SentinelOne Purple AI MCP Server - provides tools for security operations including alerts, vulnerabilities, misconfigurations, threat intelligence, inventory queries, and PowerQuery SDL access
Purple MCP has 33 tools across security domains (alerts, vulnerabilities, misconfigurations, inventory, threat intel, CVE). Tool naming follows verb_noun conventions consistently (get_*, list_*, search_*). Descriptions are present for all tools but vary significantly in quality and completeness. Critical gap: parameter schemas are not visible in provided source, only tool names and basic descriptions are evident. Without access to actual parameter definitions, schema validation cannot be confirmed. Risk assessment shows all tools are READ_ONLY, which is appropriate for a security analytics platform. The server imports tool definitions from separate modules (alerts.py, sdl.py, etc.) but the actual parameter schemas, types, and constraints are not shown in the excerpt provided, making it impossible to verify JSON Schema compliance for input validation or output structure documentation.
Check the status of the CVE database
Search CVE database by CVE ID
Search CVE database by vendor
Retrieve a specific alert by ID
Retrieve history/timeline of a specific alert
Retrieve AI investigation report for a specific alert
Retrieve notes associated with a specific alert
Retrieve a specific inventory item by ID
Input schemas not visible in source code. Cannot verify parameter types, descriptions, constraints, or validation rules. All 33 tools score 0 on schema dimension.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 25 | - | v1 |
Retrieve a specific misconfiguration by ID
Retrieve history/timeline of a specific misconfiguration
Retrieve notes associated with a specific misconfiguration
Get timestamp range for SDL queries
Retrieve a specific vulnerability by ID
Retrieve history/timeline of a specific vulnerability
Retrieve notes associated with a specific vulnerability
Convert ISO 8601 timestamp to Unix timestamp
List alerts with optional filtering
List inventory items with optional filtering
List misconfigurations with optional filtering
List vulnerabilities with optional filtering
Execute PowerQuery SDL queries against Singularity Data Lake
Purple AI tool for security analysis
Search for alerts matching criteria
Search for inventory items matching criteria
Search for misconfigurations matching criteria
Search for vulnerabilities matching criteria
Query threat intelligence data by domain
Query threat intelligence data by file hash
Query threat intelligence data by IP address
Query threat intelligence data by URL
Retrieve file behavior analysis from threat intelligence
Retrieve file relationships from threat intelligence
Search threat intelligence data
Tool descriptions are uniformly brief (40-65 chars) and lack context for LLM selection. Examples: 'Execute PowerQuery SDL queries against Singularity Data Lake' (55 chars), 'Retrieve a specific alert by ID' (31 chars). None explain WHEN to use or what prerequisites exist. Baseline for good descriptions is 194 chars average; these fall below p10 threshold.
No evidence of output schema documentation. Tools return data but LLMs cannot infer what fields are present, types, or whether pagination is offered. Critical for chaining tools and preventing hallucination of nonexistent fields.
Pattern clustering without clear differentiation: 9 tool pairs follow get/list/search pattern (alerts, misconfigurations, vulnerabilities, inventory, threat_intel). Without detailed descriptions explaining when to use search vs list vs get, LLMs must guess. Names alone do not disambiguate (e.g., search_alerts vs list_alerts both filter; why two?).
No error handling guidance visible. Tools do not appear to document what happens on failure, how to recover, or which errors are retryable. This violates the recovery-guide pattern.
No tool annotations detected (readOnlyHint, destructiveHint, idempotentHint). While all tools are marked READ_ONLY in the risk assessment, this is not expressed in tool definitions. MCP spec 2026-07-28 supports tool annotations for client safety hints.