# Security MCP connectors for Claude, ChatGPT and Cursor

10+ Security connectors in the Elaichi catalog, each callable through https://api.elaichi.ai/mcp once connected, under the same roles, restrictions and audit log as the rest of the catalog.

Source: https://elaichi.ai/connectors/category/security/

| | |
| --- | --- |
| Category | Security |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |

## Security connectors

- [Censys](https://elaichi.ai/connectors/censys/) — 47 tools · hosted sign-in
- [Herd Security](https://elaichi.ai/connectors/herdsecurity/) — 4 tools · hosted sign-in
- [Infisical](https://elaichi.ai/connectors/infisical/) — 352 tools · hosted sign-in
- [Orca Security](https://elaichi.ai/connectors/orcasecurity/) — 40 tools · hosted sign-in
- [SecurityScorecard](https://elaichi.ai/connectors/securityscorecard/) — 405 tools · hosted sign-in
- [Semgrep](https://elaichi.ai/connectors/semgrep/) — 208 tools · hosted sign-in
- [Strac](https://elaichi.ai/connectors/strac/) — 27 tools · hosted sign-in
- [The Auth API](https://elaichi.ai/connectors/theauthapi/) — 57 tools · hosted sign-in
- [UniFi On Prem](https://elaichi.ai/connectors/unifionprem/) — 109 tools · hosted sign-in
- [VirusTotal](https://elaichi.ai/connectors/virustotal/) — 150 tools · hosted sign-in
- [Wiz](https://elaichi.ai/connectors/wiz/) — 18 tools · hosted sign-in

## What teams do with Security connectors

### Security

- **Add new vendors to the right portfolio** (SecurityScorecard) — After a contract is signed, add the vendor to the correct SecurityScorecard portfolio, tag it by business unit and criticality, and move on without opening a spreadsheet.
- **Review every app connection in one pass** (Infisical) — Ask for a list of the 1Password, Auth0, and AWS app connections in Infisical, who they belong to, and which ones look unused, without clicking through each one.
- **Triage new findings before standup** (Semgrep) — Ask for the Semgrep findings that appeared overnight, grouped by severity and repository, and mark the ones that are already handled as resolved in one pass.

### Compliance

- **Check coverage across cloud accounts** (Orca Security) — List every connected AWS and GCP account in Orca Security, see which are scanned, and spot the ones with outstanding remediation before an audit.
- **Redact personal details from a document** (Strac) — Run a redaction on a Strac document and pull back the redacted copy by ID, ready to send outside the company. The original stays untouched for the record.
- **Gather evidence for the audit** (Wiz) — Collect the backup findings, firewall findings and infrastructure logging findings for a project into one summary that maps to the control you are being asked about.

### IT

- **Move a whole team to phone entry** (UniFi On Prem) — Batch assign touch passes to a department's UniFi On Prem users in one go instead of handling each person individually.
- **Fix a locked out teammate fast** (The Auth API) — Find the deactivated access key behind a failing login and reactivate it, or update the user role that is missing, while the person is still on the call.
- **Confirm new hires appear in Herd Security** (Herd Security) — Pull the Herd Security user list after a batch of new starters and compare it against the accounts you provisioned that week.

### Engineering

- **Bootstrap a fresh Infisical instance** (Infisical) — Run the admin bootstrap for a new self-hosted Infisical instance and confirm the first app connections are in place before the rest of the team signs in.
- **Understand an issue before fixing it** (Semgrep) — Pull up a single Semgrep issue by its ID, read the rule that flagged it and the line it points at, and get a plain explanation of why it matters before opening the file.
- **Spin up a project with its keys** (The Auth API) — Create a new The Auth API project for a service, add the access keys it needs, and hand the details to the team without opening the console.

## Things to ask once it is connected

- "Show new Censys hosts added in the last week." (Censys)
- "Which users have open Herd Security enrollments this month?" (Herd Security)
- "List app connections created in Infisical this month." (Infisical)
- "Show high severity Orca Security alerts opened this week." (Orca Security)
- "List the lowest scoring companies in our vendor portfolio." (SecurityScorecard)
- "List open Semgrep findings for the platform deployment." (Semgrep)
- "Which Strac detections fired on documents uploaded this week?" (Strac)
- "List access keys created in the last 7 days." (The Auth API)

## What an agent can call in Security

1417 tools across the category. 11 of these connectors use hosted sign-in with nothing to register first; 0 ask you to bring your own OAuth app.

## Frequently asked questions

### How many Security connectors does Elaichi have?

10+ Security connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.

### Can Claude, ChatGPT and Cursor all use Security connectors?

Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor, any MCP client and the Elaichi Agent all connect to that same address with OAuth. Connecting a Security account once makes it reachable from every one of them.

### Do Security connectors work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Security connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.

### Do Security connectors need me to bring my own OAuth app?

No. Every Security connector in the catalog connects through Elaichi's hosted sign-in, so there is nothing to register before you start.

### Can I stop an agent from writing to Security tools?

Yes. Tool restrictions apply at role and individual level, and a restricted tool is never advertised to the model, so it cannot be called or guessed at from the tool list. Read-only access to a Security connector is a matter of allowing the reads and leaving the writes out.

### Whose access does an agent get on a shared Security connection?

The access of the person the agent is acting for, resolved against their current role on every call — not the access of whoever connected the account. A colleague can use a connection without ever seeing its credential.

## Related categories

- [Compliance](https://elaichi.ai/connectors/category/compliance/)
- [SSO](https://elaichi.ai/connectors/category/sso/)
- [Device Management](https://elaichi.ai/connectors/category/device-management/)

[Browse the full connector catalog](https://elaichi.ai/connectors/)
