Knell
Connect provider accounts, scan their security posture, and investigate findings, inventory, collection coverage, and attack paths. A coding agent can use the same account and scan operations through Knell's remote MCP server.
Connect your providers
Sign in to Knell, select your organization, and open Providers. Choose Add provider, supply the connection details, select the services and regions to scan, and test the connection before enabling its schedule. Saved provider secrets are encrypted.
Kubernetes is available to staff organizations through a direct setup URL and is omitted from the Add provider chooser. Open Kubernetes setup, or use the URL returned by knell_get_provider_setup_url.
- AWS
- Assumed role with an External ID, or access keys.
- Azure
- Microsoft browser authorization, or a service principal.
- Google Cloud
- Service account credentials and project, folder, or organization scope.
- Kubernetes
- A kubeconfig on the scanner host. This mode requires a staff organization.
- DigitalOcean
- API token.
- Railway
- API token and workspace.
- Neon
- Organization API key.
- Vercel
- API token and team.
- Cloudflare
- Account-owned API token and account ID.
AWS ambient credentials, Azure CLI or managed identity, and Google Cloud user-account credentials also run on the scanner host and require a staff organization. Kubernetes setup refers to a file on that host; a path on an agent's computer cannot supply it.
Scan and investigate
Run a scan from the account, then inspect its status and collection errors. Completed snapshots power Findings, Inventory, Coverage, and Attack paths. A finding includes the rule, severity, affected items, rationale, remediation, and references where the rule provides them.
Check collection coverage alongside findings. A failed service read, queued scan, or missing snapshot leaves work to investigate. Attack paths distinguish confirmed exposure from potential paths that need more evidence.
Knell's findings describe cloud configuration and exposure risks. Software package CVE inventory is outside this scanner's current scope.
Connect a coding agent
Use a client that supports remote Streamable HTTP MCP and OAuth discovery. Add the URL below, sign in to Knell in the browser that opens, review the client and requested access, and approve the connection. The MCP endpoint accepts POST requests.
Knell has its own login and MCP endpoint. The Sythe Labs GRC MCP guide uses a separate server; use the Knell URL when working with cloud scans.
Access controls
Authorization uses PKCE and the mcp:access scope. The offline_access scope supports refresh tokens. Access stays bound to the signed-in user, live session, and OAuth client.
Call knell_get_context first. Pass its organization_id with every scoped tool call. Knell checks current membership and refuses a call if the active organization changes. Revoked sessions, disabled clients, bans, and impersonation also refuse access.
Provider and scan writes use the same ownership and subscription checks as the app. Read access, stopping scans, and deleting accounts retain their existing subscription exceptions. The agent can configure scanning and investigate results; cloud remediation changes happen through the provider's own tools.
Tool reference
The client's tool schemas specify each required field and accepted provider configuration. Connection payloads use the same validation as Knell's forms. Lists report pagination and snapshot state so an agent can tell whether it has complete evidence.
Context and provider setup
Discover the current organization, supported providers, connection requirements, and browser setup links.
knell_get_contextknell_list_providersknell_get_provider_setup_url
Provider scope discovery
Resolve the workspace, organization, team, or account accessible with supplied provider credentials.
knell_resolve_railway_workspaceknell_resolve_neon_organizationknell_resolve_vercel_teamknell_resolve_cloudflare_accounts
Account reads
Inspect configured accounts and credential metadata. Credential values are never returned.
knell_list_accountsknell_get_accountknell_get_account_credential_meta
Account configuration
Test and save connections, change scope or credentials, and manage scheduled scanning through Knell's existing account operations. knell_delete_account permanently deletes the account, its saved credentials, and stored scan history.
knell_test_account_setupknell_create_account_connectionknell_create_account_draftknell_set_account_draft_providerknell_update_account_connectionknell_update_account_nameknell_update_account_scopeknell_set_account_credentialknell_rotate_external_idknell_connect_accountknell_set_account_enabledknell_delete_account
Scans
Start an account scan, test its connection, inspect stored status and diagnostics, or stop a scan.
knell_list_scansknell_get_scanknell_run_account_scanknell_test_account_connectionknell_stop_account_scan
Security investigation
Page through posture findings, read remediation and affected resources, and inspect inventory and attack paths from stored scans.
knell_list_findingsknell_get_findingknell_list_inventoryknell_list_attack_paths
Work through a security issue
- Confirm the organization with
knell_get_context. - List accounts and scan status. Resolve connection or collection errors before treating a snapshot as complete.
- List findings for a completed scan, follow pagination, and inspect each important finding's remediation and affected resources.
- Use inventory and attack paths to understand scope, exposure, and which evidence supports the priority.
- Make approved changes through the provider's tools, run another account scan, and compare the resulting findings.
Troubleshooting
If access is refused, reconnect the MCP client and sign in again. If the organization changed, call knell_get_context and confirm the new target before retrying. A subscription refusal requires restoring the organization's subscription before another paid operation.
For provider failures, inspect the scan diagnostics and collection coverage, check the provider identity and permissions, and test the connection. A token that can authenticate may still lack permissions for particular services.