Skip to content
MCP server

aribot-mcp

By ayurakAll Ayurak servers

Threat modeling, code, API & cloud security, shadow-AI & compliance governance.

First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.

1
Directories
Collected by InvokeRank
18
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
-
GitHub stars
No repository data

Tools

ToolDescriptionBehaviour
apply_remediationApply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.Destructive
code_review_scanStart (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.Changes data
compliance_scanRun a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.Changes data
compliance_statusCompany-level compliance posture rollup across all frameworks (EU AI Act, DORA, NIST, ISO, SOC 2) suitable for CI gates and executive reporting.Read-only
discover_shadow_aiScan connected repositories and network traffic for unmanaged LLMs, foundational model endpoints, vector databases, agent frameworks, and leaked API keys (async).Changes data
generate_architectureGenerate a multi-tier cloud/AI architecture and auto-synthesize STRIDE/LINDDUN threat models, security requirements, and regulatory control mappings directly from a natural-language description.Changes data
generate_threat_modelCreate a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.Changes data
get_api_securityAPI security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Company-wide or one scan with `scan_id`. Reads code_review ApiEndpointDiscovery.Not declared
get_billingBilling status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasable plans, and any approved-but-unpaid plans. Pass `checkout_request_id` to get a hosted Stripe Checkout URL to COMPLETE an approved plan, `topup_amount` (EUR) to get one to TOP UP the wallet, or `request_plan` (starter|pay_per_use|pro|max|enterprise) to REQUEST a plan (files a request for super-admin approval — never grants). Use this to view or RESOLVE a 402 without leaving the connector.Not declared
get_cloud_complianceCloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Account.latest_scan -> compliances.ScanResults.Not declared
get_diagram_summaryThe canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.Read-only
get_framework_coverageGet real ControlCodeMap-backed coverage percentages, gap counts, and mapped controls for EU AI Act, DORA, NIST AI RMF, ISO 27001, SOC 2, etc.Read-only
get_insightsThreat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.Read-only
get_remediationCompute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.Read-only
get_traceabilityReturn the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.Read-only
onboard_agentsBulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cards` (name/url/provider/version/protocolVersion), or MCP client descriptors, under an optional `cohort` + shared auto-suspend policy. Idempotent. Requires the agent_governance licence + a manage:agents grant (or a first-party super-admin). Agents also self-onboard on first token/call.Not declared
run_ai_governance_auditAudit an architecture diagram or code scan against statutory AI governance frameworks (EU AI Act 2024, EU DORA 2022, NIST AI RMF 1.0, ISO 42001). Evaluates article-by-article conformity, satisfied controls, open gaps, and generates actionable remediation guidance.Read-only
verify_threats_in_codeVerify whether modelled STRIDE/LINDDUN threats are mitigated in a scan's uploaded code or AST. If threat_id is provided, returns synchronous verdict; otherwise dispatches batch verification across all diagram threats.Read-only

Directory listings

DirectoryListingTierFirst seen
Official MCP Registrycom.ayurak/aribot-mcp-2 Oct 2026