Best Have I Been Pwned MCP Servers
Have I Been Pwned is a free online service that allows users to check if their personal data has been compromised in data breaches. It was created by Troy Hunt, a security researcher, to help people discover if their email addresses or passwords have been exposed in known data breaches.
Why this server?
Provides tools to check if email addresses have been found in data breaches, verify if passwords have been exposed, get detailed information about specific data breaches, and list all breaches in the system with optional domain filtering.
AlicenseAqualityCmaintenanceA Model Context Protocol (MCP) server that provides integration with the Have I Been Pwned API to check if your accounts or passwords have been compromised in data breaches.42MITWhy this server?
Allows AI agents to search for breached accounts, credentials, and pastes using the Have I Been Pwned API.
AlicenseAqualityDmaintenanceDark web & threat intelligence for AI agents. HIBP, ThreatFox, ransomware tracking, Tor .onion access, blockchain intel, exploit search, stealer logs, malware analysis — unified into a single MCP server.66338 npm467MITWhy this server?
Enables checking email addresses for known data breaches as part of Maltego investigations.
AlicenseAqualityDmaintenanceTurns an LLM into a Maltego CE investigation copilot, enabling AI-assisted OSINT investigations by building, analyzing, and exporting Maltego graph files.52MITWhy this server?
Allows checking email addresses and domains against known data breaches and paste dumps through Have I Been Pwned.
AlicenseBqualityDmaintenanceUnified dark web and threat intelligence MCP server providing 66 tools across 16 data sources, including breach databases, ransomware tracking, Tor .onion access, blockchain intel, and malware analysis for AI agents.66338 npmMITWhy this server?
Checks whether a password or its SHA-1/NTLM hash appears in known breach dumps via Have I Been Pwned's Pwned Passwords, returning exposure count while hashing passwords locally and sending only the first five hex digits of the hash.
AlicenseAqualityCmaintenanceGives AI agents threat-intelligence verdicts for IPs, domains, URLs and hashes, CVE lookups with EPSS and CISA KEV data, and a prompt-injection gate that scans untrusted text before the agent acts on it. Agents can also batch-check up to 100 indicators, hunt brand-lookalike domains, and track scan and request quotas.1868 npmMITWhy this server?
Provides tools for checking if email addresses have been exposed in data breaches via the Have I Been Pwned API.
AlicenseNot gradedqualityCmaintenanceEnables LLMs to perform OSINT link-analysis by exposing transforms (DNS, WHOIS, Shodan, etc.) as MCP tools for autonomous investigation and graph enrichment.MITWhy this server?
Functions as a security scanner for MCP servers, auditing them against the OWASP MCP Top 10 and producing letter grades similar to Have I Been Pwned's breach notification service.
Why this server?
Provides tools for accessing Have I Been Pwned breach data classes, enabling agents to list canonical data class tags for filtering breaches.
AlicenseNot gradedqualityBmaintenanceEnables users to query Have I Been Pwned data classes and check breaches via Pipeworx MCP gateway, allowing natural language interaction.390 npmMITWhy this server?
Checks if a password has been breached using the Have I Been Pwned API with k-anonymity; the password never leaves the local machine.
AlicenseNot gradedqualityDmaintenanceA keyless, defensive code-security auditor that scans codebases for hardcoded secrets, audits dependencies for known CVEs, and checks passwords against breach data using k-anonymity.1MIT