Skip to content

Executive Summary

The Orca Security plugin integrates ChatGPT and Codex with Orca’s MCP server to provide security context for AI assistants. This connection allows the models to access correlated data from Orca, including alerts, assets, attack paths, permissions, and code origins from the cloud environment. The core concept is that the model performs reasoning over findings that are already contextualized within Orca's Unified Data Model, meaning it reasons over reachability and impact rather than raw data dumps.
The plugin provides several specific functionalities: security teams can use prompts to discover exposed risks, investigate alerts by tracing attack paths interactively, determine the effective permissions of identities, correlate similar findings across the environment, and generate high-level risk summaries in minutes. For developers using Codex, the integration allows fixing security issues directly from context, enabling them to trace code changes back to cloud assets and fix configurations at the source within the development workflow.
The necessity stems from the inefficiency of traditional security workflows where analysts must manually pull data from consoles to answer complex questions, contrasting with the need for automated, contextualized response in modern security operations.

Facts Only

* The Orca Security plugin connects ChatGPT and Codex to Orca’s MCP server.
* The plugin grants access to Orca data, including alerts, assets, attack paths, effective permissions, code origins, and documentation.
* The plugin uses Orca’s Unified Data Model, where all assets, alerts, identities, and dependencies are correlated prior to prompting.
* Exposed tools include `discoverysearch`, `getalert`/`getalertattackpathdata`, `getassetbyid`/`getassetbyname`, `getawseffectivepermissionspolicyonasset`, `getalertswithsimilarmalware`, `getcodeorigin`/`getterraformchain`, `updatealertstatus`, and `documentationsearch`.
* ChatGPT renders alerts as interactive Orca cards instead of text.
* Developers use Codex to investigate alerts, find corresponding code in repositories, and prepare fixes via a single prompt.
* The plugin enables finding internet-exposed risks by ranking assets based on Orca's risk score.
* It allows for tracing an alert’s attack path and blast radius interactively.
* It enables correlating similar findings across the environment to identify patterns.
* The platform is backed by Orca, which correlates risk across cloud, code, AI, and application environments.

Full Take

The integration fundamentally shifts the locus of security context from an external, manual lookup process to an intrinsic, integrated data layer accessible via AI. This moves the burden of context aggregation—the slow, error-prone step of compiling asset lists, finding associated alerts, and mapping permissions—out of human cognition and into the model’s reasoning capacity. The insight lies in how risk is transformed: it moves from being a static list of vulnerabilities (a CVE number) to a dynamic state of reachability and business impact (an attack path resulting in a blast radius).
The pattern observed is the automation of complex, multi-step investigative workflows. This does not just save time; it changes the cognitive bottleneck of security and development. When AI agents are fed correlated context rather than raw data, they exhibit "reasoning" over impact rather than merely processing information. The mechanism bridges the gap between descriptive knowledge (what a CVE is) and prescriptive action (which asset to patch first).
The implication is a potential acceleration of security maturity, but it also introduces a critical dependency on the fidelity and completeness of the underlying Unified Data Model. If the correlation within Orca is flawed or incomplete, the AI will reason over inaccurate risk profiles, potentially leading to decisions based on spurious correlations—a form of systemic trust vulnerability. The question shifts from "Can AI find the answer?" to "How do we ensure the context feeding the AI reflects true operational reality?" What mechanisms exist for verifying that the AI’s reasoning flows from verified, unmanipulated system state?

From the original · Orca Security

What is the Orca Security plugin for ChatGPT and Codex? The Orca Security plugin for ChatGPT and Codex connects both tools to Orca’s MCP server, giving security teams and developers access to their Orca data where they already work.
Read the full story at orca.security

Sentinel — Human

Confidence

The text reads like detailed technical marketing material explaining a specific software integration. While polished, the structure and focus on concrete workflow transformations suggest human expertise guiding the presentation of the facts.

Signals Detected
low severity: Sentence length variance and flow suggest human structuring, though the technical nature leads to some mechanical density.
low severity: The text maintains a strong internal logic focused on process transformation, demonstrating an applied understanding of a complex product integration.
low severity: The structured use of tables and numbered scenarios suggests organized content creation typical of marketing or technical white papers.
low severity: The specific mechanics, tool names (MCP server, Unified Data Model), and the detailed scenario walkthroughs feel grounded in a real product integration, not pure hallucination.
Human Indicators
Idiosyncratic emphasis on the 'Big idea: The model brings the reasoning. Orca brings the context' is a synthesized, high-level conceptual summary rather than generic LLM exposition.
The prescriptive nature of the 6 use cases and the specific examples provided in points 1 through 6 suggest a direct mapping from product functionality to user workflow, which requires contextual knowledge beyond simple pattern replication.
Connect Orca’s ChatGPT Plugin: Cloud Risk Context in Chat and Codex | Huntaegis