# Wazuh

> Use this tool when you need to integrate real-time security alerts and context into AI-powered conversations, enabling threat analysis and security operations workflows. It solves problems of accessing and standardizing security data by bridging Wazuh security tools with AI assistants through a secure API. The Wazuh MCP Server takes in JWT tokens and Elasticsearch indices as inputs and outputs standardized MCP-compliant messages through an HTTP endpoint.

Canonical page: https://skillsregistry.net/skills/unmuktoai-wazuh  
JSON: https://api.skillsregistry.net/v1/skills/unmuktoai-wazuh

## Description

The Wazuh MCP Server provides a secure bridge between Claude Desktop and Wazuh security data, enabling AI assistants to access real-time security alerts and context. Built with Flask, it authenticates with the Wazuh RESTful API using JWT tokens, retrieves alerts from Elasticsearch indices, and transforms them into standardized MCP-compliant messages. The implementation includes robust error handling for token expiration and network issues, is easily configurable through environment variables, and exposes an HTTP endpoint that Claude Desktop can query to incorporate security event data into conversations, making it valuable for security operations and threat analysis workflows.

## Trust

- **Trust score (0–1):** 0.00
- **Verification tier:** scanned
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/unmuktoai-wazuh)
- **Repository:** <https://github.com/gensecaihq/wazuh-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "unmuktoai-wazuh"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/unmuktoai-wazuh` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/unmuktoai-wazuh/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
