Overview
The Orca MCP Server extends Orca's reasoning into Claude, so your team can ask security questions from where the work already happens: Claude.ai in the browser, the Claude desktop app, and Claude Code in the terminal. The MCP Server carries correlated context from Orca's Unified Data Model, not raw data streams. Every asset, alert, identity, and dependency is already stitched together before Claude is asked a question, so answers factor in reachability, blast radius, and business impact from the first response. Tools that stitch sources together at query time return inconsistent, fragmented conclusions. Ask Claude to run in-depth analysis on an alert, query assets, investigate the code origins of a runtime risk, generate an executive readout, or kick off a remediation workflow. All of it happens without leaving Claude. Every response pulls asset, attack path, ownership, and remediation context in a single call, so end users get senior-analyst judgment baked into every answer. For teams that want the reasoning without writing the prompts, Orca maintains the AI Skills Hub, an open-source GitHub repo of agent skills that sits on top of the MCP Server. Analysts type "triage alert orca-9012345" in Claude, and the orca-alert-triage skill handles retrieval, analysis, and formatting. Teams can fork it, modify it, and extend it to their own use cases. The result: security and engineering teams work across cloud, code, and AI from a single workspace, with Claude as the interface and Orca's reasoning behind every answer.
Tools
change_alert_score
Claudediscovery_search
Claudedismiss_alert
Claudedocumentation_search
Claudeget_alert
Claudeget_alert_attack_path_data
Claudeget_alert_code_origin
Claudeget_alert_timeline
Claudeget_alerts_with_similar_alert_type
Claudeget_alerts_with_similar_malware
Claudeget_asset_alerts_count_grouped_by_risk_level
Claudeget_asset_by_alert_id
Claudeget_asset_by_id
Claudeget_asset_by_name
Claudeget_asset_crown_jewel_info
Claudeget_asset_related_alerts_summary
Claudeget_asset_related_attack_paths
Claudeget_asset_related_attack_paths_summary
Claudeget_assets_with_similar_malware
Claudeget_attack_path
Claudeget_aws_effective_permissions_policy_on_asset
Claudeget_business_units_data
Claudeget_cdr_events_grouped_by_event_name
Claudeget_code_origin
Claudeget_compliance_analysis_by_account_or_business_unit
Claudeget_compliance_framework_control_tests
Claudeget_compliance_framework_stats_for_asset
Claudeget_compliance_trend_over_time
Claudeget_control_test_alerts
Claudeget_control_test_assets
Claudeget_enabled_compliance_frameworks
Claudeget_framework_assets_with_failed_controls_count
Claudeget_integration_configs_data
Claudeget_linked_entities_data
Claudeget_linked_entities_mapping
Claudeget_other_secret_occurrences
Claudeget_recommended_compliance_frameworks_to_enable
Claudeget_related_compliance_frameworks_for_asset
Claudeget_scm_posture_alerts_on_asset
Claudeget_terraform_chain
Claudeget_trending_news
Claudemark_asset_as_crown_jewel
Claudesearch_cdr_events
Claudesnooze_alert
Claudeupdate_alert_status
Claudeverify_alert
ClaudeLinks
App Stats
47
Tools
3
Prompts
ChatGPT, Claude
Platforms
Category
Risk ScreeningWorks with
Data refreshed daily






