Connect Intruder to ChatGPT: Automate Vulnerability Scans & Audits
from the team behind Truto
Intruder in ChatGPT, in about a minute.
The best way to connect Intruder to ChatGPT is Elaichi: connect Intruder to Elaichi once, then add Elaichi to ChatGPT as a connector. Two steps, about a minute, with a 14‑day free trial and no credit card required.
- No credit card required
- 500+ connectors
- Credentials vaulted, never read back
-
Start your free trial
14 days free, no credit card required.
-
Connect Intruder
Once, in Elaichi. ChatGPT never gets more access than you have.
-
Add Elaichi to ChatGPT
In ChatGPT, open Plugins, press +, and paste the URL into Server URL. Sign in and approve.
https://api.elaichi.ai/mcp
Building Intruder into your own product? This guide is for you.
Connect Intruder's vulnerability scanning API to ChatGPT using Truto's managed MCP server. This guide covers overcoming Intruder-specific API challenges, deploying the MCP server via UI or API, and configuring ChatGPT for automated security audits and scan scheduling.
The developer guide
Learn how to connect Intruder to ChatGPT using an MCP server. Automate vulnerability scans, track issue occurrences, and manage targets via natural language.
If you need to connect Intruder to ChatGPT to automate vulnerability scans, audit security issues, or manage infrastructure targets, you need a Model Context Protocol (MCP) server. This protocol acts as the translation layer between ChatGPT's JSON-RPC tool calls and Intruder's REST APIs. You can either build, host, and maintain this stateful middleware yourself, or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL.
If your team uses Claude, check out our guide on connecting Intruder to Claude or explore our broader architectural overview on connecting Intruder to AI Agents.
Giving a Large Language Model (LLM) read and write access to an enterprise vulnerability scanner is a serious engineering task. You must handle complex relational data payloads, strict scheduling validations, and nested target authentications. Every time Intruder updates their API schemas, your custom server code must be updated, tested, and redeployed.
This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Intruder, connect it natively to ChatGPT, and execute complex security workflows using natural language.
The Engineering Reality of the Intruder API
A custom MCP server is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, implementing it against Intruder's highly specific API model is exceptionally painful.
If you decide to build a custom MCP server for Intruder, you own the entire API lifecycle. Here are the specific integration challenges that break standard CRUD assumptions when working with Intruder:
The Dual-ID System: Issues vs Occurrences
Intruder uses a specific data model for tracking vulnerabilities over time. An issue represents the vulnerability definition itself (e.g., "OpenSSH Terrapin attack"). However, an occurrence represents that vulnerability found on a specific target at a specific port.
If an LLM queries list_all_intruder_issues, it gets a high-level summary but no actionable host data. To get the host data, the LLM must call list_all_intruder_issue_occurrences. But there is a catch: the standard id of an occurrence can change between scans. You must specifically instruct the LLM to track the occurrence_id (a stable hash) to confidently modify or comment on a vulnerability across multiple scan cycles. If your MCP server does not clearly define these schema nuances in its tool descriptions, ChatGPT will hallucinate IDs and fail to update records.
Strict Validation for Scan Schedules
When a user prompts ChatGPT to "schedule a recurring scan for tomorrow afternoon," the LLM translates that into an ISO datetime string. Intruder's API will aggressively reject this if the timing is not precise.
The create_a_intruder_scan_schedule endpoint mandates that the first_scan_time MUST fall exactly on the hour (e.g., 14:00:00Z). If the LLM generates 14:32:00Z, the request fails. Furthermore, scan_frequency is restricted to strict enums (monthly, daily, weekly, quarterly). A custom MCP server must either inject validation layers to round timestamps to the nearest hour, or provide explicit, heavy-handed prompt engineering in the tool descriptions to force the LLM to conform.
Target Authentication and Multi-Part Uploads
Adding a simple IP address to Intruder is straightforward. But adding an authenticated web application target requires sequential API calls that cannot easily be bundled.
