AgentHubAgentHub

ThreatLocker MCP Setup & Guide

MCP ServerMCP RegistryOfficial

io.github.Servosity/threatlocker-mcp · v0.3.7

Every ThreatLocker Portal API feature, plus the write operations the read-only tools lack and a

Copy the install config on this page first, then verify docs and permissions upstream.

Overview

Every ThreatLocker Portal API feature, plus the write operations the read-only tools lack and a ThreatLocker MCP is a MCP Server listed from MCP Registry. Transports: stdio. This page includes an overview, setup tutorial, install commands, and use cases for Trae, Tongyi Lingma, Cursor, Claude Code, and VS Code.

Use cases

AgentHub Verified AvailabilityTested & Ready

Automated pipeline validated install commands, protocol & client compatibility

Verified At2026-10-04
Install Snippets TestedCLI & JSON config syntax verified
Protocol Handshake ReadyComplies with JSON-RPC 2.0 specifications
Origin Registry ActiveSourced from official-mcp-registry
Verified ClientsClaude Code、Claude Desktop、Cursor 等
Security Tier: A+ 级 · 官方认证推荐 (A+)·Maintained by official/verified teams, audited for standard MCP protocol compliance.
No auto-generated install guide — see the source repository README.

Troubleshooting & Common ErrorsFAQ

Common connection errors and verified fixes for ThreatLocker MCP

Getting 'connection closed' or exit code 1 in Cursor / Claude Code for ThreatLocker MCP?

Usually caused by missing runtime paths or IDE environment inheritance. Fix steps: 1. Verify Node.js 18+ (npx) or Python 3.10+ (uvx) is installed; 2. Run 'which npx' or 'which uvx' in terminal, and replace 'command' with absolute path; 3. Reload or restart the client window after modifying config.

Fix Snippet
# Check binary path in terminal:
which npx
node -v
Getting 'spawn npx ENOENT' or 'command not found'?

The editor background process does not inherit your full terminal PATH. Solution: Globally install the package, or set the absolute binary path (e.g. C:\Program Files\nodejs\npx.cmd on Windows, or /usr/local/bin/npx on macOS).

Missing required environment variable or authentication failure?

ThreatLocker MCP requires environment variables (PRINTING_PRESS_CLIENT_PROFILE、THREATLOCKER_API_KEY). Ensure you have added valid keys under the 'env' object in your config file without trailing whitespace.

Fix Snippet
// .cursor/mcp.json 或 claude_desktop_config.json
{
  "env": {
    "PRINTING_PRESS_CLIENT_PROFILE": "your_actual_key_here"
  }
}

Tool Mock Playground

Sandbox

ThreatLocker MCP Tool Interface Simulation · Preview tool schema & outputs without local runtime

Sandbox Ready
fn: threatlocker_mcpExecute the core tool interface of ThreatLocker MCP
Request ArgumentsJSON Schema
{
  "target": "ThreatLocker MCP",
  "action": "execute",
  "options": {
    "mode": "standard",
    "timeoutMs": 5000
  }
}
💡Parameters generated dynamically by Agent runtime
Agent Tool Output

Click 'Run Mock' above

to preview the raw response returned to the LLM

Env: AgentHub Virtual SandboxJSON-RPC 2.0

Decision Guide: Why & When to Use

Assess suitability before installing to save trial-and-error time

Best Suited For
  • PR review
  • Changelog generation
  • Cross-repo issue search
When NOT to Use
  • Replacing human security audit
  • Unauthorized repo access
Recommended Workflow Pairing:View Scenario →

ThreatLocker MCP + Scenario Prompt → Complete Agent Automation

MCP hands-on: install to visible results

Follow the full lab (expected UI/output + contrast checks). After installing this item, verify with the tutorial prompts.

Open tutorial →

Related resources

Often paired with

Keep exploring AgentHub

Most people compare similar tools or check scenario guides before installing—start here.

Listing badge: put AgentHub on your site

Copy either snippet into your project homepage, docs, or GitHub README. The badge is a hotlinked SVG — nothing to host — and it links back to this page so visitors can find the install steps.

PreviewListed on AgentHub: ThreatLocker MCP
HTML
<a href="https://myagenthub.cn/p/io.github.Servosity/threatlocker-mcp" title="Listed on AgentHub: ThreatLocker MCP" target="_blank" rel="noopener">
  <img src="https://myagenthub.cn/badge/io.github.Servosity/threatlocker-mcp?lang=en" alt="Listed on AgentHub: ThreatLocker MCP" height="20" style="border:0"/>
</a>
Markdown (GitHub README)
[![Listed on AgentHub: ThreatLocker MCP](https://myagenthub.cn/badge/io.github.Servosity/threatlocker-mcp?lang=en)](https://myagenthub.cn/p/io.github.Servosity/threatlocker-mcp)

Badges are generated on the fly from /badge/<package-id>, so name and listing changes propagate automatically. Keep the link target unchanged — it is what counts as the referral.

Unified Manifest

{
  "id": "io.github.Servosity/threatlocker-mcp",
  "type": "mcp-server",
  "version": "0.3.7",
  "displayName": "ThreatLocker MCP",
  "description": "Every ThreatLocker Portal API feature, plus the write operations the read-only tools lack and a",
  "repository": {
    "url": "https://github.com/servosity/msp-skills",
    "source": "github",
    "subfolder": "skills/threatlocker"
  },
  "distribution": {
    "packages": [
      {
        "registryType": "mcpb",
        "identifier": "https://github.com/Servosity/msp-skills/releases/download/threatlocker-v0.3.7/threatlocker-mcp.mcpb",
        "version": "0.3.7",
        "transport": "stdio",
        "environmentVariables": [
          {
            "name": "PRINTING_PRESS_CLIENT_PROFILE",
            "description": "Set the PRINTING_PRESS_CLIENT_PROFILE credential for the ThreatLocker MCP server.",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "THREATLOCKER_API_KEY",
            "description": "Portal API key (ThreatLocker portal: Settings > API Keys), sent as the Authorization header on every call.",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "THREATLOCKER_BASE_URL",
            "description": "Base URL for the ThreatLocker API. Leave the prefilled default unless your account uses a different regional or self-hosted host."
          },
          {
            "name": "THREATLOCKER_ORG_ID",
            "description": "Tenant GUID sent as ManagedOrganizationId (the --org flag overrides it). Most Portal API data calls answer 401/403 without it, so set it unless you pass --org on every call."
          },
          {
            "name": "THREATLOCKER_USER_AGENT",
            "description": "Overrides the User-Agent the CLI sends on ThreatLocker requests. Leave blank to use the CLI's own built-in User-Agent."
          }
        ]
      }
    ],
    "remotes": []
  },
  "dependencies": [],
  "installTargets": [
    "claude-code",
    "claude-desktop",
    "cursor",
    "vscode",
    "trae",
    "cherry-studio",
    "lingma",
    "windsurf",
    "cline",
    "workbuddy"
  ],
  "keywords": [],
  "provenance": {
    "origin": "official-mcp-registry",
    "originalId": "io.github.Servosity/threatlocker-mcp",
    "originalUrl": "https://registry.modelcontextprotocol.io/v0.1/servers/io.github.Servosity%2Fthreatlocker-mcp/versions/latest",
    "isOfficial": true,
    "status": "active"
  }
}