Skip to content

Intruder MCP connector

Connect Intruder to Elaichi and Claude, ChatGPT, Cursor or any MCP client can list targets, review open issues, start scans and manage scan schedules inside the Intruder access that was connected, with every call logged.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Intruder to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Intruder once

  1. Open Connections, choose Add connection, and pick Intruder.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste an Intruder API key. One person generates a token in Intruder and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

intruder
Intruder
Censys
Herd Security
Infisical
Orca Security
SecurityScorecard
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Intruder MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Intruder MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Intruder MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Intruder to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Intruder through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Security

    Get a morning read on open issues

    Ask which Intruder issues are still open, where each one occurs and what the scanner actually found, then leave a comment on the occurrence so the next person knows where it stands.

  • IT

    Add new servers as targets

    When a batch of new hosts goes live, add them to Intruder as targets in one go, tag them, and confirm the license has room for them.

  • Engineering

    Kick off a scan after a release

    Once a deploy lands, start an Intruder scan on the affected targets, check its progress, and cancel it if the release is rolled back.

  • Compliance

    Show what was fixed this quarter

    Pull the Intruder occurrences marked fixed in a date range and turn them into the evidence an auditor asks for, without exporting anything by hand.

  • Security

    Keep scan schedules current

    List every Intruder scan schedule, change the ones that cover retired targets, and remove the schedules nobody needs anymore.

  • AppSec

    Register API schemas for new services

    Attach an API schema to an Intruder target so the next scan covers the endpoints a new service exposes, and remove schemas for services that were shut down.

Try asking

  • “Which Intruder issues are still open on our production targets?”
  • “Start a scan of the new web servers we added yesterday.”
  • “What did we fix in Intruder over the last thirty days?”

See all 31 Intruder tools below

AI tools

Intruder tools for your AI agents

31 tools are ready to call through Elaichi's MCP endpoint the moment you connect Intruder, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Intruder gets you

6 screens from the product, each doing one job for your Intruder account.

The agent

Ask about open issues, get live answers.

Type a question in plain language and get Intruder issues, targets and scans back.

  • targets
  • scans
  • issues
  • schedules

Ask Elaichi to work across your apps.

Which Intruder issues are still open on our production targets?

Start a scan of the new web servers we added yesterday.

What did we fix in Intruder over the last thirty days?

Also runs in Claude, ChatGPT or Cursor

MCP clients

One endpoint puts Intruder in every client.

Claude, ChatGPT and Cursor all connect over OAuth, with no SDK and no shared key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

All 31 Intruder tools, no code needed.

Targets, scans, issues, schedules and API schemas, ready without writing a line of code.

  • List all Intruder health
  • List all Intruder issue occurrences
  • List all Intruder issues
  • Create a Intruder scan
ElaichiTools
Tool Action Description
List all Intruder health List Check that the Intruder API is running normally. Returns: status, authenticated_as, openapi, info, paths, components, servers.
List all Intruder issue occurrences List List occurrences for an issue in Intruder. Returns: id, occurrence_id, target, display_address, port, protocol, extra_info, age, snoozed, snooze_reason, snooze_until, exploit_likelihood, cvss_score, first_seen_at, target_last_scanned_at, cves. Required: issue_id. occurrence_id is the stable ID that persists across scans; id may change between scans.
List all Intruder issues List List current issues in Intruder, with filters for severity, snoozing, tags, target addresses, and new occurrences since a timestamp. Returns: id, severity, title, description, remediation, snoozed, snooze_reason, snooze_until, occurrences, exploit_likelihood, cvss_score.
Create a Intruder scan Create Start a scan in Intruder. Returns the created scan including its id, status, scan_type, created_at, target_addresses, and start_time. Optionally pass target_addresses and/or tag_names in the body — with no body it scans all targets. Max 500 active and scheduled scans.
List all Intruder scans List List current scans in Intruder. Returns scan records including id, status, scan_type, schedule_period, and created_at; filter by scan_type, status, schedule_period, or tag_names.

