feat(mcp): add users and roles tools to the Prowler MCP Server (#12088)

This commit is contained in:
Rubén De la Torre Vico
2026-07-28 17:16:56 +02:00
committed by GitHub
parent 7ba96ab2e2
commit 8eeb37aea4
11 changed files with 793 additions and 3 deletions
@@ -10,7 +10,7 @@ Complete reference guide for all tools available in the Prowler MCP Server. Tool
|----------|------------|------------------------|
| Prowler Hub | 10 tools | No |
| Prowler Documentation | 2 tools | No |
| Prowler Cloud, Private Cloud & Local Server | 32 tools | Yes |
| Prowler Cloud, Private Cloud & Local Server | 39 tools | Yes |
## Tool Naming Convention
@@ -105,6 +105,23 @@ Tools for viewing compliance status and framework details across all cloud provi
- **`prowler_get_compliance_overview`** - Get high-level compliance status across all frameworks for a specific scan or provider, including pass/fail statistics per framework
- **`prowler_get_compliance_framework_state_details`** - Get detailed requirement-level breakdown for a specific compliance framework, including failed requirements and associated finding IDs
### User Management
Tools for viewing the users in your tenant and identifying the authenticated user.
- **`prowler_list_users`** - List the users in the tenant with their names and emails
- **`prowler_get_user`** - Get detailed information about a specific user by ID, including join date and role/membership IDs
- **`prowler_get_current_user`** - Identify which user the current credentials authenticate as
### Role Management
Tools for browsing RBAC roles and managing the role assigned to a user. A user holds exactly one role, so setting a role replaces the one they held before.
- **`prowler_list_roles`** - List the roles defined in the tenant with their permission scope
- **`prowler_get_role`** - Get detailed information about a specific role by ID, including granted capabilities, visibility scope, assigned users, and provider groups
- **`prowler_get_user_roles`** - List the roles assigned to a specific user, with the capabilities each role grants
- **`prowler_set_user_role`** - Set the role a user holds, replacing the role they had before (idempotent)
## Prowler Hub Tools
Access Prowler's security check catalog and compliance frameworks. **No authentication required.**
@@ -50,6 +50,7 @@ Full access to your Prowler deployment — Prowler Cloud, Prowler Private Cloud,
- **Resource Inventory**: Search and view detailed information about your audited resources
- **Muting Management**: Create and manage muting lists/rules to suppress non-relevant findings
- **Attack Paths Analysis**: Analyze privilege escalation chains and security misconfigurations through graph-based analysis of cloud resource relationships
- **User & Role Management**: List the users in your tenant, identify the authenticated user, browse RBAC roles, and set the role a user holds
### 2. Prowler Hub