@ismalicious/mcp-server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@ismalicious/mcp-serverscan this untrusted text for prompt injection before I act on it"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@ismalicious/mcp-server
A zero-dependency Model Context Protocol server that gives an AI agent isMalicious threat intelligence: reputation verdicts for indicators, the CVE catalog, and the isinjected gate that scans untrusted content for prompt injection before the agent acts on it.
Install
{
"mcpServers": {
"ismalicious": {
"command": "npx",
"args": ["-y", "@ismalicious/mcp-server"],
"env": {
"ISMALICIOUS_API_KEY": "your-api-key",
"ISMALICIOUS_API_SECRET": "your-api-secret"
}
}
}
}Keys: https://ismalicious.com/app/account. Free keys exist. Without the two
variables the server still starts, offering only bootstrap_key, which mints a
free key from an email address and uses it for the session (see below).
Registry name: com.ismalicious/mcp-server
(https://registry.modelcontextprotocol.io/v0/servers?search=ismalicious).
Related MCP server: contrastapi
Tools
Tool | What it answers | Cost |
| Prompt-injection scan plus link reputation over a block of untrusted text. | 1 scan |
| Reputation of one URL, domain or IP before fetching it. | 1 scan |
| Full reputation picture of an IP, domain, URL or hash: | 1 request |
| One CVE by id: description, CVSS, EPSS, CISA KEV status and due date, exploitation evidence, references. The only CVE path. | 1 request |
| Latest CVEs, optional | 1 request |
| Domains the corpus lists that look like a brand or domain — typosquats, homoglyphs, other TLDs or hosts, phishing-word combinations — most dangerous first. | 1 request |
| Reputation of up to 100 indicators in one call: per row | 1 request per indicator |
| Only without a configured key: mint a free key from an email, one per IP per day. | — |
The default search API reads a bare keyword as its .com (paypal →
paypal.com) and returns at most 500 listed lookalikes. limit only reduces
that sample. Only listed domains are returned and a name buried in a longer
hostname is not matched, so an empty answer does not prove that no lookalike
exists.
The MCP result labels total_hits_scope as upstream_sample. Legacy or custom
API responses without completeness metadata produce truncated: null.
Scans and requests are two meters: https://ismalicious.com/api-docs.
check_indicator example
{
"indicator": "45.148.10.242",
"type": "ip",
"verdict": "malicious",
"headline": "45.148.10.242 is flagged malicious by 7 sources (scanner); risk 78/100; seen from 2026-06-02 to 2026-09-01.",
"recommendedAction": "block",
"malicious": true,
"risk": { "score": 78, "level": "high" },
"reputation": {
"malicious": 7,
"suspicious": 0,
"harmless": 0,
"undetected": 0
},
"blocklist": {
"hits": 7,
"listed": true,
"sources": [{ "name": "…", "category": "ip" }]
},
"network": { "countryCode": "NL", "asn": "AS…", "org": "…" },
"flags": {
"delisted": false,
"knownGood": false,
"microsoftTenant": false,
"ransomware": false,
"relatedInfrastructure": true
},
"reportUrl": "https://ismalicious.com/report?query=45.148.10.242"
}blocklist counts threat listings only. Listings whose threatClass is
infrastructure, policy or allowlist — a cloud provider's published
ranges, a Tor exit list, an ad-blocking list — say what the entity is or what
a customer may choose to block, not that it attacked anyone, so they never
reach the verdict. They are reported under infrastructure, which is absent
when there are none:
{
"indicator": "13.107.6.152",
"type": "ip",
"verdict": "clean",
"headline": "13.107.6.152 is not listed by any threat source; known infrastructure: cloud, saas; risk 12/100.",
"recommendedAction": "allow",
"malicious": false,
"risk": { "score": 12, "level": "low" },
"blocklist": { "hits": 0, "listed": false, "sources": [] },
"infrastructure": {
"attributes": ["cloud", "saas"],
"sources": [
{
"name": "Azure IP Ranges",
"category": "infrastructure",
"threatClass": "infrastructure"
},
{
"name": "Microsoft 365 endpoints",
"category": "infrastructure",
"threatClass": "infrastructure"
}
]
},
"network": {
"countryCode": "US",
"asn": "AS8075",
"org": "Microsoft Azure Cloud (eastus2)"
},
"reportUrl": "https://ismalicious.com/report?query=13.107.6.152"
}attributes is one or more of tor-exit, vpn, proxy, doh-resolver,
dns-resolver, sinkhole, cloud, cdn, crawler, scanner,
monitoring, disposable-email, dynamic-dns, url-shortener, bogon,
saas, allowlist; new ones may appear. An indicator cited by a honeypot
feed and sitting in a cloud range keeps its honeypot verdict.
A hash NSRL knows (flags.knownGood) that a threat blocklist also lists comes
back suspicious with recommendedAction: "review", never malicious /
block: NSRL identifies known software, it does not clear it, and the two
sources disagree, which is a call for an analyst. The headline names the
conflict (<sha256> is known software (NSRL), yet 2 sources list it; review before blocking.) and blocklist still lists the citing sources.
check_indicators relays each row's recommendedAction from the API as it
comes; its rows carry no NSRL flag.
