Isc Sans
Server Details
SANS Internet Storm Center (ISC) MCP.
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Uptime
- 45.9% over 37 days
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- pipeworx-io/mcp-isc-sans
- GitHub Stars
- 0
TDQS
Scored across 34 tools
Several tools have overlapping purposes: ask_pipeworx_beta is explicitly stated to currently behave identically to ask_pipeworx, and ask_pipeworx, ask_pipeworx_grounded, and deep_research all answer factual questions across the same catalog. The long descriptions do a decent job explaining when to prefer each, but the beta/stable duplication and the entity_profile/compare_entities/recent_changes/resolve_entity cluster create real misselection risk. Most other tool groups (polymarket_*, memory, subscriptions) are clearly distinct.
Almost everything is snake_case, which is good, but conventions are mixed: verb_noun (validate_claim, resolve_entity, generate_llms_txt), noun_phrase (threat_level, port_activity, ip_reputation), and branded prefixes (ask_pipeworx, polymarket_*, pipeworx_*). The three SANS ISC tools (ip_reputation, port_activity, threat_level) have no shared prefix and look like they belong to a different server.
34 tools is heavy for a single server and leans past the comfortable 3-15 range, especially since one (ask_pipeworx_beta) is currently a functional duplicate. The breadth of the underlying domain (thousands of sources) partially justifies the count, and each cluster is individually defensible, but there is clear room to consolidate.
Coverage is broad and mostly closed-loop: memory has remember/recall/forget, subscriptions have subscribe/list_subscriptions/unsubscribe/recent_alerts, and data workflows span lookup, research, entity resolution, comparison, and prediction markets. Minor gaps remain (no explicit update/patch for subscriptions beyond cancel-and-recreate, no delete for stored alerts), but agents can work around these.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Changed
bet_research2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "market": "when-will-bitcoin-hit-150k" - }, - { - "market": "https://polymarket.com/event/when-will-bitcoin-hit-150k" - } -]New value: +[ + { + "market": "will-kristi-noem-win-the-2028-republican-presidential-nomination" + }, + { + "market": "https://polymarket.com/event/will-kristi-noem-win-the-2028-republican-presidential-nomination" + } +] - changed
Input schema / properties / market / descriptionPrevious value: -"Polymarket slug (\"when-will-bitcoin-hit-150k\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."New value: +"Polymarket slug (\"will-kristi-noem-win-the-2028-republican-presidential-nomination\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."
2 tool updates
- Changed
bet_research2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "market": "will-bitcoin-reach-100k-in-july-2026" - }, - { - "market": "https://polymarket.com/event/will-bitcoin-hit-150k-by-june-30-2026" - } -]New value: +[ + { + "market": "when-will-bitcoin-hit-150k" + }, + { + "market": "https://polymarket.com/event/when-will-bitcoin-hit-150k" + } +] - changed
Input schema / properties / market / descriptionPrevious value: -"Polymarket slug (\"will-bitcoin-hit-150k-by-june-30-2026\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k by June 30?\")"New value: +"Polymarket slug (\"when-will-bitcoin-hit-150k\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."
- Changed
polymarket_kalshi_spread2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "topic": "fed" - }, - { - "topic": "btc" - } -]New value: +[ + { + "topic": "fed" + }, + { + "topic": "btc" + }, + { + "topic": "bitcoin" + }, + { + "topic": "fed rate decision" + } +] - changed
Input schema / properties / topic / descriptionPrevious value: -"Pre-mapped: fed | btc | cpi | gdp | sp500 | recession | next_pope | next_uk_pm | next_israel_pm | 2028_president"New value: +"Subject to compare. Canonical keys: fed | btc | eth | cpi | gdp | sp500 | recession | next_pope | next_uk_pm | next_israel_pm | 2028_president — but aliases and keywords resolve too (\"bitcoin\", \"fed rate decision\", \"ethereum\", \"inflation\", \"s&p 500\", \"us recession\", \"next pope\", \"2028 election\"). Check resolution.topic_matched_by in the response: \"exact\"/\"alias\" is a curated pairing, \"phrase\"/\"token\" is a keyword guess."
Related MCP Connectors
FIRST.org EPSS (Exploit Prediction Scoring System) MCP.
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.
RIPE Stat MCP — IP/ASN/BGP data
Related MCP Servers
- Apache 2.0
- AlicenseCqualityCmaintenanceIncident Triage MCP is a Model Context Protocol (MCP) server for incident triage. It provides safe, auditable tools for evidence retrieval, deterministic summaries, ticket workflows, and notifications.28Apache 2.0
- FlicenseNot gradedqualityCmaintenanceMCP server for detecting and analyzing scams using various heuristics and data sources.-
- AlicenseBqualityCmaintenanceDomain Name System Security Extensions (DNSSEC) Validation & Cryptographic Auditing MCP Server2MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.