MCP AbuseIPDB Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| LOG_LEVEL | No | Logging level | INFO |
| DAILY_QUOTA | No | API request quota | 1000 |
| MAX_AGE_DAYS | No | Default report age limit | 30 |
| CACHE_DB_PATH | No | SQLite cache file location | ./cache.db |
| ABUSEIPDB_API_KEY | Yes | Your AbuseIPDB API key | |
| ALLOW_PRIVATE_IPS | No | Allow checking private IPs | false |
| CONFIDENCE_THRESHOLD | No | Default confidence threshold | 75 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_ipA | Check the reputation of a single IP address using AbuseIPDB |
| check_blockB | Check the reputation of a CIDR block using AbuseIPDB |
| get_blacklistB | Retrieve the AbuseIPDB blacklist of malicious IP addresses |
| bulk_checkB | Check multiple IP addresses in batch against AbuseIPDB |
| enrich_log_lineB | Extract and enrich IP addresses from a log line with AbuseIPDB data |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| triage_ip | Generate analyst triage notes for an IP address |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| Cache Information | Current cache statistics and status |
| Usage Documentation | API usage documentation and examples |
TDQS
Scored across 5 tools
Each tool has a clearly distinct purpose: bulk_check handles multiple IPs, check_block covers CIDR blocks, check_ip is for single IPs, enrich_log_line processes log lines, and get_blacklist retrieves a blacklist. There is no overlap or ambiguity between these functions.
All tools follow a consistent verb_noun pattern (e.g., check_ip, get_blacklist) with clear, descriptive names. There are no deviations in style or convention across the set.
With 5 tools, the server is well-scoped for AbuseIPDB functionality, covering key operations like single/bulk IP checks, block analysis, log enrichment, and blacklist retrieval. Each tool earns its place without feeling excessive or insufficient.
The tool set provides comprehensive coverage for the AbuseIPDB domain, including reputation checks at different scales (single, bulk, block), log enrichment, and blacklist access. There are no obvious gaps in the core workflows for this purpose.