Real-time threat intel for AI agents: 890K+ IOCs incl. prompt-injection & AI-skill threats
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Real-time threat intelligence for AI agents, exposed as a Model Context Protocol server. Check IPs, domains, URLs, hashes, CVEs, prompt-injection payloads, and malicious AI-skill / MCP-tool definitions against the Nullcone network β 890K+ IOCs, free, no API key.
Backed by nullcone.ai.
The server is hosted at https://nullcone.ai/mcp over streamable HTTP. Add it to any MCP client:
Claude Code
Cursor / other MCP clients β add to your MCP config:
No signup or token required. Read tools and IOC submission are open; destructive tools (e.g. revoke_ioc) are disabled on the public endpoint.
30+ tools including:
lookup_ioc(value) β check any indicator against the feedrecent_threats(limit, min_severity) β current threat picturesubmit_ioc(...) / submit_batch(...) β contribute indicatorscheck_prompt(...) β sub-millisecond prompt-injection lookupvalidate_skill(...) / scan_skill_content(...) β vet MCP tools / AI skills before loadingpoll_since(last_id) β incremental sync, no persistent connectionget_stats(), list_families(), search_by_type(...), and moreResources: threat://stats, threat://recent, threat://families, threat://family/{name}, threat://ioc/{value}.
Prompts: analyze_ioc, triage_alert, threat_brief.
The server is built on the public nullcone SDK.
Or with Docker:
Set MCP_PUBLIC=1 to run an anonymous public endpoint (disables destructive tools); omit it for full local control over stdio (MCP_TRANSPORT=stdio).
Rising Sun License v1.0 β see LICENSE. Free for individuals and small teams.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/nullcone-threat-intelligence)<a href="https://allmcps.com/mcp/nullcone-threat-intelligence"><img src="https://allmcps.com/api/badge/nullcone-threat-intelligence?style=directory" alt="Nullcone Threat Intelligence on AllMCPs" /></a>