Back to Browse

Maskbreak MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Public IP signals (cloud hosting, Tor exits) and Maskbreak API status for fraud checks.

About

Public IP signals (cloud hosting, Tor exits) and Maskbreak API status for fraud checks.

Security Report

7.2
Moderate7.2Low Risk

Well-structured MCP server with proper authentication, secure credential handling, and appropriate permissions. The code demonstrates good practices: API keys are environment-variable based (not hardcoded), HTTP requests include proper timeout/error handling, and credentials are not leaked across tool calls. Minor code quality observations (broad catch blocks, verbose error construction) do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

4 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Maskbreak API key for your plan's lookup allowance (100,000 a month on the Free plan). Without it, lookups use the rate-limited keyless endpoint. The older SENTINEL_API_KEY name is still read.Required

Environment variable: MASKBREAK_API_KEY

API base URL override, for testing.Optional

Environment variable: SENTINEL_BASE_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "com-maskbreak-mcp": {
      "env": {
        "MASKBREAK_API_KEY": "your-maskbreak-api-key-here",
        "SENTINEL_BASE_URL": "your-sentinel-base-url-here"
      },
      "args": [
        "-y",
        "@sentinelsup/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Maskbreak MCP Server

Look up limited public IP intelligence — cloud-hosting ranges and Tor exit nodes — from Claude, Cursor, or another MCP client. Powered by the Maskbreak fraud detection API. Requires Node.js 18+ for the local server.

Tools

ToolWhat it does
lookup_ipPublic IPv4/IPv6 lookup: known, allow / review / block, risk score, and nullable signal/network metadata. Public-feed coverage is limited to cloud hosting and Tor.
service_statusMaskbreak API health, uptime, and latency

Setup

Grab a free API key at maskbreak.com/signup (the Free plan includes 100,000 IP lookups a month, no card; paid plans from €29 a month raise it). Keyless mode uses the free web-tool endpoint, limited to 12 lookups/minute and 80/day per caller IP. Additional endpoint and abuse-protection limits can apply.

Neither mode performs a browser visit. VPN/proxy and device evidence require a browser-SDK-backed /v1/evaluate request outside these tools; service names are available only when known. Unknown IPs, false signals and allow verdicts are not proof of safety.

Claude Code

claude mcp add sentinel -e MASKBREAK_API_KEY=sk_live_your_key -- npx -y @sentinelsup/mcp

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "sentinel": {
      "command": "npx",
      "args": ["-y", "@sentinelsup/mcp"],
      "env": { "MASKBREAK_API_KEY": "sk_live_your_key" }
    }
  }
}

Cursor / other MCP clients

Any client that speaks stdio MCP works the same way: command npx, args ["-y", "@sentinelsup/mcp"], env MASKBREAK_API_KEY.

Hosted endpoint (no install)

Prefer a remote server? The same tools are hosted at https://maskbreak.com/mcp (Streamable HTTP). Point any URL-based MCP client at it; pass your API key as an Authorization: Bearer header for full quota.

Example

"What public-feed evidence is available for this IP?"

Illustrative unknown-IP response, not a live lookup:

{
  "ip": "192.0.2.1",
  "known": false,
  "verdict": "allow",
  "risk_score": 0,
  "signals": null,
  "network": null
}

Environment

VariableRequiredDefaultPurpose
MASKBREAK_API_KEYrecommended—API key from your dashboard; unlocks your plan's lookup allowance (100,000 a month on the Free plan). Since v0.1.5; the older SENTINEL_API_KEY name is still read
SENTINEL_BASE_URLnohttps://maskbreak.comOverride for testing

Failures and local checks

Both tools return MCP isError: true for HTTP failures, malformed responses or requests that exceed the five-second timeout (including body reads). An unavailable lookup is not an allow decision.

npm ci --ignore-scripts
npm test
npm pack --dry-run --ignore-scripts
npm audit

Tests use a real stdio MCP client with loopback HTTP fixtures, without production keys. CI checks Node.js 18, 22 and 24. No package is published by these checks.

Links

MIT © Sentinel Edge Networks LTD

Reviews

No reviews yet

Be the first to review this server!