Skip to content

cybret-ai/cybret

v0.1.0MIT

Validated Cybret API and app security findings, with remediation guidance, for coding agents.

Cybret MCP

Cybret (app.cybret.ai) finds API and application vulnerabilities and validates them before they reach an engineer. This repository is the public plugin and install surface for the hosted Cybret MCP server. The server itself stays private.

Coding agents use it to pull those validated findings into the editor, apply the remediation in the repo they already have open, and mark the finding once the fix is on a pull request. The result is a short loop on confirmed issues, not a dump of unscored scanner noise.

The server is Streamable HTTP at https://mcp.cybret.ai/mcp. Sign-in is OAuth 2.1 with PKCE S256 and dynamic client registration. A personal agent token is the fallback when a client cannot complete OAuth.

You need a Cybret account that has already run a scan. This server does not start scans. With no completed scans, the findings list is empty.

Install

Every client below points at the same endpoint: https://mcp.cybret.ai/mcp.

Cursor

One click installs the remote server and prompts before adding it:

Add Cybret to Cursor

That link is the Cursor MCP install link for this config:

{
  "url": "https://mcp.cybret.ai/mcp"
}

To install the plugin (server, triage skill, and rule), add this repository from the Cursor Marketplace once the listing is approved, or load it locally. The manifest is .cursor-plugin/plugin.json, and it uses the shared mcp.json.

Manual ~/.cursor/mcp.json or .cursor/mcp.json:

{
  "mcpServers": {
    "cybret": {
      "url": "https://mcp.cybret.ai/mcp"
    }
  }
}

Cursor treats a url entry as Streamable HTTP and starts OAuth when the server asks for it.

Claude Code

Direct HTTP install:

claude mcp add --transport http cybret https://mcp.cybret.ai/mcp

Then authenticate with /mcp.

From this marketplace:

/plugin marketplace add CYBRET-AI/cybret-mcp
/plugin install cybret@cybret

The catalog is .claude-plugin/marketplace.json. The plugin manifest is .claude-plugin/plugin.json, and the server entry is .mcp.json (type http, which Claude Code accepts as Streamable HTTP).

Codex

codex mcp add cybret --url https://mcp.cybret.ai/mcp
codex mcp login cybret

codex mcp login runs OAuth for the Streamable HTTP server. The plugin package for the shared ChatGPT and Codex directory is the root plugin.json (Agent Plugins 1.0, with OpenAI listing fields under extensions.com.openai) plus mcp.json. .codex-plugin/plugin.json is the compatibility manifest and points at .mcp.json.

Generic mcp.json

Portable Agent Plugins / MCP config, the same document checked in as mcp.json:

{
  "mcpServers": {
    "cybret": {
      "type": "streamable-http",
      "url": "https://mcp.cybret.ai/mcp"
    }
  }
}

Clients that expect the HTTP alias use "type": "http" with the same URL. That is .mcp.json.

Sign in with OAuth

  1. The client calls https://mcp.cybret.ai/mcp without a token.
  2. The server answers 401 with WWW-Authenticate: Bearer and resource_metadata="https://mcp.cybret.ai/.well-known/oauth-protected-resource/mcp".
  3. The client reads that protected-resource metadata, then the authorization-server metadata at https://mcp.cybret.ai/.well-known/oauth-authorization-server.
  4. The client registers with dynamic client registration when it does not already have a client id. The server supports authorization-code plus refresh tokens, PKCE method S256, and token auth methods none, client_secret_post, and client_secret_basic.
  5. The browser opens the Cybret consent screen. Approve the scopes the client requested.
  6. The client stores the access token and sends it as Authorization: Bearer on later MCP requests.

Scopes advertised by the protected-resource metadata:

ScopeUse
findings:readList and read findings.
findings:writeUpdate finding status (mark_status).

Approve read access to triage. Approve write access only if the agent should update status.

Token fallback

If the client cannot complete OAuth, create a personal agent token in the Cybret console: app.cybret.ai/settings/agents, then Advanced, Access tokens. Send it as a bearer header. The plugin manifests do not contain a token. Set one only in your own client config, and do not commit it.

Cursor example, with the token in the environment rather than the file:

{
  "mcpServers": {
    "cybret": {
      "url": "https://mcp.cybret.ai/mcp",
      "headers": {
        "Authorization": "Bearer ${env:CYBRET_AGENT_TOKEN}"
      }
    }
  }
}

A header on the request skips the OAuth login. The token's own scopes decide whether status updates are allowed.

Tools

Names and parameters below are the contract published at Docs: MCP server. Protected-resource metadata at https://mcp.cybret.ai/.well-known/oauth-protected-resource/mcp advertises findings:read and findings:write. Agents should still read the input schema from the connected server before calling a tool.

ToolScopeArguments
list_open_findingsfindings:readOptional severity (info, low, medium, high, critical), optional target (repo owner/name or a scan run id, at most 200 characters), and limit from 1 to 100 (default 25).
get_findingfindings:readfinding_id (required). Returns reproduction, location, and remediation.
mark_statusfindings:writefinding_id and status (open, fixed, or false_positive) are required. Optional note (required for false_positive, and for fixed when there is no verify or retest proof). Optional link_pr (owner/repo#n or a GitHub pull request URL). Linking a pull request does not close the finding.

The triage workflow is skills/triage-cybret-findings/SKILL.md. Cursor also loads rules/triage-cybret-findings.mdc.

Security and privacy

  • The credential selects the tenant. OAuth is the signed-in Cybret user. An agent token is the user who created it. The server does not accept a tenant id that would cross that boundary.
  • findings:read can list and read findings. findings:write can change status. Connect read-only when the agent should not update Cybret.
  • Do not commit tokens, and do not paste them into chat. The checked-in configs contain only https://mcp.cybret.ai/mcp.
  • Customer findings are customer data. The privacy policy describes this in AI agents and MCP connections: tool results go to the AI client you choose, limited to the workspace and scopes you approved. Use of the service is covered by the terms.

Docs and support

Layout

PathRole
mcp.jsonShared server config (Agent Plugins schema, streamable-http).
.mcp.jsonClaude Code and Codex compatibility config (type http, same URL).
plugin.jsonPortable Agent Plugins manifest, including OpenAI listing fields.
.cursor-plugin/plugin.jsonCursor plugin.
.claude-plugin/plugin.jsonClaude Code plugin.
.claude-plugin/marketplace.jsonClaude Code marketplace (cybret).
.codex-plugin/plugin.jsonCodex compatibility manifest.
server.jsonMCP Registry document for remote server ai.cybret/findings. Not published from this repo.
skills/triage-cybret-findings/SKILL.mdClient-neutral triage skill.
LAUNCH.mdRemaining submission steps and server-side blockers.

The square icon is the official favicon from https://www.cybret.ai/favicon.png. See the pull request notes for which sizes are derived.

License

MIT. Copyright (c) 2026 Cybret.