aribot

Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.

사용해야 할까요

품질 및 안전성

A
설명 품질
98%
스키마 완전성
96%
이름 품질
93%
오염 위험
80%
권한 일치
100%
프로토콜 준수
100%

발견 사항 (3)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains suspicious base64-like encoded stringonboard_agents에서
  • LOWTool 'apply_remediation' description lacks action verbapply_remediation에서

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~2,486토큰 (도구 정의)
~999 B일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 1.94%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "aribot": {
      "url": "https://mcp.aribot.ayurak.com/mcp"
    }
  }
}

원격 엔드포인트

https://mcp.aribot.ayurak.com/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (16)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢get_billing(checkout_request_id, topup_amount, request_plan)

Billing status + self-service payment for your company: credit-wallet balance, pay-per-use flag, license tier / annual commitment, per-action prices, purchasable plans, and any approved-but-unpaid plans. Pass `checkout_request_id` to get a hosted Stripe Checkout URL to COMPLETE an approved plan, `topup_amount` (EUR) to get one to TOP UP the wallet, or `request_plan` (starter|pay_per_use|pro|max|enterprise) to REQUEST a plan (files a request for super-admin approval — never grants). Use this to view or RESOLVE a 402 without leaving the connector.

입력 스키마

{
  "type": "object",
  "properties": {
    "checkout_request_id": {
      "type": "string",
      "description": "Approved license_request_id to complete payment for (returns a hosted Checkout URL)"
    },
    "topup_amount": {
      "type": "number",
      "description": "Optional EUR amount to top up the credit wallet (returns a hosted Checkout URL)"
    },
    "request_plan": {
      "type": "string",
      "description": "Optional plan key to request (pro|max|…) — files a request for super-admin approval; does not grant or charge"
    }
  },
  "required": [],
  "additionalProperties": false
}
⚪onboard_agents(agents, agent_cards, cohort, auto_suspend_threshold)

Bulk-onboard agent identities to the governed fleet (Agent Governance). Accepts plain ids or {agent_id} descriptors in `agents`, A2A 1.0 Agent Cards in `agent_cards` (name/url/provider/version/protocolVersion), or MCP client descriptors, under an optional `cohort` + shared auto-suspend policy. Idempotent. Requires the agent_governance licence + a manage:agents grant (or a first-party super-admin). Agents also self-onboard on first token/call.

입력 스키마

{
  "type": "object",
  "properties": {
    "agents": {
      "type": "array",
      "items": {},
      "description": "Agent ids or descriptors ({agent_id, display?, cohort?})"
    },
    "agent_cards": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "A2A 1.0 Agent Cards ({name, url, provider, version, protocolVersion, ...})"
    },
    "cohort": {
      "type": "string",
      "description": "Optional shared cohort (provider/model/deployment group)"
    },
    "auto_suspend_threshold": {
      "type": "number",
      "description": "Optional 0..1 auto-suspend deviation threshold for the cohort policy"
    }
  },
  "required": [],
  "additionalProperties": false
}
🟡generate_threat_model(name, nodes, edges)

Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.

입력 스키마

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Threat model name"
    },
    "nodes": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "ReactFlow nodes (each: id, position, data.label)"
    },
    "edges": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "ReactFlow edges"
    }
  },
  "required": [
    "nodes"
  ],
  "additionalProperties": false
}
🟢verify_threats_in_code(scan_id, threat_id, repository_id, code_content, async_)

Verify whether threats are mitigated in a scan's uploaded code. With `threat_id`, verifies one threat synchronously and returns the verdict; without it, verifies every diagram threat in the background. Wraps code_review ThreatVerificationService.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "CodeReviewScan id (uuid)"
    },
    "threat_id": {
      "type": "string",
      "description": "Optional: a single threat id or code"
    },
    "repository_id": {
      "type": "string",
      "description": "Optional connected repo to fetch code from"
    },
    "code_content": {
      "type": "string",
      "description": "Optional inline code context"
    },
    "async_": {
      "type": "boolean",
      "default": true
    }
  },
  "required": [
    "scan_id"
  ],
  "additionalProperties": false
}
🟢get_traceability(scan_id)

Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "Code-review scan id"
    }
  },
  "required": [
    "scan_id"
  ],
  "additionalProperties": false
}
🟢get_framework_coverage(diagram_id, framework, include_graph)

Compliance-framework coverage for a diagram (real, ControlCodeMap-backed), optionally for one framework, plus an optional crossmap relationship graph. Wraps derive_framework_coverage + crossmap_cypher.build_graph.

입력 스키마

{
  "type": "object",
  "properties": {
    "diagram_id": {
      "type": "string",
      "description": "Diagram pk or uuid"
    },
    "framework": {
      "type": "string",
      "description": "Optional framework filter (e.g. 'NIST-800-53', 'SOC2')"
    },
    "include_graph": {
      "type": "boolean",
      "description": "Also return the crossmap node/edge graph",
      "default": false
    }
  },
  "required": [
    "diagram_id"
  ],
  "additionalProperties": false
}
🟢get_remediation(threat_id, rule_id, resource_context)

Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.

