You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The MCP servers from this repo can be used with the following clients
37
167
1. Cline, Claude Desktop, and other MCP supported clients
@@ -43,6 +173,31 @@ The configuration for Claude Desktop and Cline is the same (provided below for [
43
173
44
174
Please refer to the [README file](./run-with-google-adk/README.md) for both - locally running the prebuilt agent and [Cloud Run](https://cloud.google.com/run) deployment.
45
175
176
+
## MCP Client Config Locations
177
+
178
+
MCP clients all use the same JSON configuration format (see the [MCP Server Configuration Reference](https://google.github.io/mcp-security/usage_guide.html#mcp-server-configuration-reference)), but they expect the file in different locations.
179
+
180
+
| Client Application | Scope | macOS / Linux Location | Windows Location | Notes |
|**Gemini CLI**| Global |`~/.gemini/settings.json`|`%USERPROFILE%\.gemini\settings.json`| File must include `mcpServers`. Confirmed in [Google Security Ops post](https://security.googlecloudcommunity.com/google-security-operations-2/google-cloud-security-mcp-servers-in-gemini-cli-922). |
183
+
|**Claude Desktop**| Global |`~/Claude/claude_desktop_config.json`|`%USERPROFILE%\Claude\claude_desktop_config.json`| Config accessible via *Claude > Settings > Developer > Edit Config*. |
184
+
|**Claude Code**| Global |`~/.claude.json`|`%USERPROFILE%\.claude.json`| Primary config file for Claude Code CLI and extensions. |
185
+
|**Cursor IDE (Global)**| Global |`~/.cursor/mcp.json`|`%USERPROFILE%\.cursor\mcp.json`| Enables MCP servers globally across all projects. |
186
+
|**Cursor IDE (Project)**| Project |`<project-root>/.cursor/mcp.json`|`<project-root>/.cursor/mcp.json`| Workspace/project-specific config file. |
187
+
|**VS Code (Workspace)**| Workspace |`<project-root>/.vscode/mcp.json`|`<project-root>/.vscode/mcp.json`| Workspace-level config used when an MCP extension (like **Cline**) is installed. Overrides global config if present. |
188
+
|**Cline (VS Code Ext.)**| Global | Inside VS Code extension data |`%APPDATA%\Code\User\globalStorage\<extension-id>\settings\cline_mcp_settings.json`| Exact path varies by VS Code variant and platform. `<extension-id>` corresponds to the installed extension folder (e.g., `saoudrizwan.claude-dev`). |
-`<project-root>` → folder opened in VS Code or IDE for the project
195
+
-`<extension-id>` → name of the installed extension folder (e.g., `saoudrizwan.claude-dev` for Claude/Cline)
196
+
197
+
### Tip: Single Config with Symlinks
198
+
199
+
If you use multiple MCP clients, you can maintain a **single config file** and symlink it into each expected location. This avoids drift and keeps your server definitions consistent.
Copy file name to clipboardExpand all lines: docs/soar_integrations/active_directory.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ Get the members list of the provided group name in Active Directory
13
13
*`case_id` (str, required): The ID of the case.
14
14
*`alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
15
15
*`group_name` (str, required): Specify whether the name of the group of which you would like to list down the group members.
16
-
*`members_type` (List[Any], required): Specify the member type of the group.
16
+
*`members_type` (List[str], required): Specify the member type of the group.
17
17
*`perform_nested_search` (bool, required): Specify whether the action should fetch additional details regarding groups found in the main group.
18
18
*`limit` (str, required): Specify the maximum number of listings to fetch from Active Directory
19
19
*`target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.
Copy file name to clipboardExpand all lines: docs/soar_integrations/algo_sec.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ List available templates in AlgoSec.
12
12
13
13
*`case_id` (str, required): The ID of the case.
14
14
*`alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
15
-
*`filter_logic` (Optional[List[Any]], optional, default=None): Specify what filter logic should be applied.
15
+
*`filter_logic` (Optional[List[str]], optional, default=None): Specify what filter logic should be applied.
