, or→ search_productson stdio) - Results — structured product table before the assistant summary
- Truss — assistant reply (cyan), guided offers (yellow), FilterQL blocks (magenta)
Controls: color / color on / color off / color auto · env TRUSS_MCP_COLOR · standard NO_COLOR=1
MCP host (Cursor / Claude) — remote OAuth (recommended)
No API key in host config. Growth+ Truss account; browser OAuth consent.
{
"mcpServers": {
"truss-mcp": {
"url": "https://api.truss-security.com/mcp"
}
}
}
Samples: config/cursor.mcp.json · config/claude_desktop_config.json · guides/client-setup-cursor.md.
Legacy stdio (air-gap)
{
"mcpServers": {
"truss-mcp": {
"command": "truss-mcp",
"args": ["mcp"],
"env": { "TRUSS_API_KEY": "YOUR_KEY" }
}
}
}
See config/cursor.mcp.stdio.json and guides/getting-started.md.
Remote MCP OAuth validation (registry gate)
Use as the OAuth + MCP doctor before registry publish or release. After OAuth it requires search_threats to return at least one Truss product (id + title). The access token stays in memory for that process only unless you pass --save-token.
truss-mcp doctor --remote --strict-oauth
# or:
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth
After token exchange it prints an OAuth compatibility checklist (resource URI, redirects, PKCE S256, issuer match, audience vs MCP resource, truss_role), then proves MCP access with real Truss data.
Options:
truss-mcp validate-remote https://api.truss-security.com/mcp --verbose
truss-mcp validate-remote https://api.truss-security.com/mcp --strict-oauth
truss-mcp validate-remote https://api.truss-security.com/mcp --save-token /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --token-file /tmp/truss-mcp-token
truss-mcp validate-remote https://api.truss-security.com/mcp --port 9877
truss-mcp validate-remote https://api.truss-security.com/mcp --no-open
--verbose— HTTP statuses, key headers, truncated bodies (tokens redacted)--strict-oauth— exit2if the OAuth checklist has WARN/FAIL (even when Truss MCP calls succeed)--save-token PATH— write the access token for local replay (mode0600; delete after debugging)--token-file PATH— skip browser OAuth; reuse a saved token to re-check MCP access + Truss data
Optional automated OAuth data tests (saved token + TRUSS_RUN_MCP_OAUTH=1) are documented in guides/publishing.md.
Official listing: server.json (com.truss-security/truss-mcp) · Tracker: guides/registry-submission.md · Internal metadata: config/mcp-registry.json · Architecture: docs/05-hosted-mcp-oauth-architecture.md
Configuration
Env load order (shell vars win): ~/.config/truss/env → ~/.truss/.env → ./.env
| Variable | Required for | Notes |
|---|---|---|
TRUSS_API_KEY |
local mcp / stdio search |
From Truss dashboard (legacy air-gap only) |
TRUSS_MCP_URL |
remote search / doctor |
Default https://api.truss-security.com/mcp |
TRUSS_MCP_OAUTH_TOKEN_FILE |
remote search |
Bearer token from validate-remote --save-token |
LLM_PROVIDER |
search | anthropic or openai — set via init |
LLM_MODEL |
search | Set via init |
ANTHROPIC_API_KEY / OPENAI_API_KEY |
search | Per provider |
Full list: env.example
Documentation
Guides — install, REPL, MCP clients, FilterQL examples
Reference — API contract, tools, architecture (docs/README.md — docs 01–06)
Development
npm install && npm run build
npm test
npm run truss:search # from source without global install
Contributors / AI agents: see AGENTS.md for repo operations and conventions.
Publish: guides/publishing.md · Changes: CHANGELOG.md
Related
- @truss-security/truss-sdk — API client
- truss-agent — scheduled webhook delivery
- Truss docs — public API / SDK documentation
MIT
Install Truss Agent in Claude Desktop, Claude Code & Cursor
unyly install truss-agent-mcpInstalls into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.
First time? Get the CLI: curl -fsSL https://unyly.org/install | sh
Or configure manually
Run in your terminal:
claude mcp add truss-agent-mcp -- npx -y github:truss-security/truss-agent-mcpStep-by-step: how to install Truss Agent
FAQ
Is Truss Agent MCP free?
Yes, Truss Agent MCP is free — one-click install via Unyly at no cost.
Does Truss Agent need an API key?
No, Truss Agent runs without API keys or environment variables.
Is Truss Agent hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Truss Agent in Claude Desktop, Claude Code or Cursor?
Open Truss Agent on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
by modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
by xuzexin-hzCompare Truss Agent with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All ai MCPs
