Back to Browse

Cyber Intel MCP Server

Developer ToolsUse Caution3.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.

About

CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.

Remote endpoints: streamable-http: https://cyber-intel-mcp-production.up.railway.app/mcp

Security Report

3.8
Use Caution3.8High Risk

This cybersecurity threat intelligence MCP server implements a reasonable architecture with proper authentication gating via x402 payments and API keys. However, several code quality and security concerns reduce the score: missing input validation on several endpoints, broad exception handling that masks errors, potential for unhandled null/missing data in critical paths, and inadequate logging of security-relevant events. The server appropriately handles sensitive credentials via environment variables and implements payment verification correctly, but the lack of defensive validation against malformed requests and incomplete error handling present moderate risk. Supply chain analysis found 5 known vulnerabilities in dependencies (1 critical, 3 high severity).

7 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Cybersecurity Threat Intelligence MCP

Cybersecurity threat intelligence for AI agents — CVE search enriched with EPSS exploit-likelihood + CISA known-exploited (KEV) status, plus live IP/domain reputation and a real-time threat feed.

Part of the FoundryNet Data Network. Every result carries verifiable provenance so a buyer can confirm it was produced by this server, unaltered. See also: gov-contracts-mcp, brand-intel-mcp, patent-intel-mcp, financial-signals-mcp, weather-intel-mcp, compliance-mcp.

Connect

  • MCP endpoint (Streamable HTTP): https://cyber-intel-mcp-production.up.railway.app/mcp
  • Registry: io.github.FoundryNet/cyber-intel-mcp
  • Agent card: https://cyber-intel-mcp-production.up.railway.app/.well-known/agent-card.json

Claude Desktop / Cursor / Claude Code

claude mcp add --transport http cyber-intel https://cyber-intel-mcp-production.up.railway.app/mcp
{ "mcpServers": { "cyber-intel": { "url": "https://cyber-intel-mcp-production.up.railway.app/mcp" } } }

Tools

ToolPriceWhat it does
search_cve$0.01CVE search by severity, CVSS, EPSS, attack vector, KEV status
cve_detailfreeFull CVE — CVSS breakdown, EPSS, KEV, CWE, affected products, refs
check_ip$0.01IP reputation (AbuseIPDB + OTX) — abuse score, threat type, pulses
check_domain$0.01Domain threat indicators (OTX)
vulnerability_scan$0.05All CVEs for a product, sorted by EPSS — "should I worry about this dependency?"
threat_feed$0.01Recent threat indicators (IPs/domains/hashes/URLs)
brief_summary$0.50Sample of the day's curated threat brief (headline findings)
daily_brief$15Full curated daily threat brief — top exploited CVEs, KEV adds, active indicators
mint_infofreeFoundryNet Data Network + provenance/attestation info

Free tier: 25 paid-tool queries/day per agent. Then metered: the tool returns an HTTP-402 with a payment request — settle it, re-call with the same args plus payment_tx=<reference>. An Authorization: Bearer fnet_… key bypasses the paywall.

The edge: EPSS-ranked vulnerabilities

Raw CVE counts are noise. Every vulnerability here carries its EPSS score (the probability it'll be exploited) and a CISA KEV flag (whether it's actively exploited). vulnerability_scan sorts a product's CVEs by exploit likelihood — so an agent triaging a dependency sees what actually matters first.

Sources

Every 6 hours: NVD (CVEs, keyless + throttled), EPSS (exploit probability), CISA KEV (known-exploited catalog), GitHub Advisories. Live on demand: AbuseIPDB (IP reputation) + AlienVault OTX (IP/domain/pulse indicators). Stored in a standalone Supabase project.

Discovery

MCP registry: io.github.FoundryNet/cyber-intel-mcp

Built by FoundryNet · forge@foundrynet.io

Live network activity

Live feed: mint.foundrynet.io/feed
Real-time verified work across 17 servers and autonomous agents, with verifiable provenance on every result.

Reviews

No reviews yet

Be the first to review this server!

Cyber Intel MCP Server - CVE search, vulnerability database, EPSS exploit | MCP Marketplace