Lacework FortiCNAPP MCP Server
for AI Agents
Connect your AI agent to StackOne's Lacework FortiCNAPP MCP server and give it 56 MCP tools out of the box. Auth, tool execution, and security all managed.
Coverage
56 Agent Actions
Create, read, update, and delete across Lacework FortiCNAPP — and extend your agent's capabilities with custom actions.
Authentication
Agent Tool Authentication
Per-user OAuth in one call. Your Lacework FortiCNAPP MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Agent Protection
Every Lacework FortiCNAPP tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Max Agent Context. Min Cost.
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Lacework FortiCNAPP call.
Tools Discovery →What is the Lacework FortiCNAPP MCP Server?
A Lacework FortiCNAPP MCP server lets AI agents read and write Lacework FortiCNAPP data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Lacework FortiCNAPP MCP server ships with 56 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
All Lacework FortiCNAPP MCP Tools
Every action from Lacework FortiCNAPP's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Alert Channels
- Create Alert Channel
Create an alert channel by specifying parameters in the request body.
- List Alert Channels
Get a list of alert channels for the current user.
- Get Alert Channel
Get details about an alert channel.
- Update Alert Channel
Update an alert channel by specifying parameters in the request body.
- Delete Alert Channel
Delete an alert channel.
Alert Rules
- Create Alert Rule
Create an alert rule by specifying parameters in the request body.
- List Alert Rules
List all alert rules in your Lacework instance.
- Get Alert Rule
Get details about an alert rule.
- Update Alert Rule
Update an alert rule by specifying parameters in the request body.
- Delete Alert Rule
Delete an alert rule.
Alerts
- List Alerts
Get a list of alerts during the specified date range.
- Search Alerts
Search alerts.
- Get Alert
Get details about an alert.
Cloud Accounts
- Create Cloud Account
Create a cloud account by specifying parameters in the request body.
- List Cloud Accounts
Get a list of cloud accounts for the current user.
- Get Cloud Account
Get details about a cloud account.
- Update Cloud Account
Update a cloud account by specifying parameters in the request body.
- Delete Cloud Account
Delete a cloud account.
Container Registrys
- Create Container Registry
Create a container registry by specifying parameters in the request body.
- Get Container Registry
Get details about a container registry.
- Update Container Registry
Update a container registry by specifying parameters in the request body.
- Delete Container Registry
Delete a container registry.
Policys
- Create Policy
Create a Lacework Query Language (LQL) policy by specifying parameters in the request body.
- Get Policy
Get details about a single LQL policy.
- Update Policy
Update an existing LQL policy registered in your Lacework instance by specifying parameters in the request body.
- Delete Policy
Delete an LQL custom policy registered in your Lacework instance.
Resource Groups
- Create Resource Group
Create a resource group by specifying parameters in the request body.
- List Resource Groups
Get a list of all resource groups for the account.
- Get Resource Group
Get details about a resource group.
- Update Resource Group
Update a resource group by specifying parameters in the request body.
- Delete Resource Group
Delete a resource group.
Team Members
- Create Team Member
Create a team member in your Lacework instance.
- List Team Members
Get a list of team members in your Lacework instance.
- Get Team Member
Get details about a team member.
- Update Team Member
Optionally update the userName and userEnabled settings and the props sub-settings of the passed in team member.
- Delete Team Member
Delete a team member.
Vulnerability Exceptions
- Create Vulnerability Exception
Create a vulnerability exception by specifying parameters in the request body.
- List Vulnerability Exceptions
Get a list of all vulnerability exceptions for the account.
- Delete Vulnerability Exception
Delete a vulnerability exception.
Other (17)
- Create Query
Create a Lacework Query Language (LQL) query by specifying parameters in the request body.
- List Audit Logs
Get audit logs.
- List Container Registries
Get a list of container registries for the current user.
- Search Machines
Search for machines in your environment.
- Search Users
Search for users in your environment.
- Search Inventory
The Inventory API enables you to retrieve information about resources in your cloud integrations, such as virtual machines, S3 buckets, security groups, and more, using the following endpoint: By default, Lacework collects resource information once a day.
- List Policies
List all registered LQL policies in your Lacework instance.
- List Queries
List all registered LQL queries in your Lacework instance.
- Get Query
Get details about a single LQL query.
- List Reports
Retrieve a compliance report filtered by report type, severity, status, and format.
- Search Container Vulnerabilities
Search the scan (assessment), including the risk score and scan status, the vulnerabilities found in the scan, and statistics for those vulnerabilities.
- Search Host Vulnerabilities
Search the scan (assessment), including the risk score and scan status, vulnerabilities found in the scan, and statistics about those vulnerabilities.
- Update Query
Update an existing LQL query registered in your Lacework instance.
- Delete Query
Delete a Lacework Query Language (LQL) query registered in your Lacework instance.
- Comment Alert
Post a user comment on an alert’s timeline.
- Close Alert
Change the status of an alert to closed.
- Execute Query
Run an existing LQL query registered in your Lacework instance.
Set Up Your Lacework FortiCNAPP MCP Server in Minutes
One endpoint. Any framework. Your agent is talking to Lacework FortiCNAPP in under 10 lines of code.
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Check More Security MCP Servers
150+ actions
110+ actions
78+ actions
76+ actions
69+ actions
68+ actions
64+ actions
Platform Resources
MCP Code Mode: Keeping Tool Responses Out of Agent Context
Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Comparing BM25, TF-IDF, and Hybrid Search for MCP Tool Discovery
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
Indirect Prompt Injection Defense for MCP Tools: A Technical Guide
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
MCP vs A2A: Architecture, Security, and When to Use Each
MCP vs A2A: what each protocol standardizes, how they differ, their shared security risks including indirect prompt injection, and when to use one, both, or a hybrid architecture.
12 min
MCP vs API: What 200+ Connector Builds Taught Us
MCP wraps APIs, it doesn't replace them. After building 200+ connectors that serve both, here's when each approach wins.
14 min read
Lacework FortiCNAPP MCP Server FAQ
Does StackOne have a Lacework FortiCNAPP MCP server?
Lacework FortiCNAPP MCP server vs direct API integration — what's the difference?
How does Lacework FortiCNAPP authentication work for AI agents?
origin_owner_id.Are Lacework FortiCNAPP MCP tools vulnerable to prompt injection?
What is the context bloat of a Lacework FortiCNAPP agent and how do I avoid it?
Can I limit which actions my Lacework FortiCNAPP agent can access?
Can I create custom agent actions for my Lacework FortiCNAPP MCP server?
When should I NOT use a Lacework FortiCNAPP MCP server?
What AI frameworks and AI clients does the StackOne Lacework FortiCNAPP MCP server support?
Put your AI agents to work
All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.