To onboard an authenticated app, the LLM must first call create_a_intruder_target. It must then extract the returned target_id and pass it to create_a_intruder_target_authentication. If an API schema is required, it must then invoke create_a_intruder_target_api_schema, which requires a multi-part file upload. LLMs natively struggle with binary file handling and multi-part form data. Bridging this gap requires the MCP server to act as a stateful proxy, caching the schema file via a signed URL before pushing it to Intruder.
Rate Limits and 429 Handling
Intruder enforces strict rate limits to protect its backend. When building an MCP server, developers often mistakenly assume the integration layer should automatically absorb and retry these limits.
Factual note on rate limits: Truto does not retry, throttle, or apply backoff on rate limit errors. When an upstream API returns an HTTP 429, Truto passes that error directly to the caller. Truto normalizes the upstream rate limit info into standardized headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset) per the IETF spec.
This means the LLM client (or your orchestration framework) is responsible for the retry and backoff logic. Your system prompt must instruct ChatGPT to read the rate limit error, parse the ratelimit-reset timestamp, and wait before attempting the next tool call.
Deploying the Intruder MCP Server
Truto's MCP architecture derives tool definitions dynamically from documentation records acting as a quality gate. A tool only appears if it has a documentation record defining its query and body JSON schemas. These tools delegate to proxy API handlers, bypassing generic unified models to execute directly against Intruder's native API.
There are two ways to generate an MCP server for your connected Intruder account.
Method 1: Via the Truto UI
This is the fastest method for testing and manual setups.
- Navigate to the Integrated Accounts page for your Intruder connection.
- Click the MCP Servers tab.
- Click Create MCP Server.
- Select the desired configuration (name, allowed methods, tags, and expiration).
- Copy the generated MCP server URL (e.g.,
https://api.truto.one/mcp/<token>).
Method 2: Via the API
For production workflows, you should dynamically generate MCP servers programmatically. This ensures servers are tightly scoped to specific tasks and automatically expire when no longer needed.
Send a POST request to /integrated-account/:id/mcp:
curl -X POST https://api.truto.one/integrated-account/$INTEGRATED_ACCOUNT_ID/mcp \
-H "Authorization: Bearer $TRUTO_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "ChatGPT Intruder Audit Server",
"config": {
"methods": ["read", "write"],
"tags": ["scans", "issues", "targets"]
},
"expires_at": "2025-12-31T23:59:59Z"
}'The response contains the url field. This URL contains a cryptographically hashed token that routes requests to the specific tenant's Intruder instance. Treat this URL as a secret.
Connecting the MCP Server to ChatGPT
Once you have the MCP server URL, you must register it with your ChatGPT environment. The MCP protocol handles the initialization handshake, securely exposing the available Intruder tools.
Method 1: Via the ChatGPT UI
If you are using ChatGPT Pro, Plus, Business, Enterprise, or Education accounts with Developer mode enabled:
- In ChatGPT, go to Settings -> Apps -> Advanced settings.
- Enable Developer mode.
- Under MCP servers / Custom connectors, click Add a new server.
- Enter a Name (e.g., "Intruder Security Scanner").
- Paste the Truto MCP server URL into the Server URL field.
- Click Add.
ChatGPT will immediately ping the endpoint, execute the initialize JSON-RPC handshake, and populate its context window with the available Intruder tools.
Method 2: Via Manual Configuration (Desktop Clients)
If you are running a local agentic framework or a desktop client that supports standard MCP JSON configuration, you can mount the server via Server-Sent Events (SSE).
Create an mcp_config.json file in your client directory:
{
"mcpServers": {
"intruder_security": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-sse",
"--url",
"https://api.truto.one/mcp/your_token_here"
]
}
}
}Hero Tools for Intruder Automation
Truto automatically maps Intruder's endpoints into snake_case MCP tools. Here are the highest-leverage operations for security automation. Do not pass the base URL or authentication headers - Truto's proxy handlers manage the underlying routing and OAuth refresh lifecycles automatically.
