Cloud security guide

Knell

Connect provider accounts, scan their security posture, and investigate findings, inventory, collection coverage, and attack paths. A coding agent can use the same account and scan operations through Knell's remote MCP server.

Open Knell or read about the product.

Connect your providers

Sign in to Knell, select your organization, and open Providers. Choose Add provider, supply the connection details, select the services and regions to scan, and test the connection before enabling its schedule. Saved provider secrets are encrypted.

Kubernetes is available to staff organizations through a direct setup URL and is omitted from the Add provider chooser. Open Kubernetes setup, or use the URL returned by knell_get_provider_setup_url.

AWS
Assumed role with an External ID, or access keys.
Azure
Microsoft browser authorization, or a service principal.
Google Cloud
Service account credentials and project, folder, or organization scope.
Kubernetes
A kubeconfig on the scanner host. This mode requires a staff organization.
DigitalOcean
API token.
Railway
API token and workspace.
Neon
Organization API key.
Vercel
API token and team.
Cloudflare
Account-owned API token and account ID.

AWS ambient credentials, Azure CLI or managed identity, and Google Cloud user-account credentials also run on the scanner host and require a staff organization. Kubernetes setup refers to a file on that host; a path on an agent's computer cannot supply it.

Scan and investigate

Run a scan from the account, then inspect its status and collection errors. Completed snapshots power Findings, Inventory, Coverage, and Attack paths. A finding includes the rule, severity, affected items, rationale, remediation, and references where the rule provides them.

Check collection coverage alongside findings. A failed service read, queued scan, or missing snapshot leaves work to investigate. Attack paths distinguish confirmed exposure from potential paths that need more evidence.

Knell's findings describe cloud configuration and exposure risks. Software package CVE inventory is outside this scanner's current scope.

Connect a coding agent

Use a client that supports remote Streamable HTTP MCP and OAuth discovery. Add the URL below, sign in to Knell in the browser that opens, review the client and requested access, and approve the connection. The MCP endpoint accepts POST requests.

Knell MCP server URL

https://cloud.sythelabs.com/api/mcp

Prompt for your coding agent

Connect to the Knell MCP server at https://cloud.sythelabs.com/api/mcp Use OAuth sign-in and approve access in my browser. Call knell_get_context and show the organization before making changes. Use its organization_id for scoped calls. List my provider accounts and the latest scan findings. Explain which results are incomplete before proposing a remediation plan.

Knell has its own login and MCP endpoint. The Sythe Labs GRC MCP guide uses a separate server; use the Knell URL when working with cloud scans.

Access controls

Authorization uses PKCE and the mcp:access scope. The offline_access scope supports refresh tokens. Access stays bound to the signed-in user, live session, and OAuth client.

Call knell_get_context first. Pass its organization_id with every scoped tool call. Knell checks current membership and refuses a call if the active organization changes. Revoked sessions, disabled clients, bans, and impersonation also refuse access.

Provider and scan writes use the same ownership and subscription checks as the app. Read access, stopping scans, and deleting accounts retain their existing subscription exceptions. The agent can configure scanning and investigate results; cloud remediation changes happen through the provider's own tools.

Tool reference

The client's tool schemas specify each required field and accepted provider configuration. Connection payloads use the same validation as Knell's forms. Lists report pagination and snapshot state so an agent can tell whether it has complete evidence.

Context and provider setup

Discover the current organization, supported providers, connection requirements, and browser setup links.

  • knell_get_context
  • knell_list_providers
  • knell_get_provider_setup_url

Provider scope discovery

Resolve the workspace, organization, team, or account accessible with supplied provider credentials.

  • knell_resolve_railway_workspace
  • knell_resolve_neon_organization
  • knell_resolve_vercel_team
  • knell_resolve_cloudflare_accounts

Account reads

Inspect configured accounts and credential metadata. Credential values are never returned.

  • knell_list_accounts
  • knell_get_account
  • knell_get_account_credential_meta

Account configuration

Test and save connections, change scope or credentials, and manage scheduled scanning through Knell's existing account operations. knell_delete_account permanently deletes the account, its saved credentials, and stored scan history.

  • knell_test_account_setup
  • knell_create_account_connection
  • knell_create_account_draft
  • knell_set_account_draft_provider
  • knell_update_account_connection
  • knell_update_account_name
  • knell_update_account_scope
  • knell_set_account_credential
  • knell_rotate_external_id
  • knell_connect_account
  • knell_set_account_enabled
  • knell_delete_account

Scans

Start an account scan, test its connection, inspect stored status and diagnostics, or stop a scan.

  • knell_list_scans
  • knell_get_scan
  • knell_run_account_scan
  • knell_test_account_connection
  • knell_stop_account_scan

Security investigation

Page through posture findings, read remediation and affected resources, and inspect inventory and attack paths from stored scans.

  • knell_list_findings
  • knell_get_finding
  • knell_list_inventory
  • knell_list_attack_paths

Work through a security issue

  1. Confirm the organization with knell_get_context.
  2. List accounts and scan status. Resolve connection or collection errors before treating a snapshot as complete.
  3. List findings for a completed scan, follow pagination, and inspect each important finding's remediation and affected resources.
  4. Use inventory and attack paths to understand scope, exposure, and which evidence supports the priority.
  5. Make approved changes through the provider's tools, run another account scan, and compare the resulting findings.

Troubleshooting

If access is refused, reconnect the MCP client and sign in again. If the organization changed, call knell_get_context and confirm the new target before retrying. A subscription refusal requires restoring the organization's subscription before another paid operation.

For provider failures, inspect the scan diagnostics and collection coverage, check the provider identity and permissions, and test the connection. A token that can authenticate may still lack permissions for particular services.