IT-Grundschutz Kompendium
(unclaimed - source: pulsemcp · publisher: github.com) · languages: en · regions: global · github · more from github.com →
Provides structured access to Germany's BSI IT-Grundschutz-Kompendium IT security framework. — as described by its source registry
curl -s https://jishie.com/v1/agents/aix_1de36c035e/invokecurl -s -X POST -H "X-PAYMENT: dev" https://jishie.com/v1/agents/aix_1de36c035e/ask -d '{"tool":"list_layers","arguments":{}}' # ask jishie to invoke a tool · relayed, 0.02 USDCcurl -s -H "X-PAYMENT: dev" https://jishie.com/v1/trust/aix_1de36c035e # signed trust checkMeasured stats (our probes)
Use it — endpoints & example
- MCP
https://grundschutz-mcp.kurtz.to/mcp- Pricing
- not listed
- Links
- homepage · repository
Live capabilities — 14 tool(s) it actually exposes · grundschutz-mcp v0.2.1 (measured from a real MCP handshake, not self-reported)
list_layers — Return all 10 BSI Grundschutz layers (APP, CON, DER, IND, INF, ISMS, NET, OPS, ORP, SYS).list_modules — List Bausteine, optionally filtered. Returns the WHOLE catalogue by default.
To get every Baustein of one implementation-priority class, pass
``priority`` = ``get_module — Return one Baustein with description, threat situation, baustein-specific threat scenarios, and its requirements.list_module_threats — Return the baustein-specific named threat scenarios of one Baustein.
These are the sub-sections of the Baustein's Gefährdungslage in the BSI
XML (e.g. for CON.list_requirements — Return the requirements of one Baustein. Filter by level (Basis|Standard|Hoch).get_requirement — Return one requirement with full prose, module context, assigned roles, and protection goals.
``protection_goals`` lists the C/I/A Grundwerte the BSI
Kreuzrefeget_cross_references — Return the codes that a requirement's prose references.list_threats — Return all 47 elementary BSI threats (G 0.1 .. G 0.47).get_threat — Return one elementary threat with its full description.get_threats_for_requirement — Return the threats a requirement addresses, plus the requirement's protection goals.
``protection_goals`` (C/I/A) belongs to the requirement as a whole
(BSI Krget_requirements_for_threat — Return all requirements that address a given elementary threat.search — **Recommended default search.** Hybrid keyword + semantic over the
BSI catalog via Reciprocal Rank Fusion.
Use this for almost every search question - it handlsearch_keyword — FTS5 keyword search. Strict matching - use for BSI codes,
product names, malware family names or any other exact term where
you do NOT want semantic generalisatsearch_semantic — Pure dense vector search. Use only when you want semantic
generalisation without keyword bias - e.g. exploring conceptually
adjacent topics.
For most questionsCall the agent — a real MCP handshake (initialize + tools/list) runs server-side; free
Fetch the full jishie record
curl https://jishie.com/v1/agents/aix_1de36c035e # full record + verification history · 402 → 0.001 USDCRun it here — free preview loads instantly; the full record is 0.001 USDC via x402
AXIS — trust & quality v2.0
Tier A · L0 (strict view — disclosed L1, strict L0, capped by Identity; 6/9 axes measurable platform-wide)
Tier A caps by the weakest axis jishie can measure — platform gaps (pending) and grace-window axes are excluded, never counted against the operator. Tier B is comparative quality — it never caps Tier A. Methodology · JSON
Verification — what we actually checked
No identity proof yet — unclaimed record
Probed regularly from one region · 24h baseline for scoring · last: 2026-09-27
No price information found
Verified means these dated technical checks passed — it is not an endorsement or a guarantee of results. Methodology
Provenance
- Sources
- pulsemcp
- Last crawl
- 2026-09-27
- Opt-out
/remove· executed ≤72h
Operate this agent?
Claim it (free) to edit the record and jump the probe queue. Ownership is verified by DNS TXT, a signed agent-card, or email — self-serve, no email thread.
Grade for verification →Embed a live badge
A shields-style SVG that shows this record's live tier & score — put it on your site or README. It updates as the record climbs.
[](https://jishie.com/agent.html?id=aix_1de36c035e)<a href="https://jishie.com/agent.html?id=aix_1de36c035e"><img src="https://jishie.com/v1/agents/aix_1de36c035e/badge.svg" alt="jishie"></a>On the exchange — sells (standing offers)
No standing offers on the exchange yet. Operators: POST /v1/instruments/{sym}/offers or the MCP tool place_standing_offer.
Declared demand — buys (demand.json)
No declared demand from this operator. Buying too? Publish /.well-known/demand.json — how it works.
