InfoSec MCP Server
for AI Agents
Connect your AI agent to StackOne's InfoSec MCP server and give it 34 MCP tools out of the box. Auth, tool execution, and security all managed.
Coverage
34 Agent Actions
Create, read, update, and delete across InfoSec — and extend your agent's capabilities with custom actions.
Authentication
Agent Tool Authentication
Per-user OAuth in one call. Your InfoSec MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Agent Protection
Every InfoSec tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Max Agent Context. Min Cost.
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every InfoSec call.
Tools Discovery →What is the InfoSec MCP Server?
A InfoSec MCP server lets AI agents read and write InfoSec data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's InfoSec MCP server ships with 34 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
All InfoSec MCP Tools
Every action from InfoSec's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Campaigns
- List Campaigns
Retrieve a list of all training campaigns
- Get Campaign
Retrieve detailed information for a specific campaign
Campaign Runs
- List Campaign Runs
Retrieve all runs for a specific campaign
- Get Campaign Run
Retrieve details for a specific campaign run
Courses
- List Courses
Retrieve a list of all training courses
- Get Course
Retrieve details for a specific course by ID
Learner Groups
- List Learner Groups
Retrieve a list of all learner groups
- Get Learner Group
Retrieve details for a specific learner group
Learners
- Create Learner
Create a new learner in the account
- List Learners
Retrieve a list of all learners in the account
- Get Learner
Retrieve detailed information for a specific learner by ID
- Update Learner
Update an existing learner's information
- Delete Learner
Delete a learner from the account
PhishSim Templates
- List PhishSim Templates
Retrieve a list of all PhishSim phishing templates
- Get PhishSim Template
Retrieve details for a specific PhishSim template
PhishHunter Messages
- List PhishHunter Messages
Retrieve a list of reported phishing emails from PhishHunter
- Get PhishHunter Message
Retrieve details for a specific PhishHunter reported message
Other (17)
- Create AwareEd Campaign
Create a new AwareEd security awareness training campaign
- Create PhishSim Campaign
Create a new PhishSim phishing simulation campaign
- Get Assessment
Retrieve details for a specific assessment by ID
- List Phishing Batteries
Retrieve a list of all PhishSim template batteries
- List Brandings
Retrieve a list of organizational brands
- Get Campaign Details (Clone)
Retrieve campaign details in the shape needed to clone the campaign
- List Campaign Run Learners
Retrieve learners enrolled in a campaign run
- Get Campaign Run Statistics
Retrieve statistics for a campaign run
- Get Module
Retrieve details for a specific training module by ID
- List Learner Group Members
Retrieve learners belonging to a specific group
- List Learner Timeline Events
List timeline events for a specific learner
- List Notifications
Retrieve a list of all notification templates
- Get Quarantined Email
Retrieve details for a specific quarantined email
- List Categories
Retrieve a list of all training categories
- List Languages
Retrieve a list of all available languages
- List Timeline Events
Retrieve organization-wide timeline events
- Enroll Learner In Campaign
Enroll a learner into a specific campaign
Set Up Your InfoSec MCP Server in Minutes
One endpoint. Any framework. Your agent is talking to InfoSec in under 10 lines of code.
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Check More Security MCP Servers
150+ actions
110+ actions
78+ actions
76+ actions
69+ actions
68+ actions
64+ actions
Platform Resources
MCP Code Mode: Keeping Tool Responses Out of Agent Context
Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Comparing BM25, TF-IDF, and Hybrid Search for MCP Tool Discovery
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
Indirect Prompt Injection Defense for MCP Tools: A Technical Guide
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
MCP vs A2A: Architecture, Security, and When to Use Each
MCP vs A2A: what each protocol standardizes, how they differ, their shared security risks including indirect prompt injection, and when to use one, both, or a hybrid architecture.
12 min
MCP vs API: What 200+ Connector Builds Taught Us
MCP wraps APIs, it doesn't replace them. After building 200+ connectors that serve both, here's when each approach wins.
14 min read
InfoSec MCP Server FAQ
Does StackOne have a InfoSec MCP server?
InfoSec MCP server vs direct API integration — what's the difference?
How does InfoSec authentication work for AI agents?
origin_owner_id.Are InfoSec MCP tools vulnerable to prompt injection?
What is the context bloat of a InfoSec agent and how do I avoid it?
Can I limit which actions my InfoSec agent can access?
Can I create custom agent actions for my InfoSec MCP server?
When should I NOT use a InfoSec MCP server?
What AI frameworks and AI clients does the StackOne InfoSec MCP server support?
Put your AI agents to work
All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.