mcp-greynoise
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_ipA | Check if an IP address is internet background noise or potentially targeted activity. GreyNoise tracks IPs that mass-scan the internet. If an IP is 'noise', traffic from it is likely untargeted scanning. If it's NOT noise, traffic may be targeted at you specifically. RIOT dataset contains known-good IPs (CDNs, DNS servers, etc.). |
| check_ipsA | Check multiple IP addresses against GreyNoise in one call. Useful for triaging a list of suspicious IPs from logs or alerts. Rate limits apply (50/day for free tier). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| GreyNoise API Status | Information about the GreyNoise Community API and rate limits |
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one checks a single IP address, the other checks multiple IPs in bulk. An agent can easily distinguish between them based on the singular/plural naming and the explicit descriptions.
Both tools follow the consistent pattern of 'check_' followed by a noun indicating the input type ('ip' vs 'ips'). The naming is predictable and uses consistent snake_case throughout.
With only two tools, the server feels minimal for its domain. While both tools are necessary and well-scoped, a more comprehensive IP intelligence server would typically benefit from additional tools (e.g., contextual enrichment, history). The count is borderline thin.
The tool set covers the basic use case of checking IPs against GreyNoise data, both individually and in bulk. However, it lacks other common operations like fetching detailed threat context, searching by tags or queries, or retrieving known-good RIOT entries specifically. Notable gaps exist for a more complete threat intelligence surface.