Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Live page: https://aristiun.github.io/aribot-mcp/ Β· Product: https://aribot.ayurak.com Β· Registry: io.github.aristiun/aribot
Aribot is a security tool from Ayurak / Aristiun, available as a remote Model Context Protocol (MCP) server. Connect it to any MCP client β ChatGPT, Gemini, Claude, or your own β and run real security work from the assistant you already use, without switching tools.
This repository is a public manifest for the hosted server. It contains no product code β only the connection details. The server requires OAuth, so listing its address exposes nothing without an authorized login.
Aribot builds one threat model per system and layers every discipline onto it β security (STRIDE + LINDDUN), cloud posture (AWS Β· Azure Β· GCP), compliance (NIST Β· ISO 27001 Β· SOC 2), and the economics of each risk (value at risk, cost to fix, dollars saved once healed) β all kept traceable end to end:
Threat β Requirement β Control β Framework β Code β Fix
Ask for any link in that chain, in either direction, with evidence behind every finding and every fix.
Point any MCP client at the server and complete the OAuth prompt:
| Transport | Streamable HTTP |
| Auth | OAuth 2.1 (Authorization Code + PKCE; Dynamic Client Registration) |
| Homepage | https://aribot.ayurak.com |
OAuth is discovered automatically at https://mcp.aribot.ayurak.com/.well-known/oauth-authorization-server.
Example (Claude Code):
Each call is checked against your company's licence, the OAuth scopes you granted (read:findings, read:threatmodel, read:insights, run:scan, run:codereview, write:threatmodel, run:remediation), your team's roles, and your tenant boundary. Usage is metered, and every action is logged. So you can run security work from an assistant without losing track of who can do what, or which company's data is which.
generate_threat_model Β· verify_threats_in_code Β· get_traceability Β· get_framework_coverage Β· compliance_status Β· discover_shadow_ai Β· get_api_security Β· get_cloud_compliance Β· get_remediation Β· get_billing
See the full tool list and pricing at https://ayurak.com/pricing.
Β© Ayurak / Aristiun. "Aribot" and "Ayurak" are trademarks of their owner. This manifest is provided for MCP discovery under the MIT License (see LICENSE).
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/aribot)<a href="https://allmcps.com/mcp/aribot"><img src="https://allmcps.com/api/badge/aribot?style=directory" alt="Aribot on AllMCPs" /></a>