List All Intruder Issues
Fetches current vulnerabilities. You can filter by severity, snoozing status, tags, and new occurrences since a specific timestamp.
Usage note: This returns the parent issue records. It does not return the specific host data. Use this tool to get the high-level posture before drilling down.
"Fetch all critical and high-severity issues in Intruder that have not been snoozed. Give me a summary of their descriptions and CVSS scores."
List All Intruder Issue Occurrences
Retrieves the specific targets affected by an issue. Returns the occurrence_id, target address, port, protocol, and first seen date.
Usage note: Requires an issue_id. The returned occurrence_id is the stable identifier you must use if you intend to add comments or track remediation state across multiple scan cycles.
"For the issue ID 'iss_12345', list all occurrences. Identify which IP addresses and ports are actively exposing this vulnerability."
Create a Intruder Scan
Triggers an on-demand scan. Returns the created scan object including its ID, status, and target addresses.
Usage note: You can pass target_addresses or tag_names in the request body to limit the scope. If you pass an empty body, Intruder will scan all configured targets. Be careful with empty bodies in production environments.
"Start a new on-demand scan in Intruder targeting only the IP addresses tagged with 'production-dmz'. Let me know the scan ID once it starts."
Intruder Targets Bulk Create
Adds multiple targets, including entire CIDR ranges, to your Intruder inventory. Returns the created target objects with their license types and statuses.
Usage note: The input requires an array of addresses. Ensure you have sufficient infrastructure licenses available before running large CIDR blocks.
"Bulk add the following CIDR blocks to Intruder: 10.0.5.0/24 and 10.0.6.0/24. Tag all of them as 'internal-staging'."
Create a Intruder Scan Schedule
Sets up a recurring scan schedule for your targets.
Usage note: As mentioned earlier, first_scan_time MUST be on the hour and in the future. scan_frequency must be one of: monthly, daily, weekly, or quarterly.
"Create a weekly scan schedule named 'Weekend Compliance Scan'. Set the first scan time for this coming Saturday at 02:00:00Z and target all IPs tagged 'pci-scope'."
List All Intruder Health
Checks the upstream availability of the Intruder API.
Usage note: Use this tool as a connectivity check before kicking off a complex multi-step orchestration.
"Ping the Intruder health endpoint. If the API is running normally, proceed to fetch the list of active scans."
For the complete tool inventory and granular JSON schema definitions, visit the Intruder integration page.
Workflows in Action
Connecting an LLM to your vulnerability scanner unlocks powerful agentic workflows. Instead of manually clicking through the Intruder dashboard to correlate data, you can prompt ChatGPT to execute multi-step investigations.
Workflow 1: SOC Analyst Triaging New Vulnerabilities
When a zero-day drops, security teams need immediate visibility into their exposure.
"Check Intruder for any critical issues related to 'OpenSSH'. If found, list all specific occurrences showing the affected IP addresses and ports. Finally, add a comment to each occurrence stating 'SOC Team investigating - ticket opened.'"
Step-by-step execution:
- Query Issues: ChatGPT calls
list_all_intruder_issuespassingseverity: "critical"and parses the response to find the OpenSSH issue ID. - Query Occurrences: It passes that ID into
list_all_intruder_issue_occurrencesto retrieve theoccurrence_idandtargetfor every affected host. - Add Comments: It iterates over the results, calling
create_a_intruder_occurrence_commentfor eachoccurrence_idwith the required text.
Outcome: The SOC analyst receives a formatted list of vulnerable servers in chat, and the Intruder dashboard is automatically annotated to prevent duplicated effort.
sequenceDiagram
participant User
participant ChatGPT
participant TrutoMCP as Truto MCP Server
participant Intruder
User->>ChatGPT: "Find OpenSSH issues and comment..."
