Best Have I Been Pwned MCP Servers
Have I Been Pwned is a free online service that allows users to check if their personal data has been compromised in data breaches. It was created by Troy Hunt, a security researcher, to help people discover if their email addresses or passwords have been exposed in known data breaches.
Why this server?
Enables checking email addresses for known data breaches as part of Maltego investigations.
AlicenseAqualityBmaintenanceTurns an LLM into a Maltego CE investigation copilot, enabling AI-assisted OSINT investigations by building, analyzing, and exporting Maltego graph files.52MITWhy this server?
Allows checking email addresses and domains against known data breaches and paste dumps through Have I Been Pwned.
AlicenseBqualityBmaintenanceUnified dark web and threat intelligence MCP server providing 66 tools across 16 data sources, including breach databases, ransomware tracking, Tor .onion access, blockchain intel, and malware analysis for AI agents.6643MITWhy this server?
Provides tools to check if email addresses have been found in data breaches, verify if passwords have been exposed, get detailed information about specific data breaches, and list all breaches in the system with optional domain filtering.
AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server that provides integration with the Have I Been Pwned API to check if your accounts or passwords have been compromised in data breaches.42MITWhy this server?
Allows AI agents to search for breached accounts, credentials, and pastes using the Have I Been Pwned API.
AlicenseAqualityAmaintenanceDark web & threat intelligence for AI agents. HIBP, ThreatFox, ransomware tracking, Tor .onion access, blockchain intel, exploit search, stealer logs, malware analysis — unified into a single MCP server.6643306MITWhy this server?
Provides tools for checking if email addresses have been exposed in data breaches via the Have I Been Pwned API.
AlicenseNot gradedqualityBmaintenanceEnables LLMs to perform OSINT link-analysis by exposing transforms (DNS, WHOIS, Shodan, etc.) as MCP tools for autonomous investigation and graph enrichment.MITWhy this server?
Checks if a password has been breached using the Have I Been Pwned API with k-anonymity; the password never leaves the local machine.
AlicenseNot gradedqualityBmaintenanceA keyless, defensive code-security auditor that scans codebases for hardcoded secrets, audits dependencies for known CVEs, and checks passwords against breach data using k-anonymity.1MITWhy this server?
Functions as a security scanner for MCP servers, auditing them against the OWASP MCP Top 10 and producing letter grades similar to Have I Been Pwned's breach notification service.
Why this server?
Used for checking if a password has been exposed in data breaches via the Pwned Passwords k-anonymity API in the password_check tool.
AlicenseNot gradedqualityBmaintenanceA Cloudflare Workers MCP server that puts a SOC analyst's enrichment, investigation, and detection-context workflow behind a single endpoint. It aggregates over 20 threat-intel sources into 18 MCP tools for IP, domain, URL, hash, and CVE lookups.MITWhy this server?
Provides tools for accessing Have I Been Pwned breach data classes, enabling agents to list canonical data class tags for filtering breaches.
AlicenseNot gradedqualityCmaintenanceEnables users to query Have I Been Pwned data classes and check breaches via Pipeworx MCP gateway, allowing natural language interaction.10MIT