A security policy can span hundreds of rules and thousands of objects, and the value here is asking a real question and getting a structured answer instead of parsing exports. The monorepo is many independent servers — the management one for policy and objects, the logs one for audit trails — each with its own credentials, so you enable exactly the surface your task needs.
A monorepo of MCP servers for Check Point security products, each a separate package covering one domain — management, logs, threat prevention, and more.
- Management (@chkp/quantum-management-mcp) — query policies, rules, objects and network topology
- Management Logs (@chkp/management-logs-mcp) — query and gain insight from connection and audit logs
- Threat Prevention (@chkp/threat-prevention-mcp) — policies, profiles, indicators, IPS updates and IOC feeds
- HTTPS Inspection (@chkp/https-inspection-mcp) — inspection policies, rules and exceptions
- Harmony SASE (@chkp/harmony-sase-mcp) — SASE regions, networks and applications
- Reputation Service (@chkp/reputation-service-mcp) — URL, IP and file reputation
- GW CLI (@chkp/quantum-gw-cli-mcp) — gateway diagnostics across hardware, network, HA and performance
- Threat Emulation, Gaia OS, Spark management, WAF, policy insights and a documentation assistant
Each server is a separate npm package launched with npx, with its own configuration and credentials — refer to the individual package README for what a given server needs. Development against the monorepo uses npm install and npm run build; end users only install the specific servers they want.
One command — npx -y @chkp/argos-erm-mcp
