aribot-mcp
Threat modeling, code, API & cloud security, shadow-AI & compliance governance.
使うべきか
品質と安全性
検出事項(3)
- HIGH
- MEDIUMonboard_agents 内
- LOWapply_remediation 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"aribot-mcp": {
"url": "https://mcp.aribot.ayurak.com/"
}
}
}リモートエンドポイント
https://mcp.aribot.ayurak.com/streamable-httphttps://mcp.aribot.ayurak.com/ssesseできること
ツール一覧
ツール(18)
🟢get_billing(checkout_request_id, topup_amount, request_plan)
Billing status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasable plans, and any approved-but-unpaid plans. Pass `checkout_request_id` to get a hosted Stripe Checkout URL to COMPLETE an approved plan, `topup_amount` (EUR) to get one to TOP UP the wallet, or `request_plan` (starter|pay_per_use|pro|max|enterprise) to REQUEST a plan (files a request for super-admin approval — never grants). Use this to view or RESOLVE a 402 without leaving the connector.
入力スキーマ
{
"type": "object",
"properties": {
"checkout_request_id": {
"type": "string",
"description": "Approved license_request_id to complete payment for (returns a hosted Checkout URL)"
},
"topup_amount": {
"type": "number",
"description": "Optional EUR amount to top up the credit wallet (returns a hosted Checkout URL)"
},
"request_plan": {
"type": "string",
"description": "Optional plan key to request (pro|max|…) — files a request for super-admin approval; does not grant or charge"
}
},
"required": [],
"additionalProperties": false
}⚪onboard_agents(agents, agent_cards, cohort, auto_suspend_threshold)
Bulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cards` (name/url/provider/version/protocolVersion), or MCP client descriptors, under an optional `cohort` + shared auto-suspend policy. Idempotent. Requires the agent_governance licence + a manage:agents grant (or a first-party super-admin). Agents also self-onboard on first token/call.
入力スキーマ
{
"type": "object",
"properties": {
"agents": {
"type": "array",
"items": {},
"description": "Agent ids or descriptors ({agent_id, display?, cohort?})"
},
"agent_cards": {
"type": "array",
"items": {
"type": "object"
},
"description": "A2A 1.0 Agent Cards ({name, url, provider, version, protocolVersion, ...})"
},
"cohort": {
"type": "string",
"description": "Optional shared cohort (provider/model/deployment group)"
},
"auto_suspend_threshold": {
"type": "number",
"description": "Optional 0..1 auto-suspend deviation threshold for the cohort policy"
}
},
"required": [],
"additionalProperties": false
}🟡generate_threat_model(name, nodes, edges)
Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Threat model name"
},
"nodes": {
"type": "array",
"items": {
"type": "object"
},
"description": "ReactFlow nodes (each: id, position, data.label)"
},
"edges": {
"type": "array",
"items": {
"type": "object"
},
"description": "ReactFlow edges"
}
},
"required": [
"nodes"
],
"additionalProperties": false
}🟢verify_threats_in_code(scan_id, threat_id, repository_id, code_content)
Verify whether modelled STRIDE/LINDDUN threats are mitigated in a scan's uploaded code or AST. If threat_id is provided, returns synchronous verdict; otherwise dispatches batch verification across all diagram threats.
入力スキーマ
{
"type": "object",
"properties": {
"scan_id": {
"type": "string",
"description": "Code review scan id"
},
"threat_id": {
"type": "string",
"description": "Optional specific threat id/code to verify"
},
"repository_id": {
"type": "string",
"description": "Optional repository id"
},
"code_content": {
"type": "string",
"description": "Optional inline code snippet to verify"
}
},
"required": [
"scan_id"
],
"additionalProperties": false
}🟢get_traceability(scan_id)
Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.
入力スキーマ
{
"type": "object",
"properties": {
"scan_id": {
"type": "string",
"description": "Code-review scan id"
}
},
"required": [
"scan_id"
],
"additionalProperties": false
}🟢get_framework_coverage(diagram_id, framework, include_graph)
Get real ControlCodeMap-backed coverage percentages, gap counts, and mapped controls for EU AI Act, DORA, NIST AI RMF, ISO 27001, SOC 2, etc.
入力スキーマ
{
"type": "object",
"properties": {
"diagram_id": {
"type": "string",
"description": "Diagram id/uuid"
},
"framework": {
"type": "string",
"description": "Optional framework filter (e.g. eu-ai-act, dora, nist, iso)"
},
"include_graph": {
"type": "boolean",
"description": "Include crossmap relationship graph"
}
},
"required": [
"diagram_id"
],
"additionalProperties": false
}🟢get_remediation(threat_id, rule_id, resource_context)
Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.
入力スキーマ
{
"type": "object",
"properties": {
"threat_id": {
"type": "string",
"description": "Threat id/code to remediate"
},
"rule_id": {
"type": "string",
"description": "Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)"
},
"resource_context": {
"type": "object",
"description": "provider/resource_id/region/account_id/metadata"
}
},
"required": [
"threat_id",
"rule_id"
],
"additionalProperties": false
}🟢compliance_status(scan_id, diagram_id)
Company-level compliance posture rollup across all frameworks (EU AI Act, DORA, NIST, ISO, SOC 2) suitable for CI gates and executive reporting.
入力スキーマ
{
"type": "object",
"properties": {
"scan_id": {
"type": "string",
"description": "Optional scan id filter"
},
"diagram_id": {
"type": "string",
"description": "Optional diagram id filter"
}
},
"required": [],
"additionalProperties": false
}⚪discover_shadow_ai(scan_id)
Scan connected repositories and network traffic for unmanaged LLMs, foundational model endpoints, vector databases, agent frameworks, and leaked API keys (async).