Toolboxes

Each team gets its own Intruder toolbox.

Security triages issues, IT manages targets, engineering starts scans, each from a scoped toolbox.

  • Security
  • IT
  • Engineering
  • AppSec
ElaichiToolboxes
Name Source template Tools Created

Security toolbox

Intruder · issues and scans

Intruder starter 18 Mar 4, 2026

IT toolbox

Intruder · targets and schedules

— 9 Mar 2, 2026

Engineering toolbox

Intruder · scans after releases

— 24 Feb 27, 2026

AppSec toolbox

Intruder · API schemas and targets

Intruder starter 6 Feb 19, 2026

Compliance toolbox

Intruder · fixed occurrences and scanner output

— 31 Jan 30, 2026

Leadership toolbox

Intruder · licenses and health

— 12 Jan 22, 2026

Shared connections

Share Intruder access, never the API key.

One person connects Intruder, teams work through it, and nobody else sees the credential.

  • Security
  • IT operations
  • Platform engineering
  • AppSec
ElaichiConnections
Connection Scope Status Access
IN

Intruder (Security)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
IN

Intruder (IT operations)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
IN

Intruder (Platform engineering)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
IN

Intruder (AppSec)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
IN

Intruder (Compliance)

Connected by Clara Nowak

Personal • Active Not shared
IN

Intruder (Production)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Every Intruder action is on the record.

See who started a scan, added a target or removed a schedule, and when.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

Intruder Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

Intruder Targets Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

Intruder Targets List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule fires, the digest ships itself.

New Intruder issues are fetched, grouped, drafted into a digest, approved, then posted back.

Intruder digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. ✓

    Schedule

    Every weekday at 08:00

    0.2s
  2. ✓

    Fetch targets

    Intruder

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Intruder

    Queued

Collections and dashboards

Intruder scan health, counted without a model.

Four metrics, 14 days of scans created and a team breakdown, refreshed on a schedule.

Intruder health

Refreshed 4 minutes ago · every 15 minutes · from the targets collection

Live

Targets

1,284 ↓ 12%

Scans

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Targets created

Last 14 days

By team

Share of activity

Security 34%

IT operations 27%

Platform engineering 21%

AppSec 18%

FAQ

Frequently asked questions

How do I connect Intruder to Claude?

In Elaichi, choose Intruder and paste in your Intruder API key. Then open Claude, go to Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. There is no OAuth application to register and no client ID or secret to generate, so the whole thing takes a few minutes.

Does Intruder work with ChatGPT and Cursor as well as Claude?

Yes. Intruder is connected once in Elaichi, and the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. Nothing is set up separately for each client.

What can an AI agent actually do with my Intruder data?

An agent can list your Intruder targets, scans and open issues, show where each issue occurs and what the scanner output said, and read or add comments on an occurrence. It can also start or cancel a scan, add or remove targets, manage scan schedules and API schemas, and check licenses and health. Short, specific asks such as open issues on production targets work better than long sentences.

Does connecting Intruder give the AI access to every target and scan?

Access follows the Intruder API key that was connected, so the AI sees the targets, issues and scans that key can see and nothing more. Elaichi can narrow that further for each team, for example read-only on issues, but it can never widen what the key already allows.

Can my team share one Intruder connection?

Yes. One person connects Intruder in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so the audit log names the person who started a scan or added a target, not the connection.

Can I stop an agent from deleting targets or changing scan schedules in Intruder?

Yes. Restrictions in Elaichi apply per action, so you can allow listing Intruder issues and scans while blocking target deletion or schedule changes. A restricted action is never advertised to the AI client at all, so no prompt can reach it.

What happens to an Intruder connection when someone leaves?

Offboarding a person in Elaichi ends their access to Intruder at once, across every client they used. A shared Intruder connection keeps working for everyone else on the team. If you disconnect Intruder in Elaichi, it is removed from Claude, ChatGPT, Cursor and every other client in one step.

Does the Intruder MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Intruder is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Put Intruder in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.