MCP App Store
by KeenEthics
Data-Analytics

Orca Security

by Orca Security

Overview

The Orca MCP Server extends Orca's reasoning into Claude, so your team can ask security questions from where the work already happens: Claude.ai in the browser, the Claude desktop app, and Claude Code in the terminal. The MCP Server carries correlated context from Orca's Unified Data Model, not raw data streams. Every asset, alert, identity, and dependency is already stitched together before Claude is asked a question, so answers factor in reachability, blast radius, and business impact from the first response. Tools that stitch sources together at query time return inconsistent, fragmented conclusions. Ask Claude to run in-depth analysis on an alert, query assets, investigate the code origins of a runtime risk, generate an executive readout, or kick off a remediation workflow. All of it happens without leaving Claude. Every response pulls asset, attack path, ownership, and remediation context in a single call, so end users get senior-analyst judgment baked into every answer. For teams that want the reasoning without writing the prompts, Orca maintains the AI Skills Hub, an open-source GitHub repo of agent skills that sits on top of the MCP Server. Analysts type "triage alert orca-9012345" in Claude, and the orca-alert-triage skill handles retrieval, analysis, and formatting. Teams can fork it, modify it, and extend it to their own use cases. The result: security and engineering teams work across cloud, code, and AI from a single workspace, with Claude as the interface and Orca's reasoning behind every answer.

Tools

add_alert_comment

Claude

change_alert_score

Claude

dismiss_alert

Claude

get_alert

Claude

get_alert_attack_path_data

Claude

get_alert_code_origin

Claude

get_alert_timeline

Claude

get_alerts_with_similar_alert_type

Claude

get_alerts_with_similar_malware

Claude

get_asset_alerts_count_grouped_by_risk_level

Claude

get_asset_by_alert_id

Claude

get_asset_by_id

Claude

get_asset_by_name

Claude

get_asset_crown_jewel_info

Claude

get_assets_with_similar_malware

Claude

get_attack_path

Claude

get_aws_effective_permissions_policy_on_asset

Claude

get_business_units_data

Claude

get_cdr_events_grouped_by_event_name

Claude

get_code_origin

Claude

get_compliance_analysis_by_account_or_business_unit

Claude

get_compliance_framework_control_tests

Claude

get_compliance_framework_stats_for_asset

Claude

get_compliance_trend_over_time

Claude

get_control_test_alerts

Claude

get_control_test_assets

Claude

get_enabled_compliance_frameworks

Claude

get_framework_assets_with_failed_controls_count

Claude

get_integration_configs_data

Claude

get_linked_entities_data

Claude

get_linked_entities_mapping

Claude

get_other_secret_occurrences

Claude

get_scm_posture_alerts_on_asset

Claude

get_terraform_chain

Claude

mark_asset_as_crown_jewel

Claude

search_cdr_events

Claude

snooze_alert

Claude

update_alert_status

Claude

verify_alert

Claude

App Stats

47

Tools

Claude

Platforms

Works with

Claude

Data refreshed daily