Skip to main content
Glama
xiaobenyang-com

IP-Search

IP情报查询工具 IP Search

依托全球蜜罐网络及百万级节点构建的IP情报分析平台,提供精准的IP画像与威胁预警服务。 Relying on a global honeypot network and an IP intelligence analysis platform built with millions of nodes, it provides precise IP profiling and threat early warning services.## 工具列表 Tool List

本MCP服务封装下列工具,可让模型通过标准化接口调用以下功能。 本MCP服务封装下列工具,可让模型通过标准化接口调用以下功能。

工具 Tool

描述 Description

长亭 IP 情报查询

基于长亭威胁情报,获取给定 IP 的威胁情报信息,包括 IP 地址、地理位置、ASN、历史恶意行为等信息

检查服务 ## Inspector

工具在线测试: https://mcp.xiaobenyang.com/inspector/1777316659365891

Online Tool test https://mcp.xiaobenyang.com/inspector/1777316659365891

Related MCP server: Chaitin IP Intelligence Search Tool

服务配置 MCP Server Config

如何获取 XBY-APIKEY ? How to get XBY-APIKEY ?

访问小笨羊科技网站 https://xiaobenyang.com,注册用户即可获得APIKEY Visit XiaoBenYang website https://xiaobenyang.com, register and get the APIKEY.

SSE

{
  "mcpServers": {
    "IP情报查询工具": {
      "headers": {
        "XBY-APIKEY": "<YOUR_XBY_APIKEY>"
      },
      "type": "sse",
      "url": "https://mcp.xiaobenyang.com/1777316659365891/sse"
    }
  }
}

STREAMABLE HTTP

{
  "mcpServers": {
    "IP情报查询工具": {
      "headers": {
        "XBY-APIKEY": "<YOUR_XBY_APIKEY>"
      },
      "type": "streamable_http",
      "url": "https://mcp.xiaobenyang.com/1777316659365891/mcp"
    }
  }
}

STDIO

{
    "mcpServers": {
        "IP情报查询工具": {
          "command": "npx",
          "args": [
            "-y",
            "xiaobenyang-mcp"
          ],
          "env": {
            "XBY_APIKEY": "<YOUR_XBY_APIKEY>",
            "mcpId": "1777316659365891",
          },
          "transport": "stdio"
        }
      }
}

Available Tools

1 tool
长亭 IP 情报查询长亭 IP 情报查询B

基于长亭威胁情报,获取给定 IP 的威胁情报信息,包括 IP 地址、地理位置、ASN、历史恶意行为等信息

ParametersJSON Schema
NameRequiredDescriptionDefault
ipYes

TDQS

B3.1/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It states what information is returned (IP address, geographic location, ASN, historical malicious behavior) but doesn't describe other important behavioral traits: whether this is a read-only operation, rate limits, authentication requirements, error conditions, or response format. For a tool with zero annotation coverage, this leaves significant gaps in understanding how the tool behaves.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, efficient sentence that clearly states the tool's purpose and what information it returns. It's appropriately front-loaded with the core functionality. While very concise, it could potentially benefit from slightly more detail given the complete lack of annotations and output schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of threat intelligence queries and the complete lack of annotations (0% coverage) and no output schema, the description is insufficiently complete. It mentions what information is returned but doesn't describe the response structure, error handling, rate limits, or authentication requirements. For a tool that presumably queries external threat intelligence data, more context about behavioral expectations is needed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 1 parameter with 0% description coverage (no schema descriptions). The tool description doesn't mention the 'ip' parameter at all, providing no additional semantic information beyond what's in the bare schema. However, with only one simple parameter, the baseline is appropriately 3 - the description doesn't add value but the simplicity of the schema means this isn't critically problematic.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: '获取给定 IP 的威胁情报信息' (get threat intelligence information for a given IP). It specifies the verb ('获取' - get/retrieve) and resource ('IP 的威胁情报信息' - IP threat intelligence information). However, since there are no sibling tools mentioned, it cannot demonstrate differentiation from alternatives, preventing a perfect score of 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage context by stating '基于长亭威胁情报' (based on Changting threat intelligence), suggesting this tool is specifically for querying that intelligence source. However, it provides no explicit guidance on when to use this tool versus alternatives (e.g., other IP lookup services), nor does it mention any prerequisites or exclusions. The guidance is implied rather than explicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

B3.2/5.0
Disambiguation5/5

With only one tool, there is no possibility of confusion or overlap between tools. The tool has a single, clear purpose focused on IP threat intelligence queries.

Naming Consistency5/5

A single tool inherently has perfect naming consistency, as there are no other tools to compare against. The name '长亭 IP 情报查询' is descriptive and stands alone without conflicting patterns.

Tool Count2/5

One tool is too few for a server named 'IP-Search', which suggests broader IP-related functionality. A single query tool feels thin and limits the server's utility, lacking operations like batch queries, historical data access, or IP range analysis.

Completeness2/5

The tool surface is severely incomplete for an IP search domain. It only provides threat intelligence for a single IP, missing essential operations such as searching by domain, reverse DNS lookups, IP reputation scoring, or network analysis tools, which are typical for such services.

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI-powered threat intelligence analysis of IPs, domains, URLs, and file hashes across multiple threat intelligence platforms (VirusTotal, AlienVault OTX, AbuseIPDB, IPinfo) with APT attribution and interactive reporting through natural language queries.
    40
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    Enables checking IP reputations and threat intelligence by querying Chaitin's global honeypot network and millions of defense nodes. Provides real-time IP profiling, malicious behavior detection, and threat alerts based on aggregated security data.
    1
    26
    2
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables comprehensive threat analysis for Indicators of Compromise (IoCs) including IP addresses, file hashes, domains, and URLs. It provides detailed reputation scores, security vendor evaluations, and network metadata to facilitate security assessments and risk detection.
    4
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Honeypot threat intelligence for AI agents. Query 90 days of probe data from our sensor network: IP reputation, scanner classification, CVE probing trends, TLS/SSH/JA4 fingerprints. Free tier 500 credits/day, OAuth + bearer auth, streamable HTTP at https://mcp.honeylabs.net/mcp.
    7
    2
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/xiaobenyang-com/1777316659365891'

If you have feedback or need assistance with the MCP directory API, please join our Discord server