MCP server for the Vectra AI Platform - exposes detection, investigation, and response tools to AI assistants.
The Vectra AI MCP server demonstrates solid definition quality across 26 tools. Strengths include consistent naming patterns (all tools use verb_noun format: list_, get_, create_, delete_), comprehensive parameter schemas with proper JSON Schema types, and detailed descriptions that explain filtering and sorting behavior. However, several notable gaps reduce the score: (1) Output schemas are not explicitly documented in the visible source code, tools return JSON strings but the structure is not formally declared for LLM consumption. (2) No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite the server declaring READ_ONLY and WRITE risk classifications. (3) Error handling guidance is minimal, no recovery hints or per-item success/failure reporting for batch operations. (4) Some parameter descriptions are verbose but lack actionable format constraints (e.g., date strings documented as YYYY-MM-DDTHH:MM:SS but not enforced via pattern fields). (5) Tool descriptions occasionally conflate similar tools (list_detection_ids vs list_detections_with_basic_info vs list_detections_with_details) without clearly explaining when each should be used. Spot-check: get_detection_details has a clear description and proper input schema; list_detections_with_details has comprehensive filtering but no output schema documentation; create_entity_note is a WRITE operation but the description doesn't mention idempotency or retry behavior.
Create investigation assignment for an account or host
Add an investigation note to an entity (host or account).
Delete an investigation assignment.
Get complete detailed information about a specific account entity. This tool returns account details including detections, scoring information, associated accounts, access history, detection summaries, external data, and more. Response can be customized using various parameters to include or exclude specific fields and related data.
Retrieve details of a specific investigation assignment.
Retrieve investigation assignment for a specific account.
Output schemas not formally documented. Tools return JSON strings but the structure/fields are not declared, forcing LLMs to parse unstructured responses without advance knowledge of available fields. This prevents proper downstream tool chaining and increases hallucination risk.
No tool annotations despite declared risk classifications. Server metadata lists READ_ONLY and WRITE operations, but tools lack readOnlyHint/destructiveHint annotations. This prevents clients from distinguishing safe operations from destructive ones for UI/UX optimization and safety gates.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | C | 69 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 12 | - | v1 |
Get the total count of detections matching the specified criteria.
Get complete detailed information for a particular detection.
Get pcap file for a specific detection.
Get summarized detection information including counts by category and state.
Get complete detailed information about a specific host entity.
Get results from a completed investigation.
Get platform health, a specific health category, or complete diagnostics.
List all investigation assignments with optional filtering by timestamp and resolved state.
List all investigation assignments assigned to a user/analyst.
List detection IDs with optional filtering and sorting.
List detections with basic information including filtering and sorting options.
List detections with filtering and sorting options. Use this to get a detailed list of detections based on various criteria.
List entities (hosts & accounts) in Vectra platform based on various filters. This tool returns entities with all their detailed information.
List all detections with full details for a specific entity.
List entities that are currently in lockdown.
List users in the Vectra platform.
Retrieve information about an entity (account or host) by its name. Search is case-insensitive and can match partial names.
Lookup host entity by IP address.
Marks or unmark detection as fixed. For marking as fixed, the detection will be closed as remediated, indicating it has been addressed.
Run an investigation query on detections or entities.
Three highly similar list tools (list_detection_ids, list_detections_with_basic_info, list_detections_with_details) with nearly identical filtering parameters. Descriptions do not clearly explain the difference or when to use each. This creates ambiguity for LLM tool selection and violates single-responsibility principle.
Minimal error handling guidance. Tools lack recovery hints, actionable error messages, or guidance for retryable vs non-retryable failures. E.g., run_investigation() and get_investigation_results() give no indication of failure modes or expected latency.
Batch operations (mark_detection_fixed with array of detection_ids) lack per-item success/failure reporting. If 1 detection out of 50 fails, the entire operation fails, forcing retry of all 50.
WRITE operations lack idempotency guarantees or confirmation steps. create_assignment and create_entity_note do not indicate whether repeated calls with the same input are safe or risk duplicate records/assignments.
Date/time parameters documented as YYYY-MM-DDTHH:MM:SS but not enforced via JSON Schema pattern constraints. LLMs may pass invalid formats (e.g., 2024-13-45) without validation, causing API errors.
run_investigation and get_investigation_results have minimal documentation. investigation_query parameter is described as 'Investigation query string' with no syntax, examples, or link to query documentation. LLMs cannot construct valid queries.