入力スキーマ
{
"type": "object",
"properties": {
"scan_id": {
"type": "string",
"description": "Scan id with uploaded code or repository"
}
},
"required": [
"scan_id"
],
"additionalProperties": false
}🟢get_api_security(scan_id, limit)
API security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Company-wide or one scan with `scan_id`. Reads code_review ApiEndpointDiscovery.
入力スキーマ
{
"type": "object",
"properties": {
"scan_id": {
"type": "string",
"description": "Optional CodeReviewScan id; company-wide if omitted"
},
"limit": {
"type": "integer",
"description": "Max endpoints to return",
"default": 20
}
},
"required": [],
"additionalProperties": false
}🟢get_cloud_compliance(account_id)
Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Account.latest_scan -> compliances.ScanResults.
入力スキーマ
{
"type": "object",
"properties": {
"account_id": {
"type": "string",
"description": "Optional single cloud Account id; all company accounts if omitted"
}
},
"required": [],
"additionalProperties": false
}⚪code_review_scan(scan_id)
Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.
入力スキーマ
{
"type": "object",
"properties": {
"scan_id": {
"type": "string",
"description": "Id of an existing code-review scan to (re)run"
}
},
"required": [
"scan_id"
],
"additionalProperties": false
}⚪compliance_scan(scan_type, account_id, diagram_id, frameworks, severity_filter, ...)
Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.
入力スキーマ
{
"type": "object",
"properties": {
"scan_type": {
"type": "string",
"enum": [
"platform",
"compliance",
"pipeline",
"sbom",
"diagram",
"account"
],
"description": "platform | compliance | pipeline | sbom"
},
"account_id": {
"type": "string",
"description": "Cloud account id (account-scoped scans)"
},
"diagram_id": {
"type": "string",
"description": "Diagram id/uuid (diagram-scoped scans)"
},
"frameworks": {
"type": "array",
"items": {
"type": "string"
},
"description": "Optional standard/framework ids to scope the scan"
},
"severity_filter": {
"type": "array",
"items": {
"type": "string"
},
"description": "Optional severity levels to include"
},
"simulation_mode": {
"type": "boolean",
"description": "Dry-run the scan without side effects"
},
"source": {
"type": "string",
"description": "Scan source (default: hybrid)"
}
},
"required": [
"scan_type"
],
"additionalProperties": false
}🔴apply_remediation(threat_id, rule_id, resource_context)
Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.
入力スキーマ
{
"type": "object",
"properties": {
"threat_id": {
"type": "string",
"description": "Threat id/code to remediate"
},
"rule_id": {
"type": "string",
"description": "Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)"
},
"resource_context": {
"type": "object",
"description": "provider/resource_id/region/account_id/metadata"
}
},
"required": [
"threat_id",
"rule_id"
],
"additionalProperties": false
}🟢get_diagram_summary(diagram_id)
The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.
入力スキーマ
{
"type": "object",
"properties": {
"diagram_id": {
"type": "string",
"description": "Diagram id/uuid"
}
},
"required": [
"diagram_id"
],
"additionalProperties": false
}🟢get_insights(diagram_id)
Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.
入力スキーマ
{
"type": "object",
"properties": {
"diagram_id": {
"type": "string",
"description": "Diagram id/uuid"
}
},
"required": [
"diagram_id"
],
"additionalProperties": false
}⚪generate_architecture(description, name, style, cloud_provider, compliance_standards, ...)
Generate a multi-tier cloud/AI architecture and auto-synthesize STRIDE/LINDDUN threat models, security requirements, and regulatory control mappings directly from a natural-language description.
入力スキーマ
{
"type": "object",
"properties": {
"description": {
"type": "string",
"description": "Natural-language description of the system or architecture to design"
},
"name": {
"type": "string",
"description": "Optional diagram name"
},
"style": {
"type": "string",
"enum": [
"security",
"cloud",
"network",
"data-flow"
],
"description": "Architecture layout style"
},
"cloud_provider": {
"type": "string",
"enum": [
"aws",
"azure",
"gcp",
"hybrid",
"agnostic"
],
"description": "Target cloud platform"
},
"compliance_standards": {
"type": "array",
"items": {
"type": "string"
},
"description": "Compliance standards to address (e.g. ['EU_AI_ACT', 'DORA', 'NIST_AI_RMF', 'SOC2'])"
},
"save_as_diagram": {
"type": "boolean",
"description": "Persist as an active threat-modeling diagram (default: true)"
}
},
"required": [
"description"
],
"additionalProperties": false
}🟢run_ai_governance_audit(diagram_id, framework, scan_id)
Audit an architecture diagram or code scan against statutory AI governance frameworks (EU AI Act 2024, EU DORA 2022, NIST AI RMF 1.0, ISO 42001). Evaluates article-by-article conformity, satisfied controls, open gaps, and generates actionable remediation guidance.
入力スキーマ
{
"type": "object",
"properties": {
"diagram_id": {
"type": "string",
"description": "Diagram id/uuid to audit"
},
"framework": {
"type": "string",
"description": "Framework identifier: eu-ai-act-2024 | eu-dora-2022 | nist-ai-rmf-1-0 | iso-42001-2023 (default: eu-ai-act-2024)"
},
"scan_id": {
"type": "string",
"description": "Optional code-review scan id for cross-correlated code evidence"
}
},
"required": [
"diagram_id"
],
"additionalProperties": false
}コミュニティ
エビデンス