darknet-mcp-server
Related Servers
Alternatives to darknet-mcp-server
No user-submitted related servers found.
Related Servers
- AlicenseAqualityDmaintenanceDark web & threat intelligence for AI agents. HIBP, ThreatFox, ransomware tracking, Tor .onion access, blockchain intel, exploit search, stealer logs, malware analysis — unified into a single MCP server.66186 npm442MIT
- FlicenseNot gradedqualityDmaintenanceDarknet threat intelligence MCP server with 10 tools powered by 12,000+ vectorized data points from IronClaw pipeline.-
- AlicenseNot gradedqualityAmaintenanceAn MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.1MIT
- AlicenseCqualityDmaintenanceMCP server for the OSINT Intelligence Platform, enabling AI assistants to interact with Telegram intelligence archives via 65 tools for search, entity analysis, event tracking, social graph, and platform monitoring.712MIT
- AlicenseAqualityBmaintenanceMCP server for offensive-security tooling, enabling AI agents to run reconnaissance, CVE intelligence, JavaScript analysis, HTTP probing, and port scanning against authorized targets.10MIT
- AlicenseBqualityBmaintenanceEnables AI agents to perform general-purpose open-source intelligence lookups across domains, infrastructure, identity, social media, and threat/breach sources through a unified MCP interface, with most tools free and no API keys required.32MIT
TDQS
Scored across 66 tools
Most tools are clearly scoped by service and operation, such as breachGet vs breachSearch or otx_ip vs otx_domain. However, a few pairs like greynoise_ip vs greynoise_check and tor_fetch_onion vs tor_scrape_onion are similar enough to potentially confuse an agent.
Naming is inconsistent: some tools use camelCase (breachPassword, ransomwareRecent) while others use snake_case (tor_status, otx_ip). Verb placement also varies (breachGet vs tor_fetch_onion), making it harder to predict tool names.
With 66 tools, this server far exceeds the typical well-scoped limit. The broad scope of threat-intel sources explains the count, but it is overwhelming and includes many overlapping services, pushing the count to an extreme.
The server covers a wide range of darknet and threat-intel domains: breaches, Tor, ransomware, malware, IP reputation, vulnerabilities, Bitcoin, and dark web search. Most workflows have paired operations (initiate/get results), though a few sources like RansomLook lack detailed lookup endpoints.