OfficialVerified

Imperva Cloud Waf MCP Server

Imperva Cloud WAF configurations managed via natural language queries.

Data last scanned today · Reviewed today

764 tools7PythonApache-2.0

Overview

This MCP server provides a conversational interface for retrieving and analyzing Imperva Cloud WAF settings. It allows users to interact with security configurations, site details, and domain data directly through their AI assistant without navigating through traditional dashboards. The server is currently in beta and provides read-only access to your account data. It includes specific tools to fetch site and domain information using filters like account IDs, site IDs, and domain names, streamlining the review of security policies.

Our verdict

With a security score of 38/100, this tool is classified as high-risk. This is primarily because it is a community-maintained project rather than an official Imperva release, and both its authentication methods and read-only mode have not been independently reviewed. It is suitable for testing and exploration by developers who understand the implications of using non-official security tools, but it should not be used in critical production environments until these security aspects are fully vetted.

  • Zero direct dependencies simplifies the supply-chain surface
  • Active development with a recent commit history
  • Openly licensed under the Apache-2.0 license
  • High-risk score due to lack of official vendor status
  • Authentication and read-only mechanisms are not yet reviewed
  • Beta-stage software with limited functional scope

Tools

ToolDescriptionRisk
Get SitesRetrieve information about your Cloud WAF sites. Returns site details including name, ID, account ID, type, active status, CNAMEs, site status, and creation time.low
Get DomainsFetch domain information for your sites. Returns domain details including name, ID, status, creation date, A records (for apex domains), and CNAME records. Note: A Cloud WAF site can have multiple domains.low
Get PoliciesQuery security policies across your account. Returns complete policy information including ID, name, description, enabled status, policy type, settings, configurations, asset assignments, and sub-account permissions.low
Get RulesRetrieve custom security rules assigned to your sites. Supports rate rules, security rules, forward rules, redirect rules, and rewrite rules. Returns detailed rule information including rule ID, site ID, name, action, enabled status, filters, and rule-specific settings (rate limiting, redirects, rewrites, etc.).low

Compatibility

ClientLocalDockerRemoteRead-only
Claude Desktop
Cursor
VS Code
Windsurf
ChatGPT

Frequently asked questions

Can I use this server to update or delete my WAF configurations?

No, this is a beta release that currently supports read-only operations only. You must use the Imperva Cloud WAF Console for any write, modification, or deletion tasks.

What are the system requirements for running the server?

You must have Docker Desktop installed to run the MCP server. It is designed to work with clients like the Claude Desktop app.

Which specific components of the Cloud WAF can I query?

You can retrieve detailed information regarding sites, domains, security policies, and various custom security rules such as rate limiting, redirects, and rewrites.

Alternatives

Badge

Imperva Cloud Waf MCP Server security score, rated on RepoAI

Maintain this server? Add the live badge to your README.