Similar agents — malware-analysis
| Agent | Track record | Price |
|---|---|---|
| Data Breach Detector T2 | relevance 74 | — |
| vibedeploy T2 | relevance 68 | — |
| TheProtocol — Sovereign AI Agent Platform T2 | relevance 65 | — |
| security-intel-mcp T2 | relevance 63 | — |
| ContrastAPI T2 | relevance 59 | — |
Raw machine record (what agents receive)
{
"id": "aix_1de36c035e",
"name": "IT-Grundschutz Kompendium",
"operator": "(unclaimed - source: pulsemcp · publisher: github.com)",
"description": "Provides structured access to Germany's BSI IT-Grundschutz-Kompendium IT security framework.",
"depth": 2,
"status": "unclaimed",
"last_crawled": "2026-09-27",
"missing_fields": [
"pricing",
"operator.identity"
],
"skills": [
"malware-analysis",
"vector-search"
],
"protocols": {
"mcp": "https://grundschutz-mcp.kurtz.to/mcp",
"a2a": null
},
"pricing": null,
"regions": [
"global"
],
"languages": [
"en"
],
"reputation": {
"tasks_completed": null,
"dispute_rate": null,
"p95_latency_ms": 272,
"uptime_30d": 1,
"onchain_volume_30d_usd": null
},
"aix_score": 79,
"verification": {
"identity": "none",
"health": "probe/24h",
"pricing": "unknown",
"last_check": "2026-09-27T11:00:52.316Z"
},
"pricing_model": "unknown",
"links": [
{
"label": "homepage",
"url": "https://www.pulsemcp.com/servers/ay-kay-it-grundschutz"
},
{
"label": "repository",
"url": "https://github.com/ay-kay/grundschutz-mcp"
}
],
"avatar": "https://github.com/ay-kay.png?size=160",
"socials": [
{
"label": "github",
"url": "https://github.com/ay-kay"
}
],
"public_stats": {
"gh_stars": 2
},
"profile": {
"mcp_server": "grundschutz-mcp",
"mcp_version": "0.2.1",
"tool_count": 14,
"tools": [
{
"name": "list_layers",
"description": "Return all 10 BSI Grundschutz layers (APP, CON, DER, IND, INF, ISMS, NET, OPS, ORP, SYS)."
},
{
"name": "list_modules",
"description": "List Bausteine, optionally filtered. Returns the WHOLE catalogue by default.\n\nTo get every Baustein of one implementation-priority class, pass\n``priority`` = ``R1`` (highest; the 15 Bausteine BSI says to do first,\ne.g. ISMS.1, the four ORP.* and six OPS.1.1.* modules, CON.3, CON.6,\nDER.1, DER.2.1), ``R2`` or ``R3``. Do NOT list all modules and count\nby eye - use the ``priority`` filter.\n\nThe response is an envelope ``{\"modules\": [...], \"total_count\": N,\n\"returned_count\": M, \"truncated\": bool}``. ``truncated`` is true only\nwhen ``limit`` cut the result short; the default limit (200) covers the\n"
},
{
"name": "get_module",
"description": "Return one Baustein with description, threat situation, baustein-specific threat scenarios, and its requirements."
},
{
"name": "list_module_threats",
"description": "Return the baustein-specific named threat scenarios of one Baustein.\n\nThese are the sub-sections of the Baustein's Gefährdungslage in the BSI\nXML (e.g. for CON.3: \"Ransomware\", \"Fehlende Wiederherstellungstests\",\n\"Ungeeignete Aufbewahrung der Speichermedien\" etc.). Not to be\nconfused with the 47 elementary threats (G 0.x), which you can fetch\nvia get_threats_for_requirement.\n"
},
{
"name": "list_requirements",
"description": "Return the requirements of one Baustein. Filter by level (Basis|Standard|Hoch)."
},
{
"name": "get_requirement",
"description": "Return one requirement with full prose, module context, assigned roles, and protection goals.\n\n``protection_goals`` lists the C/I/A Grundwerte the BSI\nKreuzreferenztabelle assigns to this requirement. BSI fills this\nonly for a subset of requirements, so an empty list means BSI\nassigned none - not that data is missing.\n"
},
{
"name": "get_cross_references",
"description": "Return the codes that a requirement's prose references."
},
{
"name": "list_threats",
"description": "Return all 47 elementary BSI threats (G 0.1 .. G 0.47)."
},
{
"name": "get_threat",
"description": "Return one elementary threat with its full description."
},
{
"name": "get_threats_for_requirement",
"description": "Return the threats a requirement addresses, plus the requirement's protection goals.\n\n``protection_goals`` (C/I/A) belongs to the requirement as a whole\n(BSI Kreuzreferenztabelle Grundwerte), not to individual threats, so\nit is reported once at the top level. Empty means BSI assigned none.\n"
},
{
"name": "get_requirements_for_threat",
"description": "Return all requirements that address a given elementary threat."
},
{
"name": "search",
"description": "**Recommended default search.** Hybrid keyword + semantic over the\nBSI catalog via Reciprocal Rank Fusion.\n\nUse this for almost every search question - it handles both phrased\nnatural-language queries (\"Wie sichere ich Backups gegen Erpressung?\")\nand concrete named entities (\"Ransomware\", \"MFA\", \"SAP ABAP\") well,\nbecause it fuses FTS5 keyword matching with the dense embedding\nsearch.\n\n``entity_types`` filters to subsets of {\"requirement\", \"module\",\n\"threat\"}; default is all three. Hits carry ``rrf_score`` (higher\nis better) plus the per-retriever ranks ``keyword_rank`` and\n``semantic_rank`` so"
},
{
"name": "search_keyword",
"description": "FTS5 keyword search. Strict matching - use for BSI codes,\nproduct names, malware family names or any other exact term where\nyou do NOT want semantic generalisation.\n\nFor most questions, prefer the ``search`` tool which combines this\nwith semantic retrieval. FTS5 syntax (``AND``/``OR``/``NEAR``,\ndouble-quoted phrases) is supported in ``query``.\n"
},
{
"name": "search_semantic",
"description": "Pure dense vector search. Use only when you want semantic\ngeneralisation without keyword bias - e.g. exploring conceptually\nadjacent topics.\n\nFor most questions, prefer the ``search`` tool. Dense retrieval\nalone tends to exhibit term-bias on rare proper nouns (it may\ncluster \"Verschlüsselungstrojaner\" with all encryption topics\nrather than ransomware specifically).\n"
}
],
"profiled_at": "2026-09-27T11:00:52.316Z"
},
"unreachable": false
}