
Magicsword Mcp
io.github.magicsword-iov0.1.0Updated Oct 7, 2026
Manage MagicSword endpoints, alerts, policies, and private intelligence through MCP.
Overview
Lets an assistant manage MagicSword endpoint security conversationally: list endpoints, query and triage alerts, edit policies, and manage private intel feeds.
- What it does
- A local stdio MCP server wrapping the MagicSword customer API. It exposes 21 tools for listing endpoints and agent releases, searching alerts and audit or block events, triaging alerts, viewing and editing policies and their rules, previewing and applying policy assignments, flipping policies to enforcing, upgrading endpoints, requesting check-ins, minting enrollment tokens, and managing private intel feeds and items. Write tools require matching API scopes, and destructive actions use preview-then-confirm flows.
- When to use it
- Use it when you run MagicSword and want an MCP-aware client such as Claude Desktop or Cursor to inspect your fleet, triage alerts, review events, or make policy and intel changes without leaving the chat. It is aimed at Enterprise-plan organizations; pilot-tier keys get a plan-gate message and nothing else works.
- Requirements
- Node.js 22 or newer, installed from npm as @magicsword-io/magicsword-mcp. A MagicSword customer API key (msk_...) from Magic Portal settings, supplied via the MAGICSWORD_API_KEY environment variable or the configure command, which writes ~/.magicsword/mcp.json with mode 600. Network access to the configured portal base URL, HTTPS by default. Write tools need matching Customer API scopes such as alerts:write, policies:write, endpoints:write, or intel:write.
Installation
In SourceWeft
- Open Magicsword Mcp in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
magicsword-mcp
A Model Context Protocol server for MagicSword. Lets users running Claude Desktop, Cursor, or any MCP-aware client manage MagicSword conversationally — list endpoints, query alerts, triage findings, mint enrollment tokens, and preview / commit policy changes.
The server is a thin, opinionated wrapper around the
/api/public/v1/* customer API exposed by the Magic Portal. It runs on
the user's machine, holds an msk_… API key, and speaks MCP over stdio.
Plan gate. The customer API is Enterprise-only. With a pilot-tier key the server returns a clear "this MagicSword org needs the Enterprise plan to use MCP" message; nothing else works until the org is upgraded.
Install
From npm
Requires Node 22+. After publication, MCP clients that consume the official
Registry can discover this server as
io.github.magicsword-io/magicsword-mcp. Homebrew, winget, and curl packaging
can follow if demand justifies maintaining signed platform artifacts.
Configure
You'll be prompted for an API key (mint one in Magic Portal → Settings →
API Keys) and a portal base URL (defaults to https://www.magicsword.io).
The command writes ~/.magicsword/mcp.json (mode 600) and prints the exact
JSON snippet to paste into Claude Desktop's config:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Linux:
~/.config/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
The snippet looks like this:
Restart Claude Desktop and "magicsword" will appear with 21 tools. Logs are
at ~/Library/Logs/Claude/mcp*.log on macOS.
If you need a per-client override instead of ~/.magicsword/mcp.json, set
MAGICSWORD_API_KEY and optionally MAGICSWORD_BASE_URL in that MCP host's
environment. Keep API keys out of shared config snippets and screenshots.
Tools
Write tools require matching Customer API scopes in Magic Portal, such as
alerts:write, policies:write, endpoints:write, or intel:write.
Event review uses alerts:read; turning selected events into policy rules
uses policies:write.
Tools publish standard MCP safety annotations. Read-only discovery tools are marked read-only and idempotent; enforcement, deletion, policy assignment, rule changes, and agent upgrades are marked destructive so MCP clients can apply appropriate confirmation UX.
Example transcript
Configuration sources, in order of precedence
MAGICSWORD_API_KEY/MAGICSWORD_BASE_URLenv vars (set by the MCP host).~/.magicsword/mcp.json(or$MAGICSWORD_CONFIG).- Default base URL
https://www.magicsword.io.
Optional transport controls are MAGICSWORD_REQUEST_TIMEOUT_MS (default
30 seconds), MAGICSWORD_RESPONSE_MAX_BYTES (default 4 MiB), and
MAGICSWORD_GET_RETRIES (default 2, maximum 3). Only idempotent GET requests
are retried; write actions are never retried automatically.
Safety notes
flip_to_enforcingis two-step. The first call returns a server preview and one-time confirmation token; you must show the preview to a human and pass the token back to commit. Tokens are short-lived and single-use.- Fleet changes and deletion are explicit. Endpoint upgrades, policy
assignments, and private-intel deletion return a no-op preview unless the
approved follow-up call includes
confirm=true. - Windows WDAC policy edits should not use explicit flat file hashes.
Use
manage_policy_ruleswithevent_idswhen approving audit events so the Portal can derive supported path / publisher / filename rules, or useupsert_customer_intel_itemsfor hash, AuthentiHash, page-hash, and TBS intelligence in a private feed. - Secrets stay on the user's machine. The MCP server is a local stdio
process; the API key is read from
~/.magicsword/mcp.json(mode 600) or an env var passed by the MCP host. Nothing is sent off-machine except the requests to the configuredMAGICSWORD_BASE_URL. - Remote Portal URLs must use HTTPS. Plain HTTP is accepted only for localhost development. Configured URLs cannot contain credentials, paths, query strings, or fragments.
Develop
Tests validate --help, --version, configure validation, secret redaction,
modern and legacy MCP startup, focused mutation confirmation, retry and timeout
semantics, response-size bounds, malformed responses, write non-retry behavior,
and npm pack contents. test:package installs a production-only tarball and
checks the installed CLI and MCP tool discovery; release:verify checks all
release metadata. See docs/RELEASING.md for npm and MCP Registry releases.
Source: README.md at commit 981980f
Tools
0Version history
1- v0.1.0LatestOct 7, 2026

