Bits MCP
The Bits MCP is a public Model Context Protocol server that helps you adopt the Cert-IX Bits host agents. It advises and prepares: it recommends an agent, explains what that agent observes and what it never does, gives you a download you can verify — version, file size, SHA-256 and a verify command — and drafts a configuration for a human to review. It never acts on your estate.
Point your AI client at it once, and you can ask things like "which agent tells me what's listening on my hosts?" or "draft me a bitcollector config for an unprivileged Linux host" and get answers grounded in what the agents actually do.
https://mcp.cert-ix.com/bits
No account, no API key
Unlike DepCheck and SecCheck, this endpoint needs no credential of any kind. There is nothing to request, nothing to rotate, and nothing to leak.
That is possible because of what it deliberately cannot do: it reads only the public release catalogue. It knows no tenant, no host, and no user. It cannot see your fleet, cannot enrol an agent, and cannot change anything anywhere.
The Bits MCP helps you choose, verify and configure. Enrolling an agent and deploying to your fleet happen inside your Cert-IX dashboard, from an authenticated session. That separation is deliberate — an AI client can help you prepare, but only a signed-in human can act on your estate.
Enrolment uses a token generated in your Cert-IX dashboard. That token goes on
the machine the agent runs on — never paste it into the MCP.
bits_plan_config and bits_download refuse any argument shaped like an
enrolment token, and tell you where the token belongs instead.
What you can ask it
| Tool | Answers |
|---|---|
bits_recommend | "I need X" → which agent fits, including "none of these do" |
bits_explain | What an agent observes, what it never touches, what privilege changes |
bits_platforms | Which OS and architecture each agent ships on today |
bits_plan_config | A host profile → a draft config for a human to review, plus what it will not do |
bits_download | One agent and platform → the download URL, version, file size, SHA-256 and a command to verify it |
See the tools reference for parameters and output shapes.
What it will not tell you
This matters more than the feature list, because an AI client will relay whatever it receives as though it were certain.
It never guesses. If the release catalogue cannot be read — or can be read but not verified — the answer is an explicit failure, never an empty list. "We looked and found nothing" and "we could not look" are different answers, and only one of them is safe to act on.
It never collapses separate facts. An agent can ship a signed binary for a platform, not yet have an enrolment path, and never report a heartbeat. Those are three independent facts, and the tools keep them apart. Flattening them into "supported: yes" would be true and misleading.
It never writes an acknowledgement on your behalf. Some Bits settings require
the operator to assert something — most importantly, that you are legally
authorised to send unsolicited packets onto a network. bits_plan_config will
never place that assertion in a config for you. It will tell you the setting
exists, what it means, and that only you can make the claim.
It never returns an install command. Its output goes into an AI client's
context alongside text from your own environment, so executable instructions are
kept to a minimum. bits_download is the only tool that returns a link and a
command: the download URL for one binary, always with its SHA-256, and a command
that fetches the file and checks that checksum. Nothing here installs, enrols or
runs anything — read the command before you use it, and verify the checksum
before you run the binary.
Bilingual
Every description and every human-readable line comes back in English and French.
Next
- Getting started — connect Claude Code, Claude Desktop, Cursor or VS Code
- Tools reference — parameters, outputs, and the failure shapes worth handling
Questa pagina ti è stata utile?