Koot by Datakoot
Server Details
One-call briefings for AI agents: dependency risk (KEV/EPSS), SEC companies, domains, US places.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-06-18
- URL
- Repository
- datakoot/koot-mcp
- GitHub Stars
- 0
TDQS
Score is being calculated.
Available Tools
8 toolsbrief_companyAsk Koot: Brief Me on a CompanyRead-onlyIdempotentInspect
One call briefs you on a US public company: SEC profile, recent filings (8-K material events flagged), insider trades and reported financials. Give a ticker, name or CIK.
| Name | Required | Description | Default |
|---|---|---|---|
| company | Yes | Ticker (TSLA), company name (Tesla) or CIK. |
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
brief_domainAsk Koot: Check a DomainRead-onlyIdempotentInspect
One call checks a domain: registration and DNS, email security (SPF/DKIM/DMARC), tech stack, and subdomains from certificate logs.
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain, e.g. stripe.com. |
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
brief_placeAsk Koot: What's Happening at a Place?Read-onlyIdempotentInspect
One call briefs you on a US place: current conditions, forecast, active weather alerts for the state, nearby earthquakes and elevation.
| Name | Required | Description | Default |
|---|---|---|---|
| place | Yes | US city or address, e.g. 'Harrisburg, PA'. |
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
brief_stackAsk Koot: Is My Stack Safe?Read-onlyIdempotentInspect
One call answers 'is my project safe?'. Checks every package for known vulnerabilities, tells you which are being EXPLOITED IN THE WILD right now (CISA KEV) or likely to be (EPSS), flags abandoned/deprecated packages, and returns a ranked fix-first list. Accepts a package list or a pasted package.json / requirements.txt.
| Name | Required | Description | Default |
|---|---|---|---|
| manifest | No | Or paste a whole package.json or requirements.txt here. | |
| packages | No | Packages as 'name' or 'name@version' strings (or {name, version, ecosystem} objects), e.g. ["lodash@4.17.15", "express"]. | |
| ecosystem | No | Registry for string packages (default npm). |
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
koot_unwatchKoot Watch: Stop Watching (Pro)DestructiveIdempotentInspect
PRO. Stop watching some packages or companies, all: true to stop and forget everything, or stop_alerts: true to turn off Slack/Discord alerts.
| Name | Required | Description | Default |
|---|---|---|---|
| all | No | ||
| packages | No | ||
| companies | No | ||
| stop_alerts | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
koot_watchKoot Watch: Watch My Stack & Companies (Pro)IdempotentInspect
PRO. Tell Koot what to watch once: packages (or a pasted package.json) and/or companies (tickers). Koot remembers them and only reports what is NEW: newly exploited or likely-exploited vulnerabilities in your packages, and new SEC filings (8-K material events flagged) from your companies. Add notify_url (Slack or Discord webhook) and Koot posts new items there by itself, daily. Calling again adds to the list.
| Name | Required | Description | Default |
|---|---|---|---|
| manifest | No | Or paste a whole package.json or requirements.txt here. | |
| packages | No | Packages as 'name' or 'name@version' strings (or {name, version, ecosystem} objects), e.g. ["lodash@4.17.15", "express"]. | |
| companies | No | US public companies to watch for NEW SEC filings: tickers, names or CIKs, e.g. ["TSLA", "AAPL"]. Up to 25. | |
| ecosystem | No | Registry for string packages (default npm). | |
| notify_url | No | Optional. A Slack or Discord incoming-webhook URL. Koot checks daily and posts there only when something NEW is exploited or likely to be. |
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
koot_watchesKoot Watch: What Are You Watching? (Pro)Read-onlyIdempotentInspect
PRO. Lists what Koot is watching for you.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
koot_whats_newKoot Brief: Anything New for Me? (Pro)Inspect
PRO. Ask 'anything new?' and Koot reports only what changed since the last check: new exploited or likely-exploited issues in your watched packages and new SEC filings from your watched companies. Great to call at the start of every session.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| koot | Yes | Koot's one-line answer. |
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
8 tool updates
- First observed
brief_company - First observed
brief_domain - First observed
brief_place - First observed
brief_stack - First observed
koot_unwatch - First observed
koot_watch - First observed
koot_watches - First observed
koot_whats_new
Related MCP Connectors
Threat intel for AI agents: IOCs, CVEs (EPSS/KEV), wallet sanctions and age, domain and URL checks.
Public data intelligence for AI agents — CVE, compliance, patents, contracts, domains.
Live threat intel for agents: incidents, actors, CVEs with KEV/EPSS, ransomware leak-site victims.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Related MCP Servers
- AlicenseNot gradedqualityFmaintenanceProvides CVE search enriched with EPSS exploit likelihood and CISA KEV status, plus live IP/domain reputation and a real-time threat feed for AI agents.MIT
- AlicenseAqualityAmaintenanceSecurity intelligence API for AI models. CVE lookup with EPSS/KEV, domain recon (DNS, WHOIS, SSL, subdomains, WAF), and code security checks (secrets, injection, headers). 16 tools, no API key required.5533MIT
- AlicenseNot gradedqualityDmaintenanceProvides CVE lookup, search, and exploit intelligence from public vulnerability sources (NVD, CISA KEV, EPSS) for AI agents to produce remediation guidance without consuming LLM tokens for data fetching.1MIT
- AlicenseNot gradedqualityBmaintenanceVulnerability intelligence for AI agents that enables CVE lookup, package vulnerability checks, and dependency auditing without API keys.MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.