{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_cvju5e9ndehy","handle":"iflow-mcp-securitycopilotmcpserver","url":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver","links":{"self":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver/record.json","html":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver","markdown":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver/record.md","api":"https://wellknown.network/api/v1/agents/iflow-mcp-securitycopilotmcpserver","status":"https://wellknown.network/api/v1/agents/iflow-mcp-securitycopilotmcpserver/status","claim":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver/claim.json","badge":"https://wellknown.network/agents/iflow-mcp-securitycopilotmcpserver/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/iflow-mcp-securitycopilotmcpserver/history","tools":"https://wellknown.network/api/v1/agents/iflow-mcp-securitycopilotmcpserver/tools"},"ard":{"identifier":"urn:air::server:iflow-mcp-securitycopilotmcpserver","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"iflow-mcp_securitycopilotmcpserver","summary":"MCP Server that integrates with Security Copilot, Sentinel and other tools","description":"# Security Copilot and Sentinel MCP Server\n\nA Python-based MCP server using FastMCP library that provides integration with Microsoft Security Copilot and Microsoft Sentinel using Azure Identity Authentication.\n![Diagram](Diagram.png)\n## Overview\n\nThis project implements an MCP server that enables:\n\n- Running KQL queries against Microsoft Sentinel\n- Uploading/Updating Microsoft Security Copilot skillsets/plugins\n- Running prompts and skills in Microsoft Security Copilot\n\nThe server acts as a bridge between development environments and Microsoft Security Copilot, allowing for testing, deployment, and execution of skills and plugins. It uses SSE as transport layer for the MCP server.\nThere are many use cases for the current integration. One of the most interesting ones is to support the development, test and deployment of Security Copilot KQL Skills. \n\n![AgentFlow1](screenshot.png)\n![AgentFlow2](screenshot2.png)\n## Features\n\n- **Sentinel Integration**: Execute KQL queries against your Sentinel workspace\n- **Security Copilot Management**:\n  - List existing skillsets/plugins\n  - Upload new or update existing skillsets/plugins\n  - Run prompts or skills within Security Copilot\n- **Authentication Support**: Multiple authentication methods including interactive browser, client secret, and managed identity\n## Roadmap\nThe next features will include: \n- **Promptbook test and Update**\n- **Run Advance Hunting queries in Defender XDR**\n## Prerequisites\n\n- Python 3.8+\n- Microsoft Sentinel workspace\n- Microsoft Security Copilot access\n- Appropriate Azure permissions for Sentinel and Security Copilot\n\n## Installation\n\n1. Clone the repository:\n   ```\n   git clone https://github.com/jguimera/SecurityCopilotMCPServer.git\n   cd SecurityCopilotMCPServer\n   ```\n\n2. Install dependencies:\n   ```\n   pip install -r requirements.txt\n   ```\n\n3. Create a `.env` file with the following configuration:\n   ```\n   #Add App Reg to use ClientID and Secret authentication\n   #AZURE_TENANT_ID=your_tenant_…","publisher":null,"homepage":"https://github.com/jguimera/SecurityCopilotMCPServer","repository":"https://github.com/jguimera/SecurityCopilotMCPServer","version":"0.1.0","license":"MIT","protocols":["mcp"],"tags":["mcp"],"pricing":null,"endpoints":[{"url":"pypi:iflow-mcp_securitycopilotmcpserver","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi"}},"derived":{"capabilities":[{"slug":"dev.version-control","name":"Version Control","confidence":1,"provenance":"derived"},{"slug":"security.identity","name":"Identity & Access","confidence":1,"provenance":"derived"},{"slug":"ai.prompting","name":"Prompt Management","confidence":0.791,"provenance":"derived"},{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":0.779,"provenance":"derived"}],"categories":["ai","dev","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"iflow-mcp_securitycopilotmcpserver","registry":"pypi","observedAt":"2026-09-15T20:21:19.801Z","publishedAt":"2025-11-26T08:27:18.542245Z","latestVersion":"0.1.0"},"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"iflow-mcp_securitycopilotmcpserver","url":"https://pypi.org/project/iflow-mcp_securitycopilotmcpserver/","firstSeenAt":"2026-09-09T21:23:44.101Z","fetchedAt":"2026-09-15T20:19:26.592Z","normalizedAt":"2026-09-15T20:19:26.592Z"}]},"firstSeenAt":"2026-09-09T21:23:44.101Z","updatedAt":"2026-09-15T20:21:19.801Z"}