CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Inspect callable tools, capabilities, and parameters exposed to AI agents by Cybersecurity Threat Intelligence MCP.
search_cveCVE search by severity, CVSS, **EPSS**, attack vector, KEV status
cve_detailFull CVE β CVSS breakdown, EPSS, KEV, CWE, affected products, refs
check_ipIP reputation (AbuseIPDB + OTX) β abuse score, threat type, pulses
check_domainDomain threat indicators (OTX)
vulnerability_scanAll CVEs for a product, **sorted by EPSS** β "should I worry about this dependency?"
threat_feedRecent threat indicators (IPs/domains/hashes/URLs)
Cybersecurity threat intelligence for AI agents β CVE search enriched with EPSS exploit-likelihood + CISA known-exploited (KEV) status, plus live IP/domain reputation and a real-time threat feed.
Part of the FoundryNet Data Network. Every result carries verifiable provenance so a buyer can confirm it was produced by this server, unaltered. See also: gov-contracts-mcp, brand-intel-mcp, patent-intel-mcp, financial-signals-mcp, weather-intel-mcp, compliance-mcp.
https://cyber-intel-mcp-production.up.railway.app/mcpio.github.FoundryNet/cyber-intel-mcphttps://cyber-intel-mcp-production.up.railway.app/.well-known/agent-card.json| Tool | Price | What it does |
|---|---|---|
search_cve | $0.01 | CVE search by severity, CVSS, EPSS, attack vector, KEV status |
cve_detail | free | Full CVE β CVSS breakdown, EPSS, KEV, CWE, affected products, refs |
check_ip | $0.01 | IP reputation (AbuseIPDB + OTX) β abuse score, threat type, pulses |
check_domain | $0.01 | Domain threat indicators (OTX) |
vulnerability_scan | $0.05 | All CVEs for a product, sorted by EPSS β "should I worry about this dependency?" |
threat_feed | $0.01 | Recent threat indicators (IPs/domains/hashes/URLs) |
brief_summary | $0.50 | Sample of the day's curated threat brief (headline findings) |
daily_brief | $15 | Full curated daily threat brief β top exploited CVEs, KEV adds, active indicators |
mint_info | free | FoundryNet Data Network + provenance/attestation info |
Free tier: 25 paid-tool queries/day per agent. Then metered: the tool returns an
HTTP-402 with a payment request β settle it, re-call with the same args plus
payment_tx=<reference>. An Authorization: Bearer fnet_β¦ key bypasses the paywall.
Raw CVE counts are noise. Every vulnerability here carries its EPSS score (the
probability it'll be exploited) and a CISA KEV flag (whether it's actively
exploited). vulnerability_scan sorts a product's CVEs by exploit likelihood β so
an agent triaging a dependency sees what actually matters first.
Every 6 hours: NVD (CVEs, keyless + throttled), EPSS (exploit probability), CISA KEV (known-exploited catalog), GitHub Advisories. Live on demand: AbuseIPDB (IP reputation) + AlienVault OTX (IP/domain/pulse indicators). Stored in a standalone Supabase project.
MCP registry: io.github.FoundryNet/cyber-intel-mcp
Built by FoundryNet Β· forge@foundrynet.io
Live feed: mint.foundrynet.io/feed
Real-time verified work across 17 servers and autonomous agents, with verifiable provenance on every result.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/cybersecurity-threat-intelligence-mcp)<a href="https://allmcps.com/mcp/cybersecurity-threat-intelligence-mcp"><img src="https://allmcps.com/api/badge/cybersecurity-threat-intelligence-mcp?style=directory" alt="Cybersecurity Threat Intelligence MCP on AllMCPs" /></a>