입력 스키마

{
  "type": "object",
  "properties": {
    "threat_id": {
      "type": "string",
      "description": "Threat id/code to remediate"
    },
    "rule_id": {
      "type": "string",
      "description": "Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)"
    },
    "resource_context": {
      "type": "object",
      "description": "provider/resource_id/region/account_id/metadata"
    }
  },
  "required": [
    "threat_id",
    "rule_id"
  ],
  "additionalProperties": false
}
🟢compliance_status(scan_id, diagram_id)

Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceability company rollup.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "Optional anchor scan; latest is used if omitted"
    },
    "diagram_id": {
      "type": "string",
      "description": "Optional diagram to add framework coverage for"
    }
  },
  "required": [],
  "additionalProperties": false
}
⚪discover_shadow_ai(scan_id, limit)

Shadow-AI posture (part of Code Security): unsanctioned / unknown AI-service usage discovered in code — totals, risk score, provider/type breakdown, hardcoded-key count, and top discoveries. Company latest, or one scan with `scan_id`. Reads code_review ShadowAIReport/ShadowAIDiscovery.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "Optional CodeReviewScan id; company-wide latest if omitted"
    },
    "limit": {
      "type": "integer",
      "description": "Max discoveries to return",
      "default": 15
    }
  },
  "required": [],
  "additionalProperties": false
}
🟢get_api_security(scan_id, limit)

API security inventory (part of Code Security): discovered API endpoints with authentication status, risk level and risk factors, plus method/risk breakdowns. Company-wide or one scan with `scan_id`. Reads code_review ApiEndpointDiscovery.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "Optional CodeReviewScan id; company-wide if omitted"
    },
    "limit": {
      "type": "integer",
      "description": "Max endpoints to return",
      "default": 20
    }
  },
  "required": [],
  "additionalProperties": false
}
🟢get_cloud_compliance(account_id)

Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Account.latest_scan -> compliances.ScanResults.

입력 스키마

{
  "type": "object",
  "properties": {
    "account_id": {
      "type": "string",
      "description": "Optional single cloud Account id; all company accounts if omitted"
    }
  },
  "required": [],
  "additionalProperties": false
}
⚪code_review_scan(scan_id)

Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "Id of an existing code-review scan to (re)run"
    }
  },
  "required": [
    "scan_id"
  ],
  "additionalProperties": false
}
⚪compliance_scan(scan_type, account_id, diagram_id, frameworks, severity_filter, ...)

Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.

입력 스키마

{
  "type": "object",
  "properties": {
    "scan_type": {
      "type": "string",
      "enum": [
        "platform",
        "compliance",
        "pipeline",
        "sbom",
        "diagram",
        "account"
      ],
      "description": "platform | compliance | pipeline | sbom"
    },
    "account_id": {
      "type": "string",
      "description": "Cloud account id (account-scoped scans)"
    },
    "diagram_id": {
      "type": "string",
      "description": "Diagram id/uuid (diagram-scoped scans)"
    },
    "frameworks": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Optional standard/framework ids to scope the scan"
    },
    "severity_filter": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Optional severity levels to include"
    },
    "simulation_mode": {
      "type": "boolean",
      "description": "Dry-run the scan without side effects"
    },
    "source": {
      "type": "string",
      "description": "Scan source (default: hybrid)"
    }
  },
  "required": [
    "scan_type"
  ],
  "additionalProperties": false
}
🔴apply_remediation(threat_id, rule_id, resource_context)

Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.

입력 스키마

{
  "type": "object",
  "properties": {
    "threat_id": {
      "type": "string",
      "description": "Threat id/code to remediate"
    },
    "rule_id": {
      "type": "string",
      "description": "Policy/rule id (e.g. AWS_S3_PUBLIC_ACCESS)"
    },
    "resource_context": {
      "type": "object",
      "description": "provider/resource_id/region/account_id/metadata"
    }
  },
  "required": [
    "threat_id",
    "rule_id"
  ],
  "additionalProperties": false
}
🟢get_diagram_summary(diagram_id)

The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.

입력 스키마

{
  "type": "object",
  "properties": {
    "diagram_id": {
      "type": "string",
      "description": "Diagram id/uuid"
    }
  },
  "required": [
    "diagram_id"
  ],
  "additionalProperties": false
}
🟢get_insights(diagram_id)

Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.

입력 스키마

{
  "type": "object",
  "properties": {
    "diagram_id": {
      "type": "string",
      "description": "Diagram id/uuid"
    }
  },
  "required": [
    "diagram_id"
  ],
  "additionalProperties": false
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 16개
검증됨버전이 기록되지 않음도구 16개
검증됨버전이 기록되지 않음도구 16개