Tracecat

Secure Annex MCP server

Investigate browser extension risk, vulnerabilities, and code review findings across Chrome, Edge, and Firefox.

Endpoint
http
Official docs

About

Connect Tracecat to Secure Annex to investigate browser extension risk from agents working alongside SOC and IT teams. You can search extensions by name or ID and pull the full risk profile, including permissions, contacted domains, and known vulnerabilities, when triaging a suspicious browser process. From there, agents can review AI-generated security assessments, inspect past code review findings, and decide whether to block, allowlist, or escalate without leaving the case.

Setup

  1. 1

    Create an API key

    The Secure Annex MCP server authenticates with a Secure Annex API key passed as the `SECUREANNEX_API_KEY` environment variable. The key is issued from your Secure Annex account and scoped to your tenant's catalog of analyzed extensions.

  2. 2

    Select the Secure Annex tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the Secure Annex tile, and paste your API key.

  3. 3

    Enable Secure Annex in your agent

    In your ai.agent action or Agents tools tab, select Secure Annex from the MCP integrations dropdown.

Tools

search_extensionsFind extensions by name, ID, owner, or other criteria.
get_extension_detailsRetrieve detailed metadata for a specific browser extension.
get_extension_versionsAccess the version history of an extension.
get_extension_vulnerabilitiesIdentify known security vulnerabilities in an extension.
get_extension_signaturesRetrieve security signatures associated with an extension.
get_extension_urlsExtract network domains contacted by an extension.
get_extension_manifest_risksAnalyze permission and manifest-related risks.
get_extension_analysisObtain an AI-powered security assessment of an extension.
get_extension_code_reviewGet a code-level security evaluation of an extension.
get_recent_updatesView extensions that were recently updated in the Secure Annex catalog.

Deploy the Secure Annex MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.

Self-host free