AI MCP
Overview
Section titled “Overview”Evidence: AI MCP
Description: Extract MCP server definitions and execution surface from AI tool configs
Category: AI
Platform: macos
Short Name: aimcp
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No
Background
Section titled “Background”Model Context Protocol (MCP) servers are the execution bridge between AI agents and external systems. Configured servers can launch local commands, expose environment variables, or connect to remote endpoints.
Data Collected
Section titled “Data Collected”This collector gathers structured data about MCP servers, including server name, launch command and arguments, environment-variable names, transport, URL host, and risk flags.
Collection Method
Section titled “Collection Method”This collector scans claude_desktop_config.json, .mcp.json, and mcp.json in per-user and per-project scope and extracts each defined MCP server.
Forensic Value
Section titled “Forensic Value”Inventories every MCP server configured on the host. Risk flags highlight remote servers, risky launchers, broad environment exposure, and suspicious command patterns that can extend an agent’s reach.