Skip to main content
Glama
alephnan

MCP AbuseIPDB Server

by alephnan

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
LOG_LEVELNoLogging levelINFO
DAILY_QUOTANoAPI request quota1000
MAX_AGE_DAYSNoDefault report age limit30
CACHE_DB_PATHNoSQLite cache file location./cache.db
ABUSEIPDB_API_KEYYesYour AbuseIPDB API key
ALLOW_PRIVATE_IPSNoAllow checking private IPsfalse
CONFIDENCE_THRESHOLDNoDefault confidence threshold75

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription
check_ipA

Check the reputation of a single IP address using AbuseIPDB

check_blockB

Check the reputation of a CIDR block using AbuseIPDB

get_blacklistB

Retrieve the AbuseIPDB blacklist of malicious IP addresses

bulk_checkB

Check multiple IP addresses in batch against AbuseIPDB

enrich_log_lineB

Extract and enrich IP addresses from a log line with AbuseIPDB data

Prompts

Interactive templates invoked by user choice

NameDescription
triage_ipGenerate analyst triage notes for an IP address

Resources

Contextual data attached and managed by the client

NameDescription
Cache InformationCurrent cache statistics and status
Usage DocumentationAPI usage documentation and examples

TDQS

A3.8/5.0

Scored across 5 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: bulk_check handles multiple IPs, check_block covers CIDR blocks, check_ip is for single IPs, enrich_log_line processes log lines, and get_blacklist retrieves a blacklist. There is no overlap or ambiguity between these functions.

Naming Consistency5/5

All tools follow a consistent verb_noun pattern (e.g., check_ip, get_blacklist) with clear, descriptive names. There are no deviations in style or convention across the set.

Tool Count5/5

With 5 tools, the server is well-scoped for AbuseIPDB functionality, covering key operations like single/bulk IP checks, block analysis, log enrichment, and blacklist retrieval. Each tool earns its place without feeling excessive or insufficient.

Completeness5/5

The tool set provides comprehensive coverage for the AbuseIPDB domain, including reputation checks at different scales (single, bulk, block), log enrichment, and blacklist access. There are no obvious gaps in the core workflows for this purpose.

Maintenance

ActivityInactive
ResponsivenessNo issues