Skip to content
Agents & MCP
Skip navigation
View as Markdown

Agents & MCP

Ground AI agents in the live WhisperGraph over MCP: 7 tools, all read-only, a shared workflow gallery, and evidence behind every answer.

Published Last updated

In this chapter

On this page (4)

Agents & MCP Documentation

Every verdict from WhisperGraph carries a coverage block beside the score, and coverage says what was actually looked at. "We have never observed this host" and "we hold data here and nothing malicious is in it" reach an agent as different answers instead of a guess. Every query and run_workflow result also ships an evidence block with the exact Cypher that ran, the row count and the timing, so the agent can cite the query behind each claim.

The other problem is staleness: an assistant answering infrastructure questions from its training data works from a snapshot that ages by the day. Whisper's MCP server at https://mcp.whisper.security connects any MCP-capable client to the live graph — 7.5B nodes and 39.8B edges — so the agent runs the lookup instead of recalling one.

An MCP client calls a tool; the server validates it, runs read-only Cypher against WhisperGraph, and returns rows with an evidence trail

What the server offers

The server speaks MCP over streamable HTTP and advertises 7 tools, 4 resources, and 10 prompts. Every tool reads; none writes, and write and admin Cypher is rejected before it reaches the database, so nothing an agent asks through this connector can change the graph. Every deployment advertises the same seven tools, so tools/list is the contract wherever you connect. The Reference documents each tool, resource and prompt; Setup has the scopes and the data-handling summary.

What the server answers

The server reads Whisper's map of the public internet. It tells you what a domain or IP is — never whether anything in your environment contacted it, so pair it with your SIEM or EDR for that half of the question.

Read coverage before band. Only known-clean — coverage: known-clean. In coverage, no malicious evidence. licenses the word "clean"; no-data — coverage: no-data. Not in coverage. This is not a verdict — nothing was looked at. means unknown, which is a different thing again; malicious-evidenced — coverage: malicious-evidenced. In coverage, with positive evidence of malice. and ambiguous — coverage: ambiguous. In coverage, and the evidence points both ways. mean there is evidence, whatever the band says. Full contract: Coverage — what we looked at.

Connect

Authentication is always required — there is no anonymous mode: sign in and an API key is created for you automatically, then add the server to your client. In Claude Code:

bash
claude mcp add --transport http whisper-graph https://mcp.whisper.security \
  --header "Authorization: Bearer YOUR_API_KEY"

Replace YOUR_API_KEY before you run it. Interactive clients such as Claude Desktop can sign in through OAuth 2.1 instead; Setup has a working config per client.

Where next

Your first investigation works one alert end to end. An agent that speaks plain HTTP can skip MCP entirely and call the HTTP API with an X-API-Key header.