Wazuh
The Wazuh MCP Server provides a secure bridge between Claude Desktop and Wazuh security data, enabling AI assistants to access real-time security alerts and context. Built with Flask, it authenticates with the Wazuh RESTful API using JWT tokens, retrieves alerts from Elasticsearch indices, and transforms them into standardized MCP-compliant messages. The implementation includes robust error handling for token expiration and network issues, is easily configurable through environment variables, and exposes an HTTP endpoint that Claude Desktop can query to incorporate security event data into conversations, making it valuable for security operations and threat analysis workflows.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.
Scan details: Circle-IR · 2026-09-28 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- security
- Source
- PulseMCP
- Repository
- github.com/gensecaihq/wazuh-mcp-server
- Author type
- human
- Last scanned
- 2026-09-28
- Updated
- 2026-09-28
Use via MCP
Resolve Wazuh from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.