AI Detection Engineering Platform (Simoon896/ai-detection-engineering-platform) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. No publisher has claimed this listing.

C
Emerging
74/100

AI Detection Engineering Platform

An MCP server that enables conversational interaction with Wazuh SIEM, allowing users to investigate alerts, hunt threats, tune false positives, edit rules, and run security actions via natural language.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Simoon896

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 6 credentials: MCP_API_KEY, ATOMIC_WINRM_PASSWORD, AUTH_SECRET_KEY, WAZUH_PASS, WAZUH_INDEXER_PASS, MASTER_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configATOMIC_AUTHLESS_ALLOW_WRITE
configAUTHLESS_ALLOW_WRITEAllow active response in authless mode
🔐 secretMCP_API_KEY
configENVIRONMENT
configMCP_HOSTServer bind address
configMCP_PORTServer port
configLOG_LEVEL
configATOMIC_MCP_URL
configWAZUH_MCP_URL
configART_INTERVAL_SEC
configART_ALERT_WAIT_SEC
configANSICON
configBUILD_DATE
configVERSION
configPYTHON_VERSION
configATOMIC_TARGET_HOST
configATOMIC_TRANSPORT
configATOMIC_MCP_HOST
configATOMIC_MCP_PORT
configATOMIC_WAZUH_AGENT_NAME
configATOMIC_VM_NAME
configATOMIC_SNAPSHOT_NAME
configATOMIC_ATOMICS_PATH
configATOMIC_MAX_RUNTIME_SECONDS
configATOMIC_OUTPUT_LIMIT_BYTES
configATOMIC_LEDGER_PATH
configATOMIC_COVERAGE_PATH
configATOMIC_WINRM_USERNAME
🔐 secretATOMIC_WINRM_PASSWORD
configATOMIC_WINRM_PORT
configATOMIC_WINRM_DOMAIN
🔐 secretAUTH_SECRET_KEYJWT signing key
configTOKEN_LIFETIME_HOURS
configAPI_KEYS
configWAZUH_HOSTWazuh Manager hostname or IP
configWAZUH_USERAPI username
🔐 secretWAZUH_PASSAPI password
configVERIFY_SSL
configWAZUH_INDEXER_HOSTIndexer hostname
configWAZUH_INDEXER_USERIndexer username
🔐 secretWAZUH_INDEXER_PASSIndexer password
configMCP_TRANSPORT
configAUTH_MODEoauth, bearer, or none
configOAUTH_ISSUER_URL
configOAUTH_ENABLE_DCR
configOAUTH_ACCESS_TOKEN_TTL
configOAUTH_REFRESH_TOKEN_TTL
configOAUTH_AUTHORIZATION_CODE_TTL
configALLOWED_ORIGINSCORS origins (comma-separated)
configWAZUH_PORTManager API port
configWAZUH_VERIFY_SSL
configWAZUH_ALLOW_SELF_SIGNED
configWAZUH_INDEXER_PORTIndexer port
configWAZUH_INDEXER_VERIFY_SSL
🔐 secretMASTER_KEY
configSSE_PORT
configSSE_HOST
configSSL_KEYFILE
configSSL_CERTFILE
configKUBERNETES_SERVICE_HOST
configDOCKER_CONTAINER
configMAX_MEMORY_MB
configRATE_LIMIT_REQUESTS
configRATE_LIMIT_WINDOW
configTRUSTED_PROXIES
configSESSION_TTL_SECONDS
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployREDIS_URL
// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/simoon896/ai-detection-engineering-platform)](https://m8ven.ai/mcp/simoon896/ai-detection-engineering-platform)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: c224f68a2adb5c90664f4ff7f778bde7e307784d
code hash: 016adcd9d929a7351bd6f0ab634b74c9b69b288ed2bd88ecbf9980476ae1d13b
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client