Back to Browse

Relayshield MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Breach, SIM swap, infostealer, domain lookalikes, MCP registry risk, prompt-injection detection.

About

Breach, SIM swap, infostealer, domain lookalikes, MCP registry risk, prompt-injection detection.

Security Report

5.2
Moderate5.2Moderate Risk

RelayShield MCP is a well-structured security intelligence server with proper authentication mechanisms, clear permission boundaries, and no malicious patterns. The codebase demonstrates good security practices including proper error handling, input validation via JSON schemas, and appropriate use of environment variables for credential storage. Minor code quality observations around exception handling breadth do not materially impact security. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

4 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

RelayShield API base URL — https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prodOptional

Environment variable: RELAYSHIELD_API_URL

RelayShield API key for subscription access (all tools available) — get one at api.relayshield.net/developersRequired

Environment variable: RELAYSHIELD_API_KEY

x402 payment proof — USDC on Base (pay-as-you-go mode, no API key needed)Required

Environment variable: RELAYSHIELD_X_PAYMENT

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-nzdsf2-gif-relayshield-mcp": {
      "env": {
        "RELAYSHIELD_API_KEY": "your-relayshield-api-key-here",
        "RELAYSHIELD_API_URL": "your-relayshield-api-url-here",
        "RELAYSHIELD_X_PAYMENT": "your-relayshield-x-payment-here"
      },
      "args": [
        "relayshield-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

relayshield-mcp

mcp-name: io.github.nzdsf2-gif/relayshield-mcp

RelayShield security intelligence as an MCP server — plug breach detection, SIM swap detection, domain lookalike monitoring, OAuth supply chain watchlist, and URL/file scanning directly into Claude and any MCP-compatible AI agent.

Tools

ToolWhat it doesPAYG price
check_breachEmail breach lookup — 13 billion+ records via HIBP$0.10 USDC
check_sim_swapSIM swap / eSIM detection via live carrier data$0.25 USDC
check_domain_lookalikesTyposquat and lookalike domain detection with cert transparency$0.50 USDC
check_oauth_watchlistOAuth-app breach + stolen-token exposure via HIBP + stealer-log corpus$0.30 USDC
check_infostealerInfostealer malware log lookup via Hudson Rock Cavalier$0.15 USDC
scan_walletEVM wallet on-chain risk check via GoPlus Security$0.10 USDC
scan_urlURL malware/phishing scan across 70+ engines (async)$0.05 USDC
scan_fileBinary malware scan across 70+ AV engines (async)$0.10 USDC
check_scan_resultPoll for verdict after scan_url / scan_filefree
check_mcp_registry_riskTyposquat/IOC/registration-age check for MCP servers$0.35 USDC
check_prompt_injection_breachBreach exposure sourced from AI-agent prompt-injection attacks$0.35 USDC
check_supply_chainUp to 10 vendor domains checked for breach/infostealer exposure$0.10 USDC
check_session_riskActive/reusable stolen session (cookie/token) exposure check$0.30 USDC
check_nhi_exposureNon-human-identity credential exposure — API keys, service tokens, PATs$0.40 USDC
check_secret_scanSecrets exposed in public GitHub repositories$0.35 USDC

check_oauth_watchlist, check_supply_chain, check_session_risk, check_nhi_exposure, and check_secret_scan cover related ground — connected-app, session, and machine-credential exposure for an identity or its supply chain — and are a natural set to use together when vetting an agent's current authority, not just a login.

Access modes

Subscription — API key from api.relayshield.net/developers. All 15 tools available. Free tier: 100 calls/month. Paid tiers from $29/month.

Pay-as-you-go — No API key needed. Pay per check in USDC on Base (x402 protocol). Set RELAYSHIELD_X_PAYMENT with your payment proof. All 15 tools available ($0.05–$0.50/check, check_scan_result free). Call a tool with no payment set to receive pricing and payment instructions.

Discovery — Set neither key nor payment. Tool calls return payment requirements and a subscription link.

Install

pip install relayshield-mcp

Or run without installing:

uvx relayshield-mcp

Configure Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

Subscription (RelayShield API key):

{
  "mcpServers": {
    "relayshield": {
      "command": "relayshield-mcp",
      "env": {
        "RELAYSHIELD_API_URL": "https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod",
        "RELAYSHIELD_API_KEY": "your-relayshield-api-key-here"
      }
    }
  }
}

Pay-as-you-go (x402 USDC on Base):

{
  "mcpServers": {
    "relayshield": {
      "command": "relayshield-mcp",
      "env": {
        "RELAYSHIELD_API_URL": "https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod",
        "RELAYSHIELD_X_PAYMENT": "your-x402-payment-proof-here"
      }
    }
  }
}

Quit and relaunch Claude Desktop after editing.

Configure Claude Code (CLI)

claude mcp add relayshield \
  --command relayshield-mcp \
  --env RELAYSHIELD_API_URL=https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod \
  --env RELAYSHIELD_API_KEY=your-relayshield-api-key-here

Usage examples

Once configured, ask Claude:

Check whether user@example.com has been breached.
Has there been a SIM swap on +14155551234?
Check acme.com for lookalike domains.
Are any OAuth apps connected to user@example.com in a recent breach?
Scan this URL for malware: https://suspicious-link.example.com

For URL and file scans, Claude automatically polls check_scan_result every 5 seconds until the verdict is ready.

Environment variables

VariableDescription
RELAYSHIELD_API_URLAPI Gateway base URL (required)
RELAYSHIELD_API_KEYRelayShield subscription key (subscription mode) — get one at api.relayshield.net/developers
RELAYSHIELD_X_PAYMENTx402 payment proof — USDC on Base (pay-as-you-go mode)

Set RELAYSHIELD_API_KEY or RELAYSHIELD_X_PAYMENT — not both. API key takes priority if both are set.

Links

Reviews

No reviews yet

Be the first to review this server!