Home Product Architecture Security Capabilities Install MCP & Skills
DEMO EXPERIENCES โšก Interactive Security Demo ๐Ÿ” View Demo Code (Syntax Highlighted)
About
IntegrationsMCP Server & Agent Skills

Give your coding agent an autonomous security engine.

Connect BreachLabs to Google Antigravity, Claude, Cursor, Windsurf, Roo/Cline, or any MCP-compatible coding agent. Provide your AI pair-programmer with tools to map attack surfaces, inspect source files, verify reachability with targeted probes, and retest patches automatically.

MCP PROTOCOL v1.0 Agent Skills Ready
Model Context Protocol Streamable HTTP & SSE Live Endpoint: /mcp Core API: /api Deterministic Tooling Zero Telemetry Leakage
RECOMMENDED AUTOMATED NPX INSTALLER

Configure All AI Agents with 1 Command

Run the interactive NPX package installer to automatically detect, merge, and configure BreachLabs MCP tools and security skills into Antigravity, Claude, Cursor, Windsurf, or Cline.

$ npx breachlabs
01 Select Agent Platform

Choose your coding environment

Select your primary AI assistant or IDE to view the exact automated CLI command or manual MCP configuration.

RECOMMENDED
Google Antigravity
Built-in subagent tool registration, sidecars, and autonomous skill triggers.
MCP + Builtin Skill Configure โ†’
Desktop & CLI
Claude (Desktop & Code)
Native claude_desktop_config.json and Claude Code CLI integration.
Stdio Server Configure โ†’
IDE Extension
Cursor
Project-level .cursor/mcp.json and tailored .cursorrules.
MCP Tools + Rules Configure โ†’
Cascade Engine
Windsurf / Cascade
Codeium Cascade agent setup via mcp_config.json and workflow instructions.
Cascade Tools Configure โ†’
VS Code Addon
Roo Code / Cline
Direct MCP tool integration in VS Code via cline_mcp_settings.json.
VS Code Settings Configure โ†’
Any MCP Client
Universal / HTTP & SSE
Direct Streamable HTTP at /mcp, SSE event stream at /mcp/sse, or Docker.
Streamable HTTP / SSE Configure โ†’
STEP 1

Google Antigravity MCP Configuration

Add the BreachLabs Streamable HTTP MCP server to your Antigravity agent configuration (e.g. in ~/.gemini/antigravity/mcp/BreachLabs/).

~/.gemini/antigravity/mcp/BreachLabs/mcp.json
{
  "mcpServers": {
    "breachlabs": {
      "url": "http://127.0.0.1:8000/mcp",
      "transport": "streamable-http"
    }
  }
}
STEP 2

Install Security Skill from skills.sh

Install the BreachLabs skill directly into your agent environment using the universal skills.sh package runner with npx, or copy the universal SKILL.md.

Terminal โ€” Universal Skill CLI (skills.sh)
$npx skills add notaayushsrivastava/BreachLabs
# Installs breachlabs autonomous security engineering skill from skills.sh
# Compatible with Antigravity, Claude, Cursor, Windsurf, Cline & Universal agents
02 Exposed MCP Tools

Autonomous tools, bounded execution, zero open shells.

BreachLabs exposes an allowlisted set of structured tools to your agent. Trigger end-to-end sandbox assessments and receive full evidence-backed security reports directly in MCP.

run_assessment

Executes the complete autonomous assessment pipeline in an isolated sandbox and returns the full Markdown & JSON report.

Inputrepo_path, mode, port
OutputMarkdown + Structured JSON Report
list_routes

Enumerates all HTTP routes, form inputs, JSON endpoints, and authentication flows on the target.

Inputtarget_url
OutputRouteTree JSON
run_static_scan

Performs AST-level taint tracking, secret scanning, and unsafe pattern matching across the repository.

Inputrepo_path
OutputTaintSinks[]
run_dast

Executes scoped runtime HTTP probes against the isolated sandbox service to observe response behavior.

Inputpaths, follow_redirects
OutputHTTPResponse alerts[]
verify_installation

Verifies that both BreachLabs MCP server and AI Skill are properly installed and active in the agent environment.

Inputrepo_path
OutputInstallStatus JSON
get_assessment_report

Retrieves the complete Markdown or structured JSON security assessment report for any assessment ID or latest run.

Inputassessment_id, format
OutputMarkdown / JSON Report
communicate

Bidirectional communication tool for the AI agent to consult the security advisor on triage, exploitability, and remediation diffs.

Inputmessage, topic
OutputAdvisory & Guidance JSON
inspect_repository

Inspects repository structure, entry points, dependency manifests, framework architecture, and returns an AI assessment brief.

Inputpath, repo_path
OutputStructure, Tree & Brief
03 Connection Tester

Test Agent MCP Handshake

Verify JSON-RPC protocol compatibility between your coding agent and the BreachLabs MCP server.

MCP PROTOCOL SIMULATOR READY TO TEST
mcp-jsonrpc-session.log
01[READY] Click 'Test Handshake Simulation' to simulate MCP JSON-RPC protocol negotiation.

Start assessing your applications today.

Build with confidence. Ship software backed by deterministic verification.