Threatfox
Server Details
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- pipeworx-io/mcp-threatfox
- GitHub Stars
- 0
- Server Listing
- mcp-threatfox
TDQS
Scored across 35 tools
Several tools have overlapping boundaries: ask_pipeworx_beta explicitly mirrors ask_pipeworx exactly, ask_pipeworx_grounded and validate_claim both verify facts, and the polymarket_edges/arbitrage/bet_research suite scans for opportunities in related ways. The detailed descriptions help, but an agent must read carefully to choose correctly.
Mostly snake_case with consistent prefixes for families like ask_pipeworx_*, polymarket_*, and search_*. However verb/noun conventions are mixed (search_ioc, validate_claim, resolve_entity vs entity_profile, recent_changes, remember), so there is no single predictable pattern.
35 tools is heavy for a server named Threatfox, where only recent_iocs, search_ioc, search_malware, and search_hash directly address threat intelligence. The remaining 31 tools span unrelated domains, making the surface feel like a broad platform grab bag rather than a focused server.
Threat-intel coverage includes recent IOCs, specific indicator lookup, hash lookup, and malware-family search, which covers primary queries. Notable gaps remain, such as search by tag/threat type/confidence, bulk export, or IOC submission, and the broad non-threat tool surface lacks clear lifecycle coverage for several domains.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Changed
bet_research2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "market": "when-will-bitcoin-hit-150k" - }, - { - "market": "https://polymarket.com/event/when-will-bitcoin-hit-150k" - } -]New value: +[ + { + "market": "will-kristi-noem-win-the-2028-republican-presidential-nomination" + }, + { + "market": "https://polymarket.com/event/will-kristi-noem-win-the-2028-republican-presidential-nomination" + } +] - changed
Input schema / properties / market / descriptionPrevious value: -"Polymarket slug (\"when-will-bitcoin-hit-150k\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."New value: +"Polymarket slug (\"will-kristi-noem-win-the-2028-republican-presidential-nomination\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."
2 tool updates
- Changed
bet_research2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "market": "will-bitcoin-reach-100k-in-july-2026" - }, - { - "market": "https://polymarket.com/event/will-bitcoin-hit-150k-by-june-30-2026" - } -]New value: +[ + { + "market": "when-will-bitcoin-hit-150k" + }, + { + "market": "https://polymarket.com/event/when-will-bitcoin-hit-150k" + } +] - changed
Input schema / properties / market / descriptionPrevious value: -"Polymarket slug (\"will-bitcoin-hit-150k-by-june-30-2026\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k by June 30?\")"New value: +"Polymarket slug (\"when-will-bitcoin-hit-150k\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."
- Changed
polymarket_kalshi_spread2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "topic": "fed" - }, - { - "topic": "btc" - } -]New value: +[ + { + "topic": "fed" + }, + { + "topic": "btc" + }, + { + "topic": "bitcoin" + }, + { + "topic": "fed rate decision" + } +] - changed
Input schema / properties / topic / descriptionPrevious value: -"Pre-mapped: fed | btc | cpi | gdp | sp500 | recession | next_pope | next_uk_pm | next_israel_pm | 2028_president"New value: +"Subject to compare. Canonical keys: fed | btc | eth | cpi | gdp | sp500 | recession | next_pope | next_uk_pm | next_israel_pm | 2028_president — but aliases and keywords resolve too (\"bitcoin\", \"fed rate decision\", \"ethereum\", \"inflation\", \"s&p 500\", \"us recession\", \"next pope\", \"2028 election\"). Check resolution.topic_matched_by in the response: \"exact\"/\"alias\" is a curated pairing, \"phrase\"/\"token\" is a keyword guess."
Related MCP Connectors
MalwareBazaar MCP — abuse.ch malware sample database (free, key required)
AlienVault OTX MCP — Open Threat Exchange (free with key)
STIX 2.1 threat indicator feed: IPs, domains, URLs, file hashes from ThreatFox, OTX, NVD.
11Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceMCP server exposing tweetfeed.live's IOC feed (URLs, domains, IPs, hashes) as tools for querying threat intelligence, with checks, enrichment, trends, and campaign clustering.MIT
- AlicenseAqualityDmaintenanceDark web & threat intelligence for AI agents. HIBP, ThreatFox, ransomware tracking, Tor .onion access, blockchain intel, exploit search, stealer logs, malware analysis — unified into a single MCP server.66186 npm442MIT
- AlicenseNot gradedqualityDmaintenanceEnables querying threat intelligence data about files, URLs, IPs, and domains from multiple abuse.ch platforms (MalwareBazaar, URLhaus, and ThreatFox) through a unified API. Provides comprehensive security reports and threat analysis data for cybersecurity investigations.3MIT

honeylabs-mcpofficial
AlicenseAqualityBmaintenanceHoneypot threat intelligence for AI agents. Query 90 days of probe data from our sensor network: IP reputation, scanner classification, CVE probing trends, TLS/SSH/JA4 fingerprints. Free tier 500 credits/day, OAuth + bearer auth, streamable HTTP at https://mcp.honeylabs.net/mcp.72MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.