# io.github.WYRE-AI/huntress-mcp

MCP server for Huntress — accounts, organizations, agents, incidents, and reports.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.2.21
- **Author:** io.github.WYRE-AI
- **License:** Unknown
- **Source:** https://github.com/WYRE-AI/huntress-mcp

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-25T01:27:15.998Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

37 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `huntress_accounts_get` — Get the Huntress account associated with the current API credentials.
- `huntress_accounts_actor` — Get the current actor (user/account/reseller) for the API credentials.
- `huntress_agents_list` — List Huntress agents with optional filters.
- `huntress_agents_get` — Get a single agent by ID.
- `huntress_billing_reports_list` — List billing reports.
- `huntress_billing_reports_get` — Get billing report by ID.
- `huntress_summary_reports_list` — List summary reports.
- `huntress_summary_reports_get` — Get summary report by ID.
- `huntress_incidents_list` — List incident reports with optional filters.
- `huntress_incidents_get` — Get incident report by ID.
- `huntress_incidents_resolve` — Resolve an incident report.
- `huntress_incidents_remediations` — List remediations for an incident report.
- `huntress_incidents_remediation_get` — Get a specific remediation.
- `huntress_incidents_bulk_approve` — Bulk approve all remediations for an incident report.
- `huntress_incidents_bulk_reject` — Bulk reject all remediations for an incident report.
- `huntress_escalations_list` — List escalations.
- `huntress_escalations_get` — Get escalation by ID (includes entities).
- `huntress_escalations_resolve` — Resolve an escalation.
- `huntress_navigate` — Discover available Huntress tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/di
- `huntress_status` — Check Huntress API connection status and available domains.
- `huntress_organizations_list` — List organizations.
- `huntress_organizations_get` — Get organization by ID.
- `huntress_organizations_create` — ⚠ HIGH-IMPACT. Creates a new organization in Huntress, which provisions tenant
- `huntress_organizations_update` — ⚠ HIGH-IMPACT. Updates an organization's name, key, or report recipients. Changing
- `huntress_organizations_delete` — ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes an organization and all of its
- `huntress_signals_list` — List security signals.
- `huntress_signals_get` — Get signal by ID.
- `huntress_users_list` — List memberships (users).
- `huntress_users_get` — Get membership by ID.
- `huntress_users_create` — ⚠ HIGH-IMPACT. Creates a membership (invites a user) and grants them the specified
- `huntress_users_update` — ⚠ HIGH-IMPACT. Updates a membership's permission level, which can grant or revoke
- `huntress_users_delete` — ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a user membership and removes
- `incident-triage` — Review all open Huntress incidents and prioritize response
- `org-coverage-check` — Verify agent deployment and SOC coverage for an organization
- `org_name` — Filter to a specific organization (optional — checks all orgs if omitted)
- `remediation-review` — Review pending remediations for an incident and recommend approve/reject
- `incident_id` — The Huntress incident ID to review remediations for

## Install

This entry has no npm package and no hosted endpoint, so there is nothing for an MCP client to launch or connect to. It is indexed as source only.

## Blast radius

Extensive blast radius — deletes data; holds an api key.
- Floor 45, ceiling 57 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Fhuntress-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Fhuntress-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.WYRE-AI%2Fhuntress-mcp
- HTML page: https://forgeregistry.com/registry/io.github.WYRE-AI%2Fhuntress-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
