googlegoogleOfficialยท5 Agent Skills Included

mcp-security

Security alert triage, threat hunting, and incident investigation

Connects Google's security products, including Chronicle SIEM, SOAR, Threat Intelligence, and Security Command Center, to your workflows. Automates alert triage, IOC enrichment, threat hunting, and case management without manual console clicking. Guides analysts through proven investigation playbooks and generates reports, cutting response time from hours to minutes.
npx skills add google/mcp-security --all -g -y

All Skills in This Repository (5)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install mcp-security?โ–ผ

Run `npx skills add google/mcp-security --all -g -y` in your terminal to install all skills in this suite globally.

How to automate security alert triage?โ–ผ

The triage skill walks your agent through a standard protocol: gathering case context, checking duplicates, enriching indicators, and classifying alerts as false positives or true threats.

Can I hunt threats in Chronicle SIEM with plain English?โ–ผ

Yes. The hunt skill translates your natural language requests into UDM queries, searches for IOCs and MITRE ATT&CK techniques, and documents findings in SOAR cases.

Does mcp-security work with Gemini CLI and Claude?โ–ผ

Yes. The servers follow the MCP standard and include setup skills for Gemini CLI and Antigravity, plus configurations for Claude Desktop, Claude Code, Cursor, and Cline.

What Google security products does it connect to?โ–ผ

It connects to Google Security Operations (Chronicle SIEM), SecOps SOAR, Google Threat Intelligence, and Security Command Center, each as a separate server you can enable independently.

Related Repositories in Legal & Compliance

View All in Legal & Complianceโ†’