Cybersecurity Threat Intelligence MCP
Server Details
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
- Status
- Unhealthy
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- FoundryNet/cyber-intel-mcp
- GitHub Stars
- 0
- Server Listing
- Cybersecurity Threat Intelligence MCP
TDQS
Scored across 9 tools
Each tool targets a distinct resource: domain, IP, CVE, threat feed, daily brief, product scan, and meta-info. The only closely related pair (brief_summary vs daily_brief) is explicitly differentiated as a cheap sample vs full brief, so no real ambiguity exists.
All tool names use lowercase snake_case, but the grammatical pattern is mixed: some are verb_noun (check_domain, check_ip, search_cve) while others are noun_noun or adjective_noun (cve_detail, daily_brief, threat_feed, vulnerability_scan, mint_info, brief_summary). The style is consistent, but the verb-first convention is not uniform.
Nine tools cover the core threat-intelligence workflows without bloat: reputation lookups, CVE search/details, vulnerability scanning, briefs, and a live feed. This is a well-scoped count for the domain.
The server covers IP and domain reputation, CVE research, product scanning, and daily briefs, but lacks a single-tool lookup for hash or URL reputation (only available via the generic threat_feed). This is a workable minor gap since the feed can filter by those types, but a dedicated check_hash or check_url tool would make the surface fully complete.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
7 tool updates
- Changed
brief_summary1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
check_domain1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
check_ip1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
daily_brief2 fields changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402." - changed
Input schema / properties / stripe_token / descriptionPrevious value: -"Stripe Checkout Session id (cs_…), when re-calling after\npaying the Stripe payment link (alternative to x402). Can also be\nsupplied via the X-Stripe-Token header."New value: +"Stripe Checkout Session id (cs_…), when re-calling after\npaying the Stripe payment link (alternative to the metered rail). Can\nalso be supplied via the X-Stripe-Token header."
- Changed
search_cve1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
threat_feed1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
- Changed
vulnerability_scan1 field changed- changed
Input schema / properties / payment_tx / descriptionPrevious value: -"Solana tx signature, when re-calling after a 402."New value: +"payment transaction reference, when re-calling after a 402."
1 tool update
- Added
brief_summary
1 tool update
- Changed
daily_brief1 field changed- added
Input schema / properties / stripe_tokenAdded value: +{ + "anyOf": [ + { + "type": "string" + }, + { + "type": "null" + } + ], + "default": null, + "description": "Stripe Checkout Session id (cs_…), when re-calling after\npaying the Stripe payment link (alternative to x402). Can also be\nsupplied via the X-Stripe-Token header." +}
1 tool update
- Added
daily_brief
7 tool updates
- First observed
check_domain - First observed
check_ip - First observed
cve_detail - First observed
mint_info - First observed
search_cve - First observed
threat_feed - First observed
vulnerability_scan
Related MCP Connectors
CVE & vulnerability search: 365k+ CVEs/NotCVEs, CVSS, EPSS, CISA KEV, exploits, patches, versions.
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.
Defensive vulnerability intelligence search across public CVE/NVD and GitHub advisory APIs with CVSS
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceProvides multi-source vulnerability intelligence for AI-powered security operations, combining NVD CVSS, CISA KEV, and EPSS scores without requiring an API key.1MIT
- AlicenseNot gradedqualityCmaintenanceProvides CVE lookup, search, and exploit intelligence from public vulnerability sources (NVD, CISA KEV, EPSS) for AI agents to produce remediation guidance without consuming LLM tokens for data fetching.1MIT
- AlicenseNot gradedqualityAmaintenanceSearch and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST National Vulnerability Database.5011Apache 2.0
- AlicenseNot gradedqualityFmaintenanceProvides unified access to vulnerability data from NVD, MITRE, and GitHub Security Advisories for cybersecurity intelligence.3419MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.