Cybret MCP
Cybret (app.cybret.ai) finds API and application vulnerabilities and validates them before they reach an engineer. This repository is the public plugin and install surface for the hosted Cybret MCP server. The server itself stays private.
Coding agents use it to pull those validated findings into the editor, apply the remediation in the repo they already have open, and mark the finding once the fix is on a pull request. The result is a short loop on confirmed issues, not a dump of unscored scanner noise.
The server is Streamable HTTP at https://mcp.cybret.ai/mcp. Sign-in is OAuth 2.1 with PKCE S256 and dynamic client registration. A personal agent token is the fallback when a client cannot complete OAuth.
You need a Cybret account that has already run a scan. This server does not start scans. With no completed scans, the findings list is empty.
Install
Every client below points at the same endpoint: https://mcp.cybret.ai/mcp.
Cursor
One click installs the remote server and prompts before adding it:
That link is the Cursor MCP install link for this config:
{
"url": "https://mcp.cybret.ai/mcp"
}
To install the plugin (server, triage skill, and rule), add this repository from the Cursor Marketplace once the listing is approved, or load it locally. The manifest is .cursor-plugin/plugin.json, and it uses the shared mcp.json.
Manual ~/.cursor/mcp.json or .cursor/mcp.json:
{
"mcpServers": {
"cybret": {
"url": "https://mcp.cybret.ai/mcp"
}
}
}
Cursor treats a url entry as Streamable HTTP and starts OAuth when the server asks for it.
Claude Code
Direct HTTP install:
claude mcp add --transport http cybret https://mcp.cybret.ai/mcp
Then authenticate with /mcp.
From this marketplace:
/plugin marketplace add CYBRET-AI/cybret-mcp
/plugin install cybret@cybret
The catalog is .claude-plugin/marketplace.json. The plugin manifest is .claude-plugin/plugin.json, and the server entry is .mcp.json (type http, which Claude Code accepts as Streamable HTTP).
Codex
codex mcp add cybret --url https://mcp.cybret.ai/mcp
codex mcp login cybret
codex mcp login runs OAuth for the Streamable HTTP server. The plugin package for the shared ChatGPT and Codex directory is the root plugin.json (Agent Plugins 1.0, with OpenAI listing fields under extensions.com.openai) plus mcp.json. .codex-plugin/plugin.json is the compatibility manifest and points at .mcp.json.
Generic mcp.json
Portable Agent Plugins / MCP config, the same document checked in as mcp.json:
{
"mcpServers": {
"cybret": {
"type": "streamable-http",
"url": "https://mcp.cybret.ai/mcp"
}
}
}
Clients that expect the HTTP alias use "type": "http" with the same URL. That is .mcp.json.
Sign in with OAuth
- The client calls
https://mcp.cybret.ai/mcpwithout a token. - The server answers
401withWWW-Authenticate: Bearerandresource_metadata="https://mcp.cybret.ai/.well-known/oauth-protected-resource/mcp". - The client reads that protected-resource metadata, then the authorization-server metadata at
https://mcp.cybret.ai/.well-known/oauth-authorization-server. - The client registers with dynamic client registration when it does not already have a client id. The server supports authorization-code plus refresh tokens, PKCE method
S256, and token auth methodsnone,client_secret_post, andclient_secret_basic. - The browser opens the Cybret consent screen. Approve the scopes the client requested.
- The client stores the access token and sends it as
Authorization: Beareron later MCP requests.
Scopes advertised by the protected-resource metadata:
| Scope | Use |
|---|---|
findings:read | List and read findings. |
findings:write | Update finding status (mark_status). |
Approve read access to triage. Approve write access only if the agent should update status.
Token fallback
If the client cannot complete OAuth, create a personal agent token in the Cybret console: app.cybret.ai/settings/agents, then Advanced, Access tokens. Send it as a bearer header. The plugin manifests do not contain a token. Set one only in your own client config, and do not commit it.
Cursor example, with the token in the environment rather than the file:
{
"mcpServers": {
"cybret": {
"url": "https://mcp.cybret.ai/mcp",
"headers": {
"Authorization": "Bearer ${env:CYBRET_AGENT_TOKEN}"
}
}
}
}
A header on the request skips the OAuth login. The token's own scopes decide whether status updates are allowed.
Tools
Names and parameters below are the contract published at Docs: MCP server. Protected-resource metadata at https://mcp.cybret.ai/.well-known/oauth-protected-resource/mcp advertises findings:read and findings:write. Agents should still read the input schema from the connected server before calling a tool.
| Tool | Scope | Arguments |
|---|---|---|
list_open_findings | findings:read | Optional severity (info, low, medium, high, critical), optional target (repo owner/name or a scan run id, at most 200 characters), and limit from 1 to 100 (default 25). |
get_finding | findings:read | finding_id (required). Returns reproduction, location, and remediation. |
mark_status | findings:write | finding_id and status (open, fixed, or false_positive) are required. Optional note (required for false_positive, and for fixed when there is no verify or retest proof). Optional link_pr (owner/repo#n or a GitHub pull request URL). Linking a pull request does not close the finding. |
The triage workflow is skills/triage-cybret-findings/SKILL.md. Cursor also loads rules/triage-cybret-findings.mdc.
Security and privacy
- The credential selects the tenant. OAuth is the signed-in Cybret user. An agent token is the user who created it. The server does not accept a tenant id that would cross that boundary.
findings:readcan list and read findings.findings:writecan change status. Connect read-only when the agent should not update Cybret.- Do not commit tokens, and do not paste them into chat. The checked-in configs contain only
https://mcp.cybret.ai/mcp. - Customer findings are customer data. The privacy policy describes this in AI agents and MCP connections: tool results go to the AI client you choose, limited to the workspace and scopes you approved. Use of the service is covered by the terms.
Docs and support
- Documentation: MCP server — install, tools, scopes, and authentication.
- Support: cybret.ai/support. Email hello@cybret.ai. Report a vulnerability to security@cybret.ai.
- Privacy: cybret.ai/privacy, including the AI agents and MCP connections section. Privacy requests still go to privacy@cybret.ai.
- Terms: cybret.ai/terms.
Layout
| Path | Role |
|---|---|
mcp.json | Shared server config (Agent Plugins schema, streamable-http). |
.mcp.json | Claude Code and Codex compatibility config (type http, same URL). |
plugin.json | Portable Agent Plugins manifest, including OpenAI listing fields. |
.cursor-plugin/plugin.json | Cursor plugin. |
.claude-plugin/plugin.json | Claude Code plugin. |
.claude-plugin/marketplace.json | Claude Code marketplace (cybret). |
.codex-plugin/plugin.json | Codex compatibility manifest. |
server.json | MCP Registry document for remote server ai.cybret/findings. Not published from this repo. |
skills/triage-cybret-findings/SKILL.md | Client-neutral triage skill. |
LAUNCH.md | Remaining submission steps and server-side blockers. |
The square icon is the official favicon from https://www.cybret.ai/favicon.png. See the pull request notes for which sizes are derived.
License
MIT. Copyright (c) 2026 Cybret.