Security intelligence API offering 55 MCP tools for vulnerability lookup, domain recon, IOC enrichment, OSINT, and code security scanning.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Contrastapi.
Security intelligence, built for AI agents. Give your agent grounded answers about vulnerabilities, threats, and attack surface β backed by authoritative sources (NVD, CISA KEV, FIRST EPSS, MITRE ATLAS & D3FEND), never guesswork. CVE/KEV/CWE lookup with EPSS exploit-probability and composite risk scoring, domain & IP investigation, IOC enrichment, code-security checks, and live web intelligence. 55 tools, 7 Resources, and 3 Prompts β free, no API key, no signup.
δΈζ Β· Live: api.contrastcyber.com
Restart your agent. Other clients (Python SDK, Node SDK, cURL, VS Code): mcp-setup Β· quickstart
Grab the .mcpb file from the latest release and double-click it (or Claude Desktop β Settings β Extensions β Install Extensionβ¦). No signup, no API key β all 55 tools ready immediately.
Both SDKs cover every HTTP endpoint and MCP tool β CVE/KEV/CWE, ATLAS, D3FEND, Sigma rules, email security posture, domain, IP, IOC, code security, and web intelligence β with wire-exact response shapes and a typed exception hierarchy that mirrors the API error envelope. They also expose MCP Resources for browsing the ATLAS, D3FEND, and CWE catalogs (see docs/MCP_Documentation.md) and a conditional triage Prompt (see docs/MCP_Documentation.md#contrast-triage). Web-intelligence tools β robots_txt, redirect_chain, email_verify, brand_assets, seo_audit, geo_audit β ship with an explicit ethical floor: per-target throttling, robots.txt respected, no SMTP probing.
OpenAPI: openapi.json
Smithery Β· npm Β· VS Code Marketplace Β· Awesome OSINT MCP Β· RapidAPI
Responses include a verdict block β deterministic, falsifiable_fields, data_age_seconds, sources_queried / sources_unavailable, completeness β so a verifier agent can independently re-derive specific fields from the upstream authority (NVD, RDAP, CT logs, URLhaus). Probe GET /v1/capabilities for "verdict_metadata": true.
CVE responses also embed next_calls: list[PivotHint] β {tool, input, reason} triples that suggest the next MCP tool to call (e.g. kev_detail when kev.in_kev=true, cwe_lookup when cwe_id is set). Agents chain workflows without manual prompting.
MIT
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/upinar-contrastapi)<a href="https://allmcps.com/mcp/upinar-contrastapi"><img src="https://allmcps.com/api/badge/upinar-contrastapi?style=directory" alt="Contrastapi on AllMCPs" /></a>