Model Context Protocol (MCP) server providing comprehensive cybersecurity intelligence from HUMAN Security. Offers real-time attack monitoring, threat detection, fraud prevention, PCI DSS compliance validation, and supply chain security for AI-powered applications.
The HUMAN Security MCP server demonstrates solid foundation with all 9 tools having descriptions and input schemas. Tool naming follows verb_noun convention consistently (get_*, e.g., human_get_attack_reporting_overtime, human_code_defender_get_incidents). Parameter descriptions are present and mostly informative. However, output schemas are not documented in the source code, responses appear to be opaque API pass-throughs with JSON stringification via mcpToolHandler rather than typed, structured responses with documented fields. Error handling is present (try/catch in mcpToolHandler) but lacks recovery guidance or categorization (retryable vs. fatal). Descriptions are good (avg ~160 chars, within 10-1024 baseline), but some are verbose marketing copy rather than action-focused LLM directives. Schema quality varies: most tools include rich parameter constraints (enums for arrays, optional pagination), but no explicit type definitions visible in parameter definitions, they appear to rely on JSON Schema inference rather than explicit Zod validation in tool registration. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) visible in registration despite risk classification being marked. All tools are READ_ONLY, which is good for safety.
Retrieves comprehensive client-side security incidents from HUMAN Security's Code Defender API, providing critical insights into code integrity threats, supply chain attacks, and browser-based vulnerabilities. This essential security monitoring tool enables proactive defense against modern web application threats.
Retrieves comprehensive account intelligence and security profile from HUMAN Security's Cyberfraud API. This critical investigation tool provides deep insights into individual account behavior, threat exposure, and risk factors for targeted security analysis and incident response.
Fetches comprehensive time-series attack reporting data from HUMAN Security's Cyberfraud API, providing granular insights into attack patterns and security events over time. This powerful analytics tool enables deep temporal analysis of threats and mitigation effectiveness.
Retrieves comprehensive attack cluster intelligence from HUMAN Security's Cyberfraud API, providing detailed analysis of detected threats and their characteristics. This essential threat intelligence tool delivers deep insights into attack patterns, impact, and attribution for informed security decision-making.
Output schemas are not documented. The mcpToolHandler returns responses as JSON-stringified blobs without typed field definitions. LLMs cannot know what fields to expect, forcing them to parse unstructured output and guess at downstream field mappings. This violates the response-shaper pattern and increases hallucination risk.
Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are not present in tool registration despite all tools being marked READ_ONLY. This information should be explicitly declared in the MCP tool definition so clients can make informed safety decisions about tool execution.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 68 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 49 | - | v1 |
Retrieves and manages the complete inventory of custom security rules configured in HUMAN Security's Cyberfraud API. This essential configuration management tool provides comprehensive visibility into your custom mitigation logic and security policies.
Retrieves raw activity records from HUMAN Security's Cyberfraud API, providing detailed individual activity logs and event data for forensic analysis and investigation.
Retrieves comprehensive traffic analysis data from HUMAN Security's Cyberfraud API, providing detailed metrics, overtime trends, and top value analysis for sophisticated security analytics.
Provides comprehensive HTTP security header analysis and monitoring for payment pages and sensitive web applications through HUMAN Security's Code Defender API. This essential security posture and compliance tool enables detailed security header assessment, PCI DSS compliance validation, and web application security optimization.
Provides comprehensive visibility into all JavaScript resources and third-party scripts running on your payment pages and sensitive web applications through HUMAN Security's Code Defender API. This critical compliance and security tool enables complete supply chain risk management and PCI DSS compliance monitoring.
Error responses from mcpToolHandler lack recovery guidance. The handler returns generic error messages ('Unknown error') without actionable next steps. Per recovery-guide pattern, errors should suggest alternatives (e.g., 'Invalid time range. Try narrowing to last 7 days.').
Descriptions are marketing-focused rather than action-focused for LLM selection. E.g., 'Retrieves comprehensive attack cluster intelligence from HUMAN Security's Cyberfraud API, providing detailed analysis...' is verbose. Rewrite as: 'Get attack cluster details: threat types, impact, timeline. Use this to investigate active attack campaigns.' This reduces tokens and clarifies WHEN to call the tool.
Parameters using object types (e.g., 'filters' in human_get_traffic_data) lack sub-field documentation. An LLM cannot construct a valid filters object without knowing its structure. Replace with explicit fields (filter_attack_type, filter_source, etc.) or provide a detailed schema example in the description.
Pagination parameters (page, pageSize, skip, take, offset, limit) are inconsistent across tools. Some use 'page'+'pageSize', others use 'skip'+'take', others use 'offset'+'limit'. This forces the LLM to memorize different signatures for the same concept. Standardize on a single pagination pattern across all tools.
Date/time parameters use ISO 8601 strings (good), but responses likely return raw API timestamps or millisecond epochs (not verified in code). Per mxe:output-date-format, convert timestamps to ISO 8601 or human-readable format in responses to prevent LLM miscalculations.