Give your coding agent an autonomous security engine.
Connect BreachLabs to Google Antigravity, Claude, Cursor, Windsurf, Roo/Cline, or any MCP-compatible coding agent. Provide your AI pair-programmer with tools to map attack surfaces, inspect source files, verify reachability with targeted probes, and retest patches automatically.
/mcp
Core API: /api
Deterministic Tooling
Zero Telemetry Leakage
Configure All AI Agents with 1 Command
Run the interactive NPX package installer to automatically detect, merge, and configure BreachLabs MCP tools and security skills into Antigravity, Claude, Cursor, Windsurf, or Cline.
Choose your coding environment
Select your primary AI assistant or IDE to view the exact automated CLI command or manual MCP configuration.
claude_desktop_config.json and Claude Code CLI integration..cursor/mcp.json and tailored .cursorrules.mcp_config.json and workflow instructions.cline_mcp_settings.json./mcp, SSE event stream at /mcp/sse, or Docker.Google Antigravity MCP Configuration
Add the BreachLabs Streamable HTTP MCP server to your Antigravity agent configuration (e.g. in ~/.gemini/antigravity/mcp/BreachLabs/).
{
"mcpServers": {
"breachlabs": {
"url": "http://127.0.0.1:8000/mcp",
"transport": "streamable-http"
}
}
}
Install Security Skill from skills.sh
Install the BreachLabs skill directly into your agent environment using the universal skills.sh package runner with npx, or copy the universal SKILL.md.
Autonomous tools, bounded execution, zero open shells.
BreachLabs exposes an allowlisted set of structured tools to your agent. Trigger end-to-end sandbox assessments and receive full evidence-backed security reports directly in MCP.
Executes the complete autonomous assessment pipeline in an isolated sandbox and returns the full Markdown & JSON report.
Enumerates all HTTP routes, form inputs, JSON endpoints, and authentication flows on the target.
Performs AST-level taint tracking, secret scanning, and unsafe pattern matching across the repository.
Executes scoped runtime HTTP probes against the isolated sandbox service to observe response behavior.
Verifies that both BreachLabs MCP server and AI Skill are properly installed and active in the agent environment.
Retrieves the complete Markdown or structured JSON security assessment report for any assessment ID or latest run.
Bidirectional communication tool for the AI agent to consult the security advisor on triage, exploitability, and remediation diffs.
Inspects repository structure, entry points, dependency manifests, framework architecture, and returns an AI assessment brief.
Test Agent MCP Handshake
Verify JSON-RPC protocol compatibility between your coding agent and the BreachLabs MCP server.
Start assessing your applications today.
Build with confidence. Ship software backed by deterministic verification.