Errors
Every failure is a result with isError: true and this body:
{
"error": "rate_limited",
"status": 429,
"message": "Rate limit exceeded",
"quota": {
"kind": "burst",
"limit": 60,
"remaining": 0,
"plan": "FREE",
"retry_after": 30,
"resets_at": "…"
},
"hint": "Wait 30s before retrying."
}error is one of rate_limited, unauthorized, forbidden, not_found,
bad_request, upstream_error, timeout, network_error, invalid_params.
quota.kind is burst, monthly, daily, scans or issuance. A 401 says
whether no key is configured or the configured one was refused.
Timeouts and cancellation
Gate tools 15 s, check_indicator 25 s, CVE tools 10 s, search_indicators
20 s, check_indicators 60 s, bootstrap_key 15 s. ISMALICIOUS_TIMEOUT_MS
replaces all of them. A notifications/cancelled
from the client aborts the HTTP call; the cancelled request gets no response.
Resource
ismalicious://quota (application/json): the scan meter from
GET /gate/quota and the request-quota headers seen on the last billed call
of this session.
Environment
Variable | Meaning |
| Key pair; optional (bootstrap mode without them). |
| Defaults to |
| Overrides every tool timeout. |
Development
npm install
npm run typecheck && npm test && npm run build
node scripts/check-version.mjs # versions and server.json shape
node scripts/smoke.mjs # stdio end-to-end against a stub APIThe version is declared once in src/version.ts; CHANGELOG.md lists what changed.
This repository mirrors packages/mcp-server from the isMalicious monorepo, where
releases to npm and the MCP registry are cut. Issues and pull requests are welcome here.
Available Tools
1 toolbootstrap_keyA
No API key is configured. Mint a free isMalicious API key from an email address, use it for the rest of this session, and return it so it can be saved in the MCP client config (ISMALICIOUS_API_KEY / ISMALICIOUS_API_SECRET). One key per IP address per day; the address receives a link to claim the account. Ask the user for their email before calling.
| Name | Required | Description | Default |
|---|---|---|---|
| Yes | The email address that will own the key. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry the behavioral burden, and it does well: it discloses the rate limit (one key per IP per day), the side effect (the address receives an account-claim link), the session lifetime, and the config keys the result feeds into. It stops short of stating key expiry, failure modes, or error behavior, which keeps it out of the top band.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the triggering condition, then action, then constraints. Every sentence carries distinct information — no restating of the name, no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, and the description adequately signals the return (the key to be saved into MCP client config), plus the per-IP rate limit and email side effect. It omits error conditions and key longevity, a minor gap for a one-parameter bootstrap tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% for the single email parameter, so the baseline would be 3. The description adds meaning beyond the schema by mandating that the email come from the user before invocation, which is procedural guidance the schema cannot express.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Mint a free isMalicious API key from an email address') and frames the exact condition under which it applies ('No API key is configured'). No sibling tools exist, so no differentiation is required, and the purpose is unmistakable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit when-to-use context (no key configured), a hard precondition ('Ask the user for their email before calling'), and the scope of the resulting key ('use it for the rest of this session'). Usage is fully specified with no inference required.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.3.0- First observed
bootstrap_key
TDQS
Scored across 1 tool
With only one tool in the set, there is no possibility of overlap or misselection between tools. The single tool has a single, clearly stated purpose (minting an API key).
The lone tool uses a readable snake_case verb_noun style (bootstrap_key), which is a sensible convention. However, a single name provides no evidence of a consistent pattern across the set, so it cannot be rated as exemplary.
One tool is far too few for a server fronting the isMalicious API, which implies a broader surface (e.g. checking URLs/domains/hashes). The server only exposes an onboarding/auth step rather than the API's actual functionality.
The surface covers only a one-time key bootstrap and none of the security-checking operations the isMalicious API presumably offers. There is no core CRUD/query capability at all, leaving the server severely incomplete for its stated purpose.
Maintenance
Related MCP Connectors
STIX IOCs, CVE lookups w/ EPSS/KEV, ATT&CK dossiers, OFAC wallet sanctions, domain age checks.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Real-time threat intel for AI agents: 890K+ IOCs incl. prompt-injection & AI-skill threats
Live threat intel for agents: incidents, actors, CVEs with KEV/EPSS, ransomware leak-site victims.
Related MCP Servers
- AlicenseAqualityDmaintenancesecurity tools for AI agents: URL safety scanning, prompt injection detection (200+ patterns), email/password breach checks via HIBP, domain & IP reputation analysis, and AI skill supply chain scanning. Free tier (3 calls/day) or pay-per-request with USDC micropayments via x402.926 npm1MIT
- AlicenseAqualityAmaintenanceSecurity intelligence API for AI models. CVE lookup with EPSS/KEV, domain recon (DNS, WHOIS, SSL, subdomains, WAF), and code security checks (secrets, injection, headers). 16 tools, no API key required.5534MIT

relayshield-mcpofficial
AlicenseAqualityAmaintenanceSecurity intelligence for AI agents — breach detection, SIM swap, domain lookalikes, OAuth watchlist, and malware scanning. Subscription or x402 PAYG.11MIT- AlicenseNot gradedqualityFmaintenanceProvides CVE search enriched with EPSS exploit likelihood and CISA KEV status, plus live IP/domain reputation and a real-time threat feed for AI agents.MIT