Agents & MCP
Ground AI agents in the live WhisperGraph over MCP: 7 tools, all read-only, a shared workflow gallery, and evidence behind every answer.
In this chapter
- SetupConnect any MCP client to the Whisper graph: the Connectors Directory listing, per-client config, OAuth and API-key auth, scope grants.
- Your first investigationOne alert, worked end to end over the connector: read the verdict's scope, find why it's listed, follow the pivot the score misses.
- Workflow galleryThe shared gallery of investigation workflows behind the MCP server: discover with list_workflows, run with run_workflow, cite the evidence.
- ReferenceEvery tool, resource and prompt the MCP server exposes — arguments, batch shapes, response fields, the evidence model, and coverage.
- Agent SkillsOpen-source investigation playbooks for the Whisper MCP connector — triage, Cypher authoring, brand protection — as a Claude Code plugin.
- Query languageWhat the query tool accepts, what it refuses before the database sees it, and how to read what comes back.
- ChangelogWhat changed on the Whisper MCP connector, dated; plus the deprecation policy and how to check the live shape right now.
- Programmatic Signup (for Agents)Two HTTP calls to a working Whisper API key — built for agents and automated runtimes, no browser or CAPTCHA, email verification only.
On this page (4)
Agents & MCP Documentation
Every verdict from WhisperGraph carries a coverage block beside the score, and coverage says what was actually looked at. "We have never observed this host" and "we hold data here and nothing malicious is in it" reach an agent as different answers instead of a guess. Every query and run_workflow result also ships an evidence block with the exact Cypher that ran, the row count and the timing, so the agent can cite the query behind each claim.
The other problem is staleness: an assistant answering infrastructure questions from its training data works from a snapshot that ages by the day. Whisper's MCP server at https://mcp.whisper.security connects any MCP-capable client to the live graph — 7.5B nodes and 39.8B edges — so the agent runs the lookup instead of recalling one.
What the server offers
The server speaks MCP over streamable HTTP and advertises 7 tools, 4 resources, and 10 prompts. Every tool reads; none writes, and write and admin Cypher is rejected before it reaches the database, so nothing an agent asks through this connector can change the graph. Every deployment advertises the same seven tools, so tools/list is the contract wherever you connect. The Reference documents each tool, resource and prompt; Setup has the scopes and the data-handling summary.
What the server answers
The server reads Whisper's map of the public internet. It tells you what a domain or IP is — never whether anything in your environment contacted it, so pair it with your SIEM or EDR for that half of the question.
Read
coveragebeforeband. Only known-clean — coverage: known-clean. In coverage, no malicious evidence. licenses the word "clean"; no-data — coverage: no-data. Not in coverage. This is not a verdict — nothing was looked at. means unknown, which is a different thing again; malicious-evidenced — coverage: malicious-evidenced. In coverage, with positive evidence of malice. and ambiguous — coverage: ambiguous. In coverage, and the evidence points both ways. mean there is evidence, whatever the band says. Full contract: Coverage — what we looked at.
Connect
Authentication is always required — there is no anonymous mode: sign in and an API key is created for you automatically, then add the server to your client. In Claude Code:
claude mcp add --transport http whisper-graph https://mcp.whisper.security \
--header "Authorization: Bearer YOUR_API_KEY"
Replace YOUR_API_KEY before you run it. Interactive clients such as Claude Desktop can sign in through OAuth 2.1 instead; Setup has a working config per client.
Where next
Your first investigation works one alert end to end. An agent that speaks plain HTTP can skip MCP entirely and call the HTTP API with an X-API-Key header.