SubImage
ClaudecommunityTriage findings, investigate CVEs and attack paths, and query your cloud security graph across AWS, GCP, Azure, GitHub, and SaaS, in plain language.
SubImage Inc
SubImage keeps a live graph of your cloud and SaaS environment: AWS, GCP, Azure, GitHub, Kubernetes, and connected SaaS apps. This connector lets Claude read and reason over that graph so you can investigate your security posture in plain language instead of clicking through dashboards. What you can do - Triage findings and issues. List and inspect open issues, see what's affected, assign owners, and snooze noise. - Investigate vulnerabilities. Explore CVEs, KEV status, affected packages and containers, where they're running, and whether a fix is available, with remediation action items. - Review attack paths. Walk attacker paths step by step, assess blast radius from any asset, and simulate what-if scenarios. - Explore your inventory. Query assets across every connected provider, follow relationships, and open the right provider console. - Understand exposure and ownership. Enrich IPs, trace why a resource is reachable, and resolve which team owns it. - Query the graph directly. Run Cypher against the underlying Neo4j graph, browse the schema, and save reusable queries. - Author custom rules and scenarios. Create tenant-local detection rules and attack-path scenarios. Everything runs against your own authenticated SubImage tenant, scoped to your data. Requires a SubImage account.
Anthropic’s own published signals, snapshot of August 5, 2026; units undocumented — treat as ordinal.
Over time
Details
Tools(40)
- loadSubImageSkill
- saveModelQuery
- searchModelQueries
- subimageAssignIssue
- subimageCreateAttackPathScenario
- subimageCreateCustomRule
- subimageEnrichIp
- subimageGetAttackPathDetails
- subimageGetAttackPathsFromAsset
- subimageGetFrameworkHistory
- subimageGetInventory
- subimageGetIssue
- subimageGetLabelStats
- subimageGetNodesSchema
- subimageGetPackageDetails
- subimageGetPackageSummary
- subimageGetRuleFindings
- subimageGetRuleHistory
- subimageGetScenarioCapabilities
- subimageGetVulnerabilityActionItem
- subimageGetVulnerabilityDetails
- subimageGetVulnerabilitySummary
- subimageListAttackPaths
- subimageListCustomRules
- subimageListFrameworks
- subimageListInventories
- subimageListIssues
- subimageListModuleSchemaNodes
- subimageListModules
- subimageListPackageContainers
- subimageListPackageRunningOn
- subimageListPackages
- subimageListRules
- subimageListVulnerabilities
- subimageListVulnerabilityActionItems
- subimageListVulnerabilityContainers
- subimageListVulnerabilityRunningOn
- subimageReadMe
- subimageRunCypher
- subimageSnoozeIssue
Data from Claude’s public directory API, snapshotted daily by the MCP App Tracker. A listing describes what the directory publishes — not an endorsement.