Server data from the Official MCP Registry
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
About
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
Remote endpoints: streamable-http: https://cyber-intel-mcp-production.up.railway.app/mcp
Security Report
This cybersecurity threat intelligence MCP server implements a reasonable architecture with proper authentication gating via x402 payments and API keys. However, several code quality and security concerns reduce the score: missing input validation on several endpoints, broad exception handling that masks errors, potential for unhandled null/missing data in critical paths, and inadequate logging of security-relevant events. The server appropriately handles sensitive credentials via environment variables and implements payment verification correctly, but the lack of defensive validation against malformed requests and incomplete error handling present moderate risk. Supply chain analysis found 5 known vulnerabilities in dependencies (1 critical, 3 high severity).
7 files analyzed · 15 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
Cybersecurity Threat Intelligence MCP
Cybersecurity threat intelligence for AI agents — CVE search enriched with EPSS exploit-likelihood + CISA known-exploited (KEV) status, plus live IP/domain reputation and a real-time threat feed.
Part of the FoundryNet Data Network. Every result carries verifiable provenance so a buyer can confirm it was produced by this server, unaltered. See also: gov-contracts-mcp, brand-intel-mcp, patent-intel-mcp, financial-signals-mcp, weather-intel-mcp, compliance-mcp.
Connect
- MCP endpoint (Streamable HTTP):
https://cyber-intel-mcp-production.up.railway.app/mcp - Registry:
io.github.FoundryNet/cyber-intel-mcp - Agent card:
https://cyber-intel-mcp-production.up.railway.app/.well-known/agent-card.json
Claude Desktop / Cursor / Claude Code
claude mcp add --transport http cyber-intel https://cyber-intel-mcp-production.up.railway.app/mcp
{ "mcpServers": { "cyber-intel": { "url": "https://cyber-intel-mcp-production.up.railway.app/mcp" } } }
Tools
| Tool | Price | What it does |
|---|---|---|
search_cve | $0.01 | CVE search by severity, CVSS, EPSS, attack vector, KEV status |
cve_detail | free | Full CVE — CVSS breakdown, EPSS, KEV, CWE, affected products, refs |
check_ip | $0.01 | IP reputation (AbuseIPDB + OTX) — abuse score, threat type, pulses |
check_domain | $0.01 | Domain threat indicators (OTX) |
vulnerability_scan | $0.05 | All CVEs for a product, sorted by EPSS — "should I worry about this dependency?" |
threat_feed | $0.01 | Recent threat indicators (IPs/domains/hashes/URLs) |
brief_summary | $0.50 | Sample of the day's curated threat brief (headline findings) |
daily_brief | $15 | Full curated daily threat brief — top exploited CVEs, KEV adds, active indicators |
mint_info | free | FoundryNet Data Network + provenance/attestation info |
Free tier: 25 paid-tool queries/day per agent. Then metered: the tool returns an
HTTP-402 with a payment request — settle it, re-call with the same args plus
payment_tx=<reference>. An Authorization: Bearer fnet_… key bypasses the paywall.
The edge: EPSS-ranked vulnerabilities
Raw CVE counts are noise. Every vulnerability here carries its EPSS score (the
probability it'll be exploited) and a CISA KEV flag (whether it's actively
exploited). vulnerability_scan sorts a product's CVEs by exploit likelihood — so
an agent triaging a dependency sees what actually matters first.
Sources
Every 6 hours: NVD (CVEs, keyless + throttled), EPSS (exploit probability), CISA KEV (known-exploited catalog), GitHub Advisories. Live on demand: AbuseIPDB (IP reputation) + AlienVault OTX (IP/domain/pulse indicators). Stored in a standalone Supabase project.
Discovery
MCP registry: io.github.FoundryNet/cyber-intel-mcp
Built by FoundryNet · forge@foundrynet.io
Live network activity
Live feed: mint.foundrynet.io/feed
Real-time verified work across 17 servers and autonomous agents, with verifiable provenance on every result.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
