# Crowdsentinel MCP Server (MCP server)

> Crowdsentinel MCP Server is an MCP server that adds database tools to AI assistants such as Claude Desktop, Claude Code and Cursor. AI threat hunting & incident response for Elasticsearch/OpenSearch with endpoint & network forensics. It has 208 GitHub stars, is released under the GPL-3.0 license and runs locally with uvx crowdsentinel-mcp-server.

Open-source threat hunting orchestrator connecting LLMs to enterprise security data via Model Context Protocol (MCP) Warning This project is in active development and intended for security testing, research, and educational purposes only. It is not production-ready. Do not deploy in production environments. APIs, tool interfaces, and data formats may change without notice. Use at your own risk.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/thomasxm/CrowdSentinels-AI-MCP |
| GitHub stars | 208 |
| License | GPL-3.0 |
| Language | Python |
| Transport | stdio |
| Packages | pypi: crowdsentinel-mcp-server |
| Remote URL | none |
| Needs API key | yes |
| Official | no |
| Works with | Claude Desktop, Claude Code, Cursor, VS Code |
| Category | Databases |
| Latest release | v0.6.0 (Jul 19, 2026) |
| Last commit | Jul 19, 2026 |
| MCP registry name | io.github.thomasxm/crowdsentinel-mcp-server |

## Install

### Claude Desktop (claude_desktop_config.json)

```json
{
  "mcpServers": {
    "crowdsentinel-mcp-server": {
      "command": "uvx",
      "args": [
        "crowdsentinel-mcp-server"
      ],
      "env": {
        "ELASTICSEARCH_API_KEY": "your-value",
        "ELASTICSEARCH_PASSWORD": "your-value",
        "ELASTICSEARCH_BEARER_TOKEN": "your-value"
      }
    }
  }
}
```

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

### Claude Code

```sh
claude mcp add --env ELASTICSEARCH_API_KEY=your-value --env ELASTICSEARCH_PASSWORD=your-value --env ELASTICSEARCH_BEARER_TOKEN=your-value --transport stdio crowdsentinel-mcp-server -- uvx crowdsentinel-mcp-server
```

### Cursor (.cursor/mcp.json)

```json
{
  "mcpServers": {
    "crowdsentinel-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "crowdsentinel-mcp-server"
      ],
      "env": {
        "ELASTICSEARCH_API_KEY": "your-value",
        "ELASTICSEARCH_PASSWORD": "your-value",
        "ELASTICSEARCH_BEARER_TOKEN": "your-value"
      }
    }
  }
}
```

Project file; use ~/.cursor/mcp.json to enable it in every project.

### VS Code (.vscode/mcp.json)

```json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "elasticsearch_api_key",
      "description": "ELASTICSEARCH_API_KEY",
      "password": true
    },
    {
      "type": "promptString",
      "id": "elasticsearch_password",
      "description": "ELASTICSEARCH_PASSWORD",
      "password": true
    },
    {
      "type": "promptString",
      "id": "elasticsearch_bearer_token",
      "description": "ELASTICSEARCH_BEARER_TOKEN",
      "password": true
    }
  ],
  "servers": {
    "crowdsentinel-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "crowdsentinel-mcp-server"
      ],
      "env": {
        "ELASTICSEARCH_API_KEY": "${input:elasticsearch_api_key}",
        "ELASTICSEARCH_PASSWORD": "${input:elasticsearch_password}",
        "ELASTICSEARCH_BEARER_TOKEN": "${input:elasticsearch_bearer_token}"
      }
    }
  }
}
```

Config formats checked against the official docs on 2026-10-07.

## Environment variables

- `ELASTICSEARCH_HOSTS`: Comma-separated Elasticsearch hosts. Supports HTTP/HTTPS, local/remote/cloud (e.g., http://localhost:9200, https://es.prod.example.com:9200)
- `ELASTICSEARCH_CLOUD_ID`: Elastic Cloud deployment ID (alternative to ELASTICSEARCH_HOSTS for cloud deployments)
- `ELASTICSEARCH_API_KEY` (secret): API key for authentication (recommended for production and Elastic Cloud)
- `ELASTICSEARCH_USERNAME`: Username for basic authentication (alternative to API key)
- `ELASTICSEARCH_PASSWORD` (secret): Password for basic authentication (used with ELASTICSEARCH_USERNAME)
- `ELASTICSEARCH_BEARER_TOKEN` (secret): Bearer/service token for authentication (alternative to API key)
- `VERIFY_CERTS`: TLS certificate verification: true (verify CA — production), false (skip — dev/test), or /path/to/ca.crt (custom CA)
- `REQUEST_TIMEOUT`: Request timeout in seconds (e.g., 60 or 10.5)

## Similar MCP servers

- [Dbx](https://appsgit.com/mcp-servers/dbx): Query databases from AI agents using connections configured in DBX. (24,945 stars, Apache-2.0)
- [Butterbase AI MCP Server](https://appsgit.com/mcp-servers/butterbase-ai-mcp-server): Butterbase MCP server — manage your backend: schemas, auth, functions, storage, RAG, deploys. (3,686 stars, Apache-2.0, needs API key)
- [DBHub](https://appsgit.com/mcp-servers/dbhub): Token-efficient database MCP server for PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, SQLite. (3,610 stars, MIT, needs API key)
- [LINQ to DB](https://appsgit.com/mcp-servers/linq-to-db): Inspect database schemas and execute SQL queries across multiple database providers with LINQ to DB. (3,332 stars, MIT)
- [Mindwtr](https://appsgit.com/mcp-servers/mindwtr): Task automation via SQLite, desktop Local API, or Mindwtr Cloud; read-only by default. (2,211 stars, AGPL-3.0, needs API key)
- [MCP Memory Service](https://appsgit.com/mcp-servers/mcp-memory-service): Open-source persistent memory for AI agent pipelines (LangGraph, CrewAI, AutoGen) and Claude. (1,988 stars, Apache-2.0)

---

Canonical page: https://appsgit.com/mcp-servers/crowdsentinel-mcp-server
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
