Skip to main content
Glama
threadlinqs-cmd

Intel Threadlinqs MCP

Enrich IOCs (live)

enrich_iocs
Read-onlyIdempotent

Cross-reference IOCs with ThreatFox, MalwareBazaar, AbuseIPDB, and DNS data to return enrichment metadata and threat intelligence matches.

Instructions

Get enrichment metadata for IOCs — cross-references with ThreatFox, MalwareBazaar, AbuseIPDB/IPsum, and DNS data. Returns enrichment status and any matching threat intelligence from external feeds.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
typeNoIOC type filter (default: all)
limitNoMax results (default 20)
queryYesIOC value or search query to enrich
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already provide readOnlyHint, idempotentHint, and destructiveHint; description adds specific data sources and output explanation, with no contradictions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded, no wasted words; efficient and clear.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Covers purpose, inputs, outputs, and data sources; lacks pagination or error details but adequate for a read-only query tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and fully documents parameters; description repeats general purpose but adds no parameter-specific meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states verb 'Get enrichment metadata' and specifies cross-references with multiple external feeds, distinguishing it from siblings like search_iocs and get_ioc_dns.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No explicit guidance on when to use this vs. alternatives; agent must infer from context of external enrichment.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/threadlinqs-cmd/intelthreadlinqs-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server