Can AI agents automate Rapid7 Command Platform?
Rapid7 · saas · devsecopsenterprise
Rapid7 Command Platform vulnerability and asset data is automatable today through the Bulk Export API. This record is that export surface and the Rapid7 MCP server that loads it. It is not Tenable, and it does not cover every Insight module. The API is GraphQL. Calls send the platform API key in the X-Api-Key header. The key must be an Organization key or a user key with Platform Administrator permissions. Regional endpoints include https://us.api.insight.rapid7.com/export/graphql, https://eu.api.insight.rapid7.com/export/graphql, and hosts for Canada, Australia, Japan, and additional United States regions. Mutations create policy, vulnerability, and remediation exports. Results are Parquet files. Download URLs last 15 minutes and can be regenerated for 30 days. Files are retained for 30 days. Data refreshes once a day, and overuse can be throttled. A remediation export date range must be after August 2025, must not be a single day, and must be at most 31 days. Rapid7 publishes github.com/rapid7/rapid7-bulk-export-mcp, which loads those exports into a local DuckDB database for agent queries. The README says support is best effort. A language SDK, a CLI, and connector catalogs were not opened. https://www.rapid7.com/llms.txt is a plain-text index of the marketing site. Computer-use viability is unassessed. The Bulk Export API scores 6 and is the best path. The MCP server scores 4.
Best path today: api · Overall automatability: 6/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | graphqlapi-key coverage: partial · docs |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: parquet · import: unknown | |
| RPA / UI automation | unknown | No repeatable UI probe was run. The opened automation surface is the Bulk Export API and a local MCP server that queries those exports.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 6 | 4 | — | — | — | — | 6 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-10-08 |
license | declared | source | 2026-10-08 |
modalities.api.exists | declared | source | 2026-10-08 |
modalities.api.kinds[0] | declared | source | 2026-10-08 |
modalities.api.auth[0] | declared | source | 2026-10-08 |
modalities.api.coverage | declared | source | 2026-10-08 |
modalities.mcp.first_party | declared | source | 2026-10-08 |
modalities.mcp.verdict | declared | source | 2026-10-08 |
modalities.data_access.export[0] | declared | source | 2026-10-08 |
modalities.agent_docs.llms_txt | declared | source | 2026-10-08 |
verdict.scores.api | declared | source | 2026-10-08 |
verdict.scores.mcp | declared | source | 2026-10-08 |
freshness.watch[0].url | declared | source | 2026-10-08 |
freshness.watch[1].url | declared | source | 2026-10-08 |
freshness.watch[2].url | declared | source | 2026-10-08 |
Related tools
Other products in this database that share a category with Rapid7 Command Platform.
Last verified 2026-10-08 · volatility medium · JSON record