Skip to main content
Glama
Cyreslab-AI

Shodan MCP Server

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
SHODAN_API_KEYYesYour Shodan API key

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription
get_host_infoC

Get detailed information about a specific IP address

search_shodanC

Search Shodan's database for devices and services

scan_network_rangeC

Scan a network range (CIDR notation) for devices

get_ssl_infoC

Get SSL certificate information for a domain

search_iot_devicesC

Search for specific types of IoT devices

get_host_countA

Get the count of hosts matching a search query without consuming query credits

list_search_facetsA

List all available search facets that can be used with Shodan queries

list_search_filtersB

List all available search filters that can be used in Shodan queries

parse_search_tokensC

Parse a search query to understand which filters and parameters are being used

list_portsB

List all ports that Shodan crawls on the Internet

list_protocolsA

List all protocols that can be used when performing on-demand Internet scans

get_api_infoB

Get information about your API plan including credits and limits

get_my_ipA

Get your current IP address as seen from the Internet

dns_lookupB

Resolve hostnames to IP addresses using DNS lookup

reverse_dns_lookupC

Get hostnames for IP addresses using reverse DNS lookup

get_domain_infoC

Get comprehensive domain information including subdomains and DNS records

get_account_profileB

Get account profile information including membership status and credits

get_cve_infoC

Get detailed information about a specific CVE

search_cvesC

Search for vulnerabilities with various filters

get_cpesC

Get Common Platform Enumeration (CPE) information for products

get_newest_cvesB

Get the newest vulnerabilities from the CVE database

get_kev_cvesB

Get Known Exploited Vulnerabilities (KEV) from CISA

get_cves_by_epssC

Get CVEs sorted by EPSS score (Exploit Prediction Scoring System)

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
Host InformationInformation about a specific IP address from Shodan

TDQS

B3.4/5.0

Scored across 23 tools

Disambiguation4/5

Most tools have distinct purposes, but there is some overlap between search tools (search_shodan, search_iot_devices, search_cves) and informational tools (get_cves_by_epss, get_newest_cves, get_kev_cves) that could cause confusion. Descriptions help clarify, but the boundaries between general and specific search/query tools are not perfectly clear.

Naming Consistency5/5

Tool names follow a highly consistent verb_noun pattern throughout, such as get_account_profile, list_ports, search_shodan, and parse_search_tokens. There are no deviations in naming conventions, making the set predictable and easy to understand.

Tool Count3/5

With 23 tools, the count is borderline high for a Shodan server, which might feel heavy for agents to navigate efficiently. While it covers many aspects of Shodan's functionality, some tools could potentially be consolidated or omitted without losing core capabilities.

Completeness5/5

The tool set provides comprehensive coverage for Shodan's domain, including account management, host and domain lookups, vulnerability searches, network scanning, and query parsing. There are no obvious gaps; it supports full CRUD-like operations and lifecycle management for security research tasks.

Maintenance

ActivityMaintained
ResponsivenessNo issues