gensecaihq/Wazuh-MCP-Server ? reverse-engineered prompt

Reverse engineered prompt

Build me a production ready MCP server for Wazuh that lets me talk to my SIEM in plain language.

I want it to connect to a Wazuh deployment and expose tools for alert triage, threat hunting, vulnerability checks, compliance reports, agent monitoring, cluster health, and active response actions like blocking IPs, isolating hosts, and rolling those actions back. It should work with Claude Desktop and other MCP clients, and also support fully local use with something like Open WebUI and Ollama so it can run air gapped.

Please make it feel secure and SOC friendly, with scopes or permissions for read versus write actions, audit logging, and good validation around anything that changes the environment. Use Docker and simple environment based setup so I can run it quickly, and include a clean health check plus docs for connecting it to Wazuh and an AI assistant. If you need current MCP or Wazuh details, look up the latest docs online.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab