# CyberAgents Exchange — Full Reference > A community directory of open-source cybersecurity AI agents, skills, MCP servers, and playbooks. This site is a directory: each listing is metadata pointing at code and content in its author's GitHub repository. The JSON endpoints below publish every listing, generated from the same data as the site's pages. ## How to use this data Fetch in two steps rather than all at once: 1. **The index** — https://exchange.tenable.com/api/listings.json — one short row per listing, 115 in all (21 agents, 67 skills, 23 mcp servers, 4 playbooks). Filter it by `type`, `tier`, `integrations`, `domains` or `tags` to find candidates. 2. **The detail record** — fetch a candidate's `json_url` for everything the site publishes about it: review dates, MCP tools, skill invocation, playbook agent chains. Then use `github_url` to read the code, and `url` to link a person to the listing page. ## JSON endpoints - **Index of every listing**: https://exchange.tenable.com/api/listings.json - **One agent**: https://exchange.tenable.com/api/agents/.json - **One skill**: https://exchange.tenable.com/api/skills/.json - **One mcp server**: https://exchange.tenable.com/api/mcp-servers/.json - **One playbook**: https://exchange.tenable.com/api/playbooks/.json All endpoints return JSON with CORS open to any origin. Dates are calendar dates (`YYYY-MM-DD`). Optional fields are omitted when a listing does not set them, rather than sent as `null`. --- ## Index rows (`/api/listings.json`) A JSON array, ordered by `type` then `slug`. Each row has: | Field | Type | Description | |-------|------|-------------| | `type` | enum | `agent`, `skill`, `mcp-server`, or `playbook` | | `slug` | string | URL-friendly identifier, unique within its type | | `name` | string | Display name | | `author` | string | Creator or maintainer | | `description` | string | What the listing does | | `tier` | enum | Trust tier — see Trust Tiers below | | `tags` | string[] | Free-form descriptive tags | | `integrations` | string[] | Products and platforms it works with, from the Integrations vocabulary | | `domains` | string[] | One or two security domains, from the Domains vocabulary (optional) | | `url` | string (URL) | The listing's page on CyberAgents Exchange | | `json_url` | string (URL) | This listing's full detail record as JSON | ## Detail records (`/api//.json`) A single JSON object. ### Common fields Every detail record has these, whatever its type: | Field | Type | Description | |-------|------|-------------| | `type` | enum | `agent`, `skill`, `mcp-server`, or `playbook` | | `slug` | string | URL-friendly identifier, unique within its type | | `name` | string | Display name | | `author` | string | Creator or maintainer | | `description` | string | What the listing does | | `github_url` | string (URL) | Source repository — the code lives there, not on this site | | `license` | string | License identifier, e.g. `MIT`, `Apache-2.0` | | `tier` | enum | Trust tier — see Trust Tiers below | | `tags` | string[] | Free-form descriptive tags | | `integrations` | string[] | Products and platforms it works with, from the Integrations vocabulary | | `domains` | string[] | One or two security domains, from the Domains vocabulary (optional) | | `date_added` | date | When the listing was added (`YYYY-MM-DD`) | | `last_reviewed` | date | Date of the most recent baseline maintainer review (optional) | | `vetted_on` | date | Date the Exchange Inspector security review passed (vetted tier only) (optional) | | `vetted_commit_sha` | string | Git commit the vetted review covered (vetted tier only) (optional) | | `works_with_tenable_hexa_mcp` | boolean | Designed to work with the Tenable Hexa AI MCP server (optional) | | `url` | string (URL) | The listing's page on CyberAgents Exchange | | `json_url` | string (URL) | This listing's full detail record as JSON | ### Agent (`agent`) Detail URL: https://exchange.tenable.com/api/agents/.json Common fields only. ### Skill (`skill`) Detail URL: https://exchange.tenable.com/api/skills/.json Common fields, plus: | Field | Type | Description | |-------|------|-------------| | `compatible_platforms` | string[] | AI coding platforms the skill runs on, from the Platforms vocabulary | | `invocation` | string | How to invoke the skill once installed | ### MCP server (`mcp-server`) Detail URL: https://exchange.tenable.com/api/mcp-servers/.json Common fields, plus: | Field | Type | Description | |-------|------|-------------| | `transport` | enum | MCP transport, from the Transports vocabulary | | `runtime` | enum | Runtime the server needs, from the Runtimes vocabulary | | `auth_method` | enum | How the server authenticates, from the Auth methods vocabulary | | `compatible_clients` | string[] | MCP clients it is known to work with, from the Clients vocabulary | | `tools_exposed` | { name, description }[] | MCP tools the server exposes | | `resources_exposed` | { name, description }[] | MCP resources the server exposes | | `prompts_exposed` | { name, description }[] | MCP prompts the server exposes | ### Playbook (`playbook`) Detail URL: https://exchange.tenable.com/api/playbooks/.json Common fields, plus: | Field | Type | Description | |-------|------|-------------| | `playbook_type` | enum | `standard`, `sponsored`, or `n8n` | | `agents_used` | object[] | Ordered chain of agents in the workflow — see Agent Chain below (optional) | | `logo` | string (URL) | Sponsor logo (`sponsored` playbooks only) (optional) | | `workflow_diagram` | string | n8n workflow diagram source (`n8n` playbooks only) (optional) | ### Agent chain (`agents_used`) Each entry in a playbook's `agents_used` is one step in its workflow: | Field | Type | Description | |-------|------|-------------| | `name` | string | Display name of the agent | | `role` | string | What this agent does in the workflow | | `type` | enum | `exchange`, `github`, `vendor`, or `info` — see below | | `ref` | string | Depends on `type` | - `exchange` — `ref` is the slug of a listing on CyberAgents Exchange - `github` — `ref` is a GitHub URL for an agent not listed here - `vendor` — `ref` is a vendor URL (`sponsored` playbooks only) - `info` — `ref` is optional; a manual step or context-only entry --- ## Trust tiers Values of `tier`: - `contributed` — passed automated validation and a baseline maintainer review - `vetted` — passed the Exchange Inspector security review process A vetted listing also carries `vetted_on` and `vetted_commit_sha`: the review covers that commit, not later changes. See https://exchange.tenable.com/security-review-process for full tier definitions. ## Controlled vocabularies Fields marked as drawing from a vocabulary only ever hold these exact strings. ### Integrations Values of `integrations`: Anthropic, AWS, Azure, Check Point, Cisco, CrowdStrike, Firebase, Fortinet, GCP, KnowBe4, Microsoft Sentinel, Mimecast, Netskope, NVD, PagerDuty, Palo Alto, Qualys, Rapid7, Recorded Future, SentinelOne, ServiceNow, Snyk, Splunk, Supabase, Tenable, Tenable Hexa AI MCP, URLScan.io, VirusTotal, Wiz, Checkmarx One, SecurityScorecard ### Domains Values of `domains`: - `ai-security` — AI Security - `application-security` — Application Security - `cloud-security` — Cloud Security - `cryptography-pki` — Cryptography & PKI - `data-security` — Data Security - `email-collaboration-security` — Email & Collaboration Security - `governance-risk-compliance` — Governance, Risk & Compliance - `identity-access` — Identity & Access - `network-security` — Network Security - `ot-iot-security` — OT/IoT Security - `platform-operations` — Platform Operations - `security-awareness` — Security Awareness - `security-operations` — Security Operations - `threat-intelligence` — Threat Intelligence - `vulnerability-management` — Vulnerability Management ### Platforms (skills) Values of `compatible_platforms`: Claude Code, Claude Desktop, Claude Cowork, Cline, Codex, Cursor, Gemini CLI, GitHub Copilot, Windsurf ### Transports (MCP servers) Values of `transport`: stdio, http, both ### Runtimes (MCP servers) Values of `runtime`: binary, bun, go, node, python, rust ### Auth methods (MCP servers) Values of `auth_method`: api-key, none, oauth2, token ### Clients (MCP servers) Values of `compatible_clients`: Antigravity, ChatGPT, Claude Code, Claude Desktop, Cline, Codex, Continue, Cursor, Gemini CLI, VS Code Copilot, Windsurf --- ## Examples An index row: ```json { "type": "agent", "slug": "chokepoint-finder", "name": "Chokepoint Finder", "author": "tarhou", "description": "Finds the smallest set of remediation actions that removes the largest share of risk, refuses to act on evidence it cannot read, and verifies the result before a change record closes.", "tier": "contributed", "tags": [ "vuln-management", "exposure-management", "remediation", "prioritization", "attack-path-analysis", "set-cover", "change-management", "claude-code" ], "integrations": [ "AWS", "Tenable" ], "domains": [ "vulnerability-management" ], "url": "https://exchange.tenable.com/agents/chokepoint-finder", "json_url": "https://exchange.tenable.com/api/agents/chokepoint-finder.json" } ``` A detail record (MCP arrays shortened to two entries): ```json { "type": "mcp-server", "slug": "checkpoint-mcp-server", "name": "Check Point Management Write-Path MCP Server", "author": "tarhou", "description": "Draft/publish/install access-rule lifecycle for compensating-control workflows -- the write path Check Point's official read-only MCP does not expose.", "github_url": "https://github.com/tarhou/checkpoint-mcp-server", "license": "MIT", "tier": "contributed", "tags": [ "firewall", "compensating-controls", "check-point", "network-security", "python" ], "integrations": [ "Check Point" ], "domains": [ "network-security" ], "date_added": "2026-07-29", "last_reviewed": "2026-07-31", "works_with_tenable_hexa_mcp": false, "transport": "stdio", "runtime": "python", "auth_method": "none", "compatible_clients": [ "Claude Code", "Claude Desktop" ], "tools_exposed": [ { "name": "checkpoint_list_access_rules", "description": "List current rules in an access layer" }, { "name": "checkpoint_add_access_rule", "description": "Add a rule in the current session (status: draft until published)" } ], "resources_exposed": [], "prompts_exposed": [], "url": "https://exchange.tenable.com/mcp-servers/checkpoint-mcp-server", "json_url": "https://exchange.tenable.com/api/mcp-servers/checkpoint-mcp-server.json" } ``` ## Tips for LLMs - Start from the index; it is small enough to read whole. Fetch detail records only for listings you are about to recommend or describe. - To recommend an MCP server, filter the index on `"type": "mcp-server"`, then read each candidate's `tools_exposed` and `compatible_clients` from its detail record. - `integrations` and `domains` hold exact vocabulary strings, so match them exactly. - Prefer `vetted` listings when trust matters, and say which tier a listing has when you recommend it. - Listings are metadata. The code, and its own documentation, is at `github_url`.