1. Conduid
  2. Developer Tools
  3. Atomic Red Team MCP
MCP server · Developer Tools

Atomic Red Team MCP

MCP server for Atomic Red Team

Unclaimed MIT last commit 6 months ago devtools
77Good

Scored 3 hours ago · breakdown

About Atomic Red Team MCP

Atomic Red Team MCP is an MCP server published by cyberbuff in the Developer Tools category: mCP server for Atomic Red Team. It has been installed 0 times through Conduid.

The repository has 110 stars and 16 forks, with the last commit 6 months ago. Six months or more without a commit doesn't mean the server is broken, but check the open issues (0) before depending on it in production.

Install

Install
npx atomic-red-team-mcp

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Atomic Red Team MCP

Powered by Claude · Grounded in docs

I know everything about Atomic Red Team MCP. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • !Scoped permissionsDoesn't declare a permission scope. Assume it can do anything its process can.

Releases

v1.3.2Release v1.3.2 · 8 Apr 2026Changes in v1.3.2 Version bumped from 1.3.1 to 1.3.2 (patch release) What's Changed See the [commit history](https://github.com/cyberbuff/atomic-red-team-mcp/compare/v1.3.1...v1.3.2) for details. Installation Using uvx (recommended):** uvx…
v1.3.1Release v1.3.1 · 8 Apr 2026Changes in v1.3.1 Version bumped from 1.3.0 to 1.3.1 (patch release) What's Changed See the [commit history](https://github.com/cyberbuff/atomic-red-team-mcp/compare/v1.2.6...v1.3.1) for details. Installation Using uvx (recommended):** uvx…
v1.2.6Release v1.2.6 · 3 Nov 2025Changes in v1.2.6 Version bumped from 1.2.5 to 1.2.6 (patch release) What's Changed See the [commit history](https://github.com/cyberbuff/atomic-red-team-mcp/compare/v1.2.5...v1.2.6) for details. Installation Using uvx (recommended):**…
v1.2.5Release v1.2.5 · 23 Oct 2025Changes in v1.2.5 Version bumped from 1.2.4 to 1.2.5 (patch release) What's Changed See the [commit history](https://github.com/cyberbuff/atomic-red-team-mcp/compare/v1.2.4...v1.2.5) for details. Installation Using uvx (recommended):**…
v1.2.4Release v1.2.4 · 22 Oct 2025Changes in v1.2.4 Version bumped from 1.2.3 to 1.2.4 (patch release) What's Changed See the [commit history](https://github.com/cyberbuff/atomic-red-team-mcp/compare/v1.2.3...v1.2.4) for details. Installation Using uvx (recommended):**…

README

Atomic Red Team MCP Server

An MCP (Model Context Protocol) server that provides access to Atomic Red Team tests.

Available Tools and Resources

The server provides the following MCP tools:

  • query_atomics - Search atomics by technique ID, name, description, or platform
  • refresh_atomics - Download latest atomics from GitHub
  • validate_atomic - Validate atomic test YAML
  • get_validation_schema - Get the atomic test schema
  • execute_atomic - Execute atomic tests (requires ART_EXECUTION_ENABLED=true)

And resources:

  • file://documents/{technique_id} - Read atomic test files by technique ID

Usage Examples

  • "Search mshta atomics for windows"
  • "Show me all the atomic tests for T1059.002"
  • "Find all the applescript atomics for macOS"
  • "Validate this atomic test YAML "

Installation

The Atomic Red Team MCP server can be installed in various development tools and AI assistants. Choose your platform below for detailed installation instructions:

Quick Start

Recommended: Using uvx

uvx atomic-red-team-mcp

Using Docker

docker run --rm -i ghcr.io/cyberbuff/atomic-red-team-mcp:latest

Platform-Specific Guides

Installation Methods

Each platform supports multiple installation methods:

  1. uvx (Recommended) - Easiest setup, automatic updates
  2. Docker - Isolated environment, consistent across systems
  3. Remote Server ⚠️ - Hosted on Railway (free tier, may have limits)

Configuration

Environment Variables

Check the .env.example file for a list of environment variables and their default values.

Server Configuration

  • ART_MCP_TRANSPORT - Transport protocol (stdio, sse, streamable-http)
  • ART_MCP_HOST - Server host address (default: 0.0.0.0)
  • ART_MCP_PORT - Server port number (default: 8000)

Repository Configuration

  • ART_GITHUB_URL - GitHub URL for atomics repository (default: https://github.com)
  • ART_GITHUB_USER - GitHub user/org (default: redcanaryco)
  • ART_GITHUB_REPO - Repository name (default: atomic-red-team)
  • ART_DATA_DIR - Local directory path where atomic test files are stored (default: ./atomics)

Security Configuration

  • ART_EXECUTION_ENABLED - Enable the execute_atomic tool (default: false). Set to true, 1, or yes to enable. ⚠️ WARNING: Only enable in controlled environments as this allows executing potentially dangerous security tests.
  • Enable Authentication if you are hosting a remote MCP server

Authentication Configuration

  • ART_AUTH_TOKEN - Static bearer token for authentication (optional, authentication disabled if not set)
  • ART_AUTH_CLIENT_ID - Client identifier for authenticated requests (default: authorized-client)

Enabling Atomic Test Execution

By default, the execute_atomic tool is disabled for safety reasons. To enable it:

# Using uvx
ART_EXECUTION_ENABLED=true uvx atomic-red-team-mcp

⚠️ Security Warning: Only enable atomic test execution in controlled, isolated environments (like test VMs or sandboxes). These tests can modify system state, create files, execute commands, and perform actions that may be flagged as malicious by security tools.

Authentication

The server supports static token authentication for securing access to the MCP tools and resources. When enabled, clients must include a bearer token in the Authorization header:

Authorization: Bearer <your-token>

To enable authentication:

  1. Set the ART_AUTH_TOKEN environment variable:

    export ART_AUTH_TOKEN="your-secure-token-here"
    
  2. Start the server (authentication is automatically enabled)

  3. Clients authenticate by including the token in requests:

    curl -H "Authorization: Bearer your-secure-token-here" http://localhost:8000
    

Security Notes:

  • Authentication is disabled by default (no token required)
  • When ART_AUTH_TOKEN is set, all requests must include a valid bearer token
  • Use strong, randomly generated tokens in production
  • Never commit tokens to version control
  • For development/testing, use a simple token. For production, use a cryptographically secure token

Example with Docker:

docker run --rm -i \
  -e ART_AUTH_TOKEN="my-secure-token" \
  -e ART_AUTH_CLIENT_ID="my-client" \
  ghcr.io/cyberbuff/atomic-red-team-mcp:latest

Built With

README mirrored from the source repository 3 hours ago. The original is authoritative.

Questions

About Atomic Red Team MCP

How do I install Atomic Red Team MCP?

Run npx atomic-red-team-mcp, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Atomic Red Team MCP safe to use with an AI agent?

Its trust score is 77 out of 100 (good). It passes 0 of 1 static security checks; the failures are listed above. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Atomic Red Team MCP still maintained?

Yes — the latest release is v1.3.2 (8 Apr 2026), and the last commit was 6 months ago. The repository has 110 stars and 0 open issues.