ChatGPT->>TrutoMCP: tools/call list_all_intruder_issues
TrutoMCP->>Intruder: GET /issues?severity=critical
Intruder-->>TrutoMCP: 200 OK (iss_890)
TrutoMCP-->>ChatGPT: JSON result
ChatGPT->>TrutoMCP: tools/call list_all_intruder_issue_occurrences
TrutoMCP->>Intruder: GET /issues/iss_890/occurrences
Intruder-->>TrutoMCP: 200 OK (occ_123, occ_456)
TrutoMCP-->>ChatGPT: JSON result
ChatGPT->>TrutoMCP: tools/call create_a_intruder_occurrence_comment
TrutoMCP->>Intruder: POST /issues/iss_890/occurrences/occ_123/comments
Intruder-->>TrutoMCP: 201 Created
TrutoMCP-->>ChatGPT: JSON result
ChatGPT-->>User: "Found 2 occurrences. Comments added."Workflow 2: DevSecOps Provisioning Scans for a New Subnet
When standing up new infrastructure, DevSecOps needs to ensure the new assets are enrolled in the vulnerability management program.
"Bulk add the subnet 192.168.50.0/24 to Intruder as targets and tag them 'new-infra'. Then, verify our license counts to ensure we didn't exceed our limit. Finally, start an immediate scan targeting only the 'new-infra' tag."
Step-by-step execution:
- Add Targets: ChatGPT calls
intruder_targets_bulk_create, passing the CIDR block and the tag. - Check Licenses: It calls
list_all_intruder_licensesto verifyavailable_infrastructure_licensesis greater than zero. - Start Scan: It calls
create_a_intruder_scanpassingtag_names: ["new-infra"]in the body.
Outcome: The IPs are ingested, licensed, and actively scanning without the engineer ever opening the Intruder console.
Security and Access Control
Exposing an enterprise security scanner to an AI model requires strict governance. Truto provides multiple layers of access control at the MCP server level:
- Method Filtering: Constrain the server to specific operation types using
config.methods. Settingmethods: ["read"]ensures the LLM can query vulnerabilities but cannot trigger scans or delete targets. - Tag Filtering: Restrict access to specific functional areas using
config.tags. By passingtags: ["scans"], the server will only expose scan-related endpoints and hide target creation or licensing tools. - Extra Authentication: Enable
require_api_token_auth: trueto force the client to provide a valid Truto API token in theAuthorizationheader. This prevents unauthorized execution even if the MCP server URL leaks. - Automatic Expiration: Set an
expires_atISO datetime. Once this timestamp is reached, Truto automatically destroys the token and drops the server, ensuring temporary contractors or test agents do not retain perpetual access to your Intruder environment.
Building agentic workflows on top of Intruder transforms vulnerability management from a manual reporting exercise into a reactive, automated discipline. By utilizing a managed MCP server, you eliminate the integration debt and focus purely on security orchestration.
FAQ
- What is the easiest way to connect Intruder to ChatGPT?
- The best way to connect Intruder to ChatGPT is Elaichi: connect Intruder to Elaichi once, then add Elaichi to ChatGPT as a connector. Two steps, about a minute, with a 14-day free trial and no credit card required.
- Does Truto automatically retry Intruder API requests if they are rate-limited?
- No. Truto does not retry, throttle, or apply backoff on rate limit errors. When Intruder returns an HTTP 429, Truto passes that error directly to the caller while normalizing the rate limit information into standard headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset). The caller or LLM must handle the retry logic.
- Can I restrict the ChatGPT MCP server to read-only access for Intruder?
- Yes. When creating the MCP server, you can pass a config object with methods set to ["read"]. This ensures the LLM can only query vulnerabilities and targets, but cannot trigger scans or delete assets.
- How are Intruder tool schemas generated for ChatGPT?
- Truto dynamically generates tool definitions based on the integration's resource configurations and documentation records. If an Intruder API method has a valid documentation record, it becomes a callable tool with validated query and body JSON schemas.
- What happens if a user tries to schedule a scan at an invalid time?
- Intruder strictly requires that recurring scan schedules start on the hour. If the LLM attempts to pass a timestamp with minutes or seconds (e.g., 14:30:00Z), the API will reject it, and the MCP server will pass the validation error back to ChatGPT.