# io.github.WYRE-AI/knowbe4-mcp

MCP server for KnowBe4 security awareness training — users, groups, training, phishing campaigns.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.1.5
- **Author:** io.github.WYRE-AI
- **License:** Unknown
- **Source:** https://github.com/WYRE-AI/knowbe4-mcp

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-25T01:27:16.267Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

34 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `knowbe4_account_get` — Get account info
- `knowbe4_account_risk_score_history` — Get risk score history
- `knowbe4_users_list` — List users
- `knowbe4_users_get` — Get user
- `knowbe4_users_risk_score_history` — Get user risk score history
- `knowbe4_groups_list` — List groups
- `knowbe4_groups_get` — Get group
- `knowbe4_groups_members` — Get group members
- `knowbe4_groups_risk_score_history` — Get group risk score history
- `knowbe4_phishing_campaigns_list` — List phishing campaigns
- `knowbe4_phishing_campaigns_get` — Get phishing campaign
- `knowbe4_phishing_security_tests_list` — List PSTs
- `knowbe4_training_campaigns_list` — List training campaigns
- `knowbe4_training_campaigns_get` — Get training campaign
- `knowbe4_training_enrollments_list` — List enrollments
- `knowbe4_reporting_phishing_summary` — Phishing summary
- `knowbe4_reporting_training_summary` — Training summary
- `knowbe4_reporting_risk_overview` — Risk overview
- `knowbe4_phishing_campaign_tests` — List all Phishing Security Tests (PSTs) for a specific campaign.
- `knowbe4_phishing_security_test_get` — Get detailed results for a specific Phishing Security Test (PST) by ID. Includes phish-prone percentage, clicked/opened/reported counts.
- `knowbe4_phishing_security_test_recipients` — Get recipient-level results for a specific PST. Shows which users clicked, opened, reported, or were otherwise affected.
- `knowbe4_phishing_security_test_recipient` — Get a specific recipient's detailed result for a PST, including click time, open time, and reported status.
- `knowbe4_training_enrollments_get` — Get detailed information about a specific training enrollment by ID, including module progress and completion date.
- `knowbe4_store_purchases_list` — List all store purchases (training content bought from the KnowBe4 ModStore). Shows purchased modules and content.
- `knowbe4_store_purchases_get` — Get detailed information about a specific store purchase by ID.
- `knowbe4_policies_list` — List all security policies. Returns policy names, status, and acknowledgment requirements.
- `knowbe4_policies_get` — Get detailed information about a specific policy by ID, including acknowledgment status.
- `knowbe4_navigate` — Discover available KnowBe4 tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/dis
- `knowbe4_back` — No-op tool for backwards compatibility. All tools are always available.
- `knowbe4_status` — Show credentials status and available domains. Also verifies API credentials are configured.
- `knowbe4_list_categories` — List all available KnowBe4 tool categories with descriptions and tool counts. Use this first to discover what the server can do before loading individual tool s
- `knowbe4_list_category_tools` — List all tools in a specific category with their full schemas. Call this after knowbe4_list_categories to see exactly what parameters a tool accepts.
- `knowbe4_execute_tool` — Execute any KnowBe4 tool by name. Use knowbe4_list_category_tools first to discover the tool's required arguments.
- `knowbe4_router` — Suggest the best KnowBe4 tool(s) for a given intent. Describe what you want to do in plain language and this tool will recommend which tool(s) to call.

## Install

This entry has no npm package and no hosted endpoint, so there is nothing for an MCP client to launch or connect to. It is indexed as source only.

## Blast radius

Contained to moderate — no package coordinates and no declared endpoint — Forge cannot tell where this would run or whose authority it would borrow. Known so far: holds an api key; read-only tool surface.
- Floor 13, ceiling 25 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Fknowbe4-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Fknowbe4-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.WYRE-AI%2Fknowbe4-mcp
- HTML page: https://forgeregistry.com/registry/io.github.WYRE-AI%2Fknowbe4-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
