Blackpoint Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Blackpoint Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol (MCP) server for Blackpoint Cyber CompassOne - Managed Detection and Response (MDR) platform.
This MCP server provides access to CompassOne's security capabilities through a decision-tree navigation interface:
The server uses decision-tree navigation to organize tools:
blackpoint_navigate, blackpoint_status)blackpoint_back to return to navigationAll tools follow the pattern: blackpoint_{domain}_{action}
Examples:
blackpoint_assets_list - List assets by classblackpoint_detections_list - List security detectionsblackpoint_vulnerabilities_scans_list - List vulnerability scansnpm install blackpoint-mcp| Variable | Description | Required |
|---|---|---|
BLACKPOINT_API_TOKEN | CompassOne API token | Yes |
BLACKPOINT_BASE_URL | API base URL (may vary by region/partner) | No |
MCP_TRANSPORT | Transport mode: stdio or http | No (default: stdio) |
MCP_HTTP_PORT | HTTP port for gateway mode | No (default: 8080) |
AUTH_MODE | Set to gateway for header-based auth | No |
LOG_LEVEL | Logging level: debug, info, warn, error | No (default: info) |
When AUTH_MODE=gateway, the server reads credentials from HTTP headers:
X-Blackpoint-API-Token → BLACKPOINT_API_TOKENThis enables per-request authentication for multi-tenant gateways.
# Set credentials
export BLACKPOINT_API_TOKEN="your-api-token"
# Run the server
blackpoint-mcpexport AUTH_MODE=gateway
export MCP_TRANSPORT=http
export MCP_HTTP_PORT=8080
blackpoint-mcp// Start by checking available domains
await tools.call("blackpoint_status");
// Navigate to assets domain
await tools.call("blackpoint_navigate", { domain: "assets" });
// List endpoint assets
await tools.call("blackpoint_assets_list", {
class: "endpoint",
pageSize: 10
});
// Get specific asset details
await tools.call("blackpoint_assets_get", {
id: "asset_12345"
});
// Return to navigation
await tools.call("blackpoint_back");| Domain | Tools | Description |
|---|---|---|
| tenants | list, get | Customer tenant management |
| assets | list, get, relationships, search | Asset inventory and relationships |
| detections | list, get | Security detections and telemetry |
| vulnerabilities | list, scans_list, darkweb_list, external_list | Vuln management, dark web, external exposure |
| Domain | Status | Notes |
|---|---|---|
| partners | SDK ready | Account management - ready to implement |
| alerts | Models only | API handlers not available in CompassOne wrapper |
| tickets | Models only | API handlers not available in CompassOne wrapper |
| cloud_security | SDK ready | M365/Google/Cisco onboarding - ready to implement |
| notifications | SDK ready | Contact groups and channels - ready to implement |
CompassOne uses hierarchical scoping: Partner → Tenants → Assets
tenantId parameters to avoid cross-tenant operationsThe server provides structured error responses:
{
"content": [{
"type": "text",
"text": "Failed to list assets: Authentication failed"
}],
"isError": true
}Common error scenarios:
The underlying SDK implements automatic rate limiting:
Retry-After headers# Build
docker build -t blackpoint-mcp .
# Run in gateway mode
docker run -p 8080:8080 \
-e AUTH_MODE=gateway \
-e MCP_TRANSPORT=http \
-e MCP_HTTP_PORT=8080 \
blackpoint-mcp# Install dependencies
npm install
# Run in development mode
npm run dev
# Build
npm run build
# Test
npm test
# Lint
npm run lintThe following operations require confirmation (when implemented):
These use the elicitConfirmation pattern to prevent accidental execution.
No tools showing:
BLACKPOINT_API_TOKEN is setGateway mode not working:
AUTH_MODE=gateway is setRate limiting:
export LOG_LEVEL=debug
blackpoint-mcp# Test basic connectivity
curl -X POST http://localhost:8080/ \
-H "Content-Type: application/json" \
-H "X-Blackpoint-API-Token: your-token" \
-d '{"jsonrpc": "2.0", "method": "tools/list", "id": 1}'git checkout -b feature-nameSee CONTRIBUTING.md for detailed guidelines.
Apache-2.0 - see LICENSE for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.