16
16
*`filter_value` (Optional[str], optional, default=None): Specify what value should be used in the filter. If "Equal" is selected, action will try to find the exact match among record types and if "Contains" is selected, action will try to find items that contain that substring. If nothing is provided in this parameter, the filter will not be applied.
17
17
*`max_templates_to_return` (Optional[str], optional, default=None): Specify how many templates to return. Default: 50.
18
18
*`target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.
*`target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.
35
35
*`scope` (str, optional, default="All entities"): Defines the scope for the action.
Copy file name to clipboardExpand all lines: docs/soar_integrations/anomali.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ Enrich entities using information from Anomali ThreatStream. Supported entities:
13
13
*`case_id` (str, required): The ID of the case.
14
14
*`alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
15
15
*`limit` (str, required): Specify how many records to return per entity.
16
-
*`severity_threshold` (Optional[List[Any]], optional, default=None): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
16
+
*`severity_threshold` (Optional[List[str]], optional, default=None): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
17
17
*`confidence_threshold` (Optional[str], optional, default=None): Specify what should be the confidence threshold for the entity, in order to mark it as suspicious. Note: Maximum is 100. If multiple records are found for the entity, action will take the average. Active records have priority. Default: 50.
18
18
*`ignore_false_positive_status` (Optional[bool], optional, default=None): If enabled, action will ignore the false positive status and mark the entity as suspicious based on the "Severity Threshold" and "Confidence Threshold". If disabled, action will never label false positive entities as suspicious, regardless, if they pass the "Severity Threshold" and "Confidence Threshold" conditions or not.
19
19
*`target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.
Copy file name to clipboardExpand all lines: docs/soar_integrations/anomali_threat_stream.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -75,12 +75,12 @@ Submit an observable to Anomali ThreatStream based on IP, URL, Hash, Email entit
75
75
76
76
*`case_id` (str, required): The ID of the case.
77
77
*`alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
78
-
*`classification` (List[Any], required): Specify the classification of the observable.
79
-
*`threat_type` (List[Any], required): Specify the threat type of the observables.
78
+
*`classification` (List[str], required): Specify the classification of the observable.
79
+
*`threat_type` (List[str], required): Specify the threat type of the observables.
80
80
*`source` (Optional[str], optional, default=None): Specify the intelligence source for the observable.
81
81
*`expiration_date` (Optional[str], optional, default=None): Specify the expiration date in days for the observable. If nothing is specified here, action will create an observable that will never expire.
82
82
*`trusted_circle_i_ds` (Optional[str], optional, default=None): Specify the comma-separated list of trusted circle ids. Observables will be shared with those trusted circles.
83
-
*`tlp` (Optional[List[Any]], optional, default=None): Specify the TLP for your observables.
83
+
*`tlp` (Optional[List[str]], optional, default=None): Specify the TLP for your observables.
84
84
*`confidence` (Optional[str], optional, default=None): Specify what should be the confidence for the observable. Note: this parameter will only work, if you create observables in your organization and requires 'Override System Confidence' to be enabled.
85
85
*`override_system_confidence` (Optional[bool], optional, default=None): If enabled, created observables will have the confidence specified in the 'Confidence' parameter. Note: you can't share observables in trusted circles and publicly, when this parameter is enabled.
86
86
*`anonymous_submission` (Optional[bool], optional, default=None): If enabled, action will make an anonymous submission.
@@ -141,7 +141,7 @@ Retrieve information about entities from Anomali ThreatStream. Supported entitie
141
141
142
142
*`case_id` (str, required): The ID of the case.
143
143
*`alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
144
-
*`severity_threshold` (List[Any], required): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
144
+
*`severity_threshold` (List[str], required): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
145
145
*`confidence_threshold` (str, required): Specify what should be the confidence threshold for the entity, in order to mark it as suspicious. Note: Maximum is 100. If multiple records are found for the entity, action will take the average. Active records have priority.
146
146
*`create_insight` (bool, required): If enabled, action will add an insight per processed entity.
147
147
*`only_suspicious_entity_insight` (bool, required): If enabled, action will create insight only for entities that exceeded the "Severity Threshold" and "Confidence Threshold".
0 commit comments