Cybersecurity Threat Intelligence MCP
Server Details
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Uptime
- 0.0% over 46 days
- Last Tested
- Transport
- Streamable HTTP
- URL
- Server Listing
- Cybersecurity Threat Intelligence MCP
TDQS
Scored across 9 tools
Each tool targets a distinct resource: domain, IP, CVE, threat feed, daily brief, product scan, and meta-info. The only closely related pair (brief_summary vs daily_brief) is explicitly differentiated as a cheap sample vs full brief, so no real ambiguity exists.
All tool names use lowercase snake_case, but the grammatical pattern is mixed: some are verb_noun (check_domain, check_ip, search_cve) while others are noun_noun or adjective_noun (cve_detail, daily_brief, threat_feed, vulnerability_scan, mint_info, brief_summary). The style is consistent, but the verb-first convention is not uniform.
Nine tools cover the core threat-intelligence workflows without bloat: reputation lookups, CVE search/details, vulnerability scanning, briefs, and a live feed. This is a well-scoped count for the domain.
The server covers IP and domain reputation, CVE research, product scanning, and daily briefs, but lacks a single-tool lookup for hash or URL reputation (only available via the generic threat_feed). This is a workable minor gap since the feed can filter by those types, but a dedicated check_hash or check_url tool would make the surface fully complete.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
7 tool updates
- Changed
brief_summary1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
check_domain1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
check_ip1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
daily_brief2 fields changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402." - changed
Input schema / properties / stripe_token / descriptionPrevious value: -"Stripe Checkout Session id (cs_…), when re-calling after\npaying the Stripe payment link (alternative to x402). Can also be\nsupplied via the X-Stripe-Token header."New value: +"Stripe Checkout Session id (cs_…), when re-calling after\npaying the Stripe payment link (alternative to the metered rail). Can\nalso be supplied via the X-Stripe-Token header."
- Changed
search_cve1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
threat_feed1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
vulnerability_scan1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
1 tool update
- Added
brief_summary
1 tool update
- Changed
daily_brief1 field changed- added
Input schema / properties / stripe_tokenAdded value: +{ + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "default": null, + "description": "Stripe Checkout Session id (cs_…), when re-calling after\npaying the Stripe payment link (alternative to x402). Can also be\nsupplied via the X-Stripe-Token header." +}
1 tool update
- Added
daily_brief
7 tool updates
- First observed
check_domain - First observed
check_ip - First observed
cve_detail - First observed
mint_info - First observed
search_cve - First observed
threat_feed - First observed
vulnerability_scan
Related MCP Connectors
CVE & vulnerability search: 365k+ CVEs/NotCVEs, CVSS, EPSS, CISA KEV, exploits, patches, versions.
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.
CVE triage in one call: NVD, CVSS, CISA KEV, EPSS, public exploits and an explained risk score.
Related MCP Servers
- AlicenseAqualityBmaintenanceEnables AI agents to search, correlate, and monitor real-time vulnerability intelligence from NVD, CISA KEV, EPSS, and MITRE ATT&CK, including CVE details, critical CVE tracking, known exploited vulnerabilities, and exploitation probability scores.52MIT
- AlicenseNot gradedqualityDmaintenanceProvides multi-source vulnerability intelligence for AI-powered security operations, combining NVD CVSS, CISA KEV, and EPSS scores without requiring an API key.1MIT
- AlicenseNot gradedqualityDmaintenanceProvides CVE lookup, search, and exploit intelligence from public vulnerability sources (NVD, CISA KEV, EPSS) for AI agents to produce remediation guidance without consuming LLM tokens for data fetching.1MIT
- AlicenseNot gradedqualityAmaintenanceSearch and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST National Vulnerability Database.406 npm1Apache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.