SecCheck
SecCheck is the second Cert-IX MCP server. Where DepCheck answers "is this dependency safe?", SecCheck answers the much broader question an agent hits the moment it is asked to do real security work:
"How is this actually done, properly, by someone who knows what they are doing?"
What SecCheck gives the agent is a written procedure — one it can follow and you can check. The agent searches the library, loads the playbook that fits the task, and works through it instead of improvising. Most playbooks state when to use them and what you need first, then give the steps in order; many also include verification or validation criteria.
The 857 playbooks — offensive testing, defensive detection and response, and GRC/regulatory compliance — are curated from three open-source libraries, published under the Apache-2.0 and MIT licences and listed below. They are the work of their original authors. What SecCheck adds is the delivery to your agent: one hosted endpoint, search across all three libraries, filters by category and framework, framework-tagged results, and editions tied to your API key.
| Server | SecCheck (security-skills v2.2.1) |
| Public endpoint | https://mcp.cert-ix.com/seccheck |
| Transport | Streamable HTTP (MCP) — works with any MCP client |
| Auth | API key, sent as Authorization: Bearer <key> — free and self-service for the Community edition |
| Tools | list_sources, search_skills, load_skill, list_skill_resources, read_skill_resource, license_status, get_attribution |
| Content | 857 playbooks across 3 open-source libraries — 745 defensive, 69 offensive, 43 compliance |
| Data | Answered from the corpus embedded in the SecCheck server — no upstream API, no fallback lookup. |
Why a playbook server, not a search engine
An agent asked to "hunt for Kerberoasting in our logs" or "get us ready for an ISO 27001 audit" will otherwise improvise from whatever it half-remembers. That produces plausible-looking security work — the most expensive kind of wrong.
SecCheck replaces improvisation with procedure. A playbook is written to be followed: most state their prerequisites and the steps in order, and many say how to check the result. When the agent loads one, its next actions come from a written procedure you can read, not from a guess.
Two properties make that work in practice:
- It is searchable the way an agent thinks — by keyword, by category
(offensive / defensive / compliance), by framework (
MITRE ATT&CK,NIST CSF,GDPR,PCI DSS…), or by tag (splunk,kubernetes,active-directory). - It says when it has nothing. A query that matches no playbook comes back
with an explicit
NO MATCHand the reminder that the library is not exhaustive of all security work — never a silent empty list the model can misread as "no such work exists".
The three libraries
| Library | Key | Skills | What it covers | Licence |
|---|---|---|---|---|
| Cybersecurity Skills | cybersecurity | 817 | Offensive + defensive practice, mapped to MITRE ATT&CK / ATLAS / D3FEND, NIST CSF and NIST AI RMF, and MITRE F3. | Apache-2.0 |
| GRC & Compliance Skills | grc | 30 | Governance, risk and compliance frameworks — ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS and more. | MIT |
| PentesterFlow CLI Skills | pentesterflow | 10 | Focused offensive web-security playbooks — recon, SSRF, SSTI, JWT, GraphQL. | Apache-2.0 |
Call list_sources against the live server for
the current counts and category breakdown — the numbers above are what the
production corpus indexes today.
These libraries are community and third-party work redistributed under their own
permissive licences, with all rights of the original authors retained.
get_attribution returns the upstream,
author, licence and full licence text for every source — that is the notice
you need if you redistribute any of it.
What it is good at
- Finding the right procedure fast — "kerberoasting" returns the detection playbook, the Impacket exploitation playbook and the red-team simulation playbook, each labelled with its category and frameworks, so the agent picks the one that matches the job.
- Framework-anchored compliance work — filter by
GDPR,ISO 27001,SOC 2,PCI DSSorHIPAAand get the playbook for gap analysis, control implementation, evidence collection or document drafting. - Both sides of the fence — the same library covers the attack and the detection for a technique, which is exactly what you want when validating that a control actually works.
- Grounding an agent that would otherwise improvise — the highest-value use. A loaded playbook is a specification the agent can be held to.
What it is not
SecCheck is deliberately scoped, and honest about its edges:
- It returns guidance documents. It does not scan your systems, execute anything, or reach into your environment. Every tool is read-only, and the hosted server has no access to your filesystem.
- It does not adapt a playbook to your environment, track what the agent did, keep a history of your team's work, or check the result. Every caller gets the same document; following it and verifying the outcome are up to the agent and to you.
- The corpus is curated, not exhaustive. A
NO MATCHmeans no playbook covers this, not this is not a real security concern. - Playbooks are written by third parties and reflect their authors' tooling and assumptions. Read one before you run it; adapt commands to your stack.
- It is a knowledge source, not a policy gate or an authorization. Whether a given piece of work is permitted in your environment is your decision, not the library's.
Editions
All 857 playbooks — the guidance itself — are free to search and load on every edition. The paywall is on the runnable material and the enterprise controls:
| Capability | Community | Pro | Enterprise |
|---|---|---|---|
search_skills / load_skill across all 857 playbooks | ✅ | ✅ | ✅ |
list_skill_resources / read_skill_resource — bundled scripts, payloads, references | — | ✅ | ✅ |
| Audit log of tool calls | — | — | ✅ |
| Usage metering | — | — | ✅ |
On the hosted endpoint your edition is bound to your API key and resolved by
the Cert-IX edge on every request — a client cannot assert its own tier. A free
self-service key is always Community; Pro and Enterprise are set on a key by
Cert-IX. Call license_status to see exactly
what your credential unlocks.
This library includes offensive material — exploitation, credential attacks, post-exploitation. It is provided for authorized work: your own systems, an engagement you have written permission for, a CTF, or defensive research. Using it against systems you are not authorized to test is your liability, not Cert-IX's.
Next steps
- Getting started — get a free key and connect your MCP client to the hosted endpoint in a couple of minutes.
- Tools reference — all seven tools, their parameters, and real example responses.
- Agent workflows — the search → load → follow discipline, and how to pair SecCheck with DepCheck.
- Security & data handling — auth, the entitlement model, rate limits, and what does (and does not) leave the Cert-IX perimeter.
Cette page vous a-t-elle été utile ?