MCP & AI Agent Integration

Knowfirst
automation.

11 automated actions available through Cerebral OS. Connect Knowfirst to any workflow, Cerebral, or Map — with full governance, audit trail, and dry-run safety on every execution.

No credit card required · 1,000 free runs · 11 actions available

Execution trace
live
11
actions
100%
governed
<200ms
latency
11
Automated actions
7
Read operations
4
Write operations
2,800+
Compatible Maps
Actions

What you can do
with Knowfirst.

Every action below is available as an MCP tool and a verb in Cerebral OS — callable from any AI agent, Claude, Cursor, Windsurf, or your own runtime via the BYOA API. All executions are governed, audited, and dry-run safe.

Create Watchlist
knowfirst:create_watchlist
Create a new watchlist to monitor specific indicators and generate alerts.
Write Medium risk
Delete Watchlist
knowfirst:delete_watchlist
Permanently delete a watchlist and all its indicators. This action cannot be undone.
Write High risk
Get Alert
knowfirst:get_alert
Fetch a single alert by ID with full details including risk score and indicators.
Read Low risk
Get Threat Intel
knowfirst:get_threat_intel
Fetch a single threat intelligence report by ID with indicators and analysis.
Read Low risk
Get Watchlist
knowfirst:get_watchlist
Fetch a single watchlist by ID with all indicators and recent alerts.
Read Low risk
List Alerts
knowfirst:list_alerts
List alerts with optional filtering by severity, status, category, and date range.
Read Low risk
List Threat Intel
knowfirst:list_threat_intel
List threat intelligence reports with filtering and search capabilities.
Read Low risk
List Watchlists
knowfirst:list_watchlists
List all watchlists with optional filtering by status, severity, and search.
Read Low risk
Search Indicators
knowfirst:search_indicators
Search for threat indicators by value with confidence scoring and context.
Read Low risk
Update Alert
knowfirst:update_alert
Update an alert's status, assignee, notes, or tags.
Write Medium risk
Update Watchlist
knowfirst:update_watchlist
Update a watchlist's configuration, status, or metadata.
Write Medium risk
How it works

Every Knowfirst action
governed end-to-end.

Cerebral OS isn't a connector. It's the execution layer that sits in front of Knowfirst — adding governance, dry-run safety, and a full audit trail to every operation.

Governance first
Every verb carries a risk classification. High-risk writes require explicit approval gates before they execute in production.
Dry-run safe
Simulate any Knowfirst action before it touches production. See exactly what would happen before a single real call is made.
Immutable audit trail
Every Knowfirst action is logged — what ran, what changed, who approved it, when it happened. Full history on every verb, forever.
Knowfirst integration

Start free.
No credit card required.

Start free with 1,000 runs — no credit card required. Connect Knowfirst in minutes, dry-run every action before it touches production, full audit trail on everything.

Start free — 1,000 runs Browse all integrations →