Servidor MCP

PG1 Sovereign Threat Intelligence

io.github.Project-Gifted1/pg1-threat-intel
Seguridad Público y accesible MCP 2026-07-28

Qué hace este MCP

Provides threat-intelligence lookups for indicators, CVEs, threat actors, STIX feeds, EPSS and CISA KEV enrichment, indicator submissions, and alert subscriptions.

check_domain_age
PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap registry for the correct per-TLD RDAP server. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for domain registration/age checks only. Do NOT use for reputation/threat-feed lookups (use get_ioc_context) or sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { found: true, available: true, registration_date, age_days, expiration_date, registrar, newly_registered, source } when available, or { found: false, available: false, reason, reason_code } when the lookup does not resolve — this tool never estimates or guesses an age. "available" is a deprecated alias of "found", kept for backward compatibility. reason_code is "unsupported_tld" when the TLD has no RDAP server in the IANA bootstrap registry, or "timeout" / "lookup_failed" for other lookup failures. A newly registered domain (age_days < 30) is reported as a common phishing signal, not as proof of malicious intent.
Esquema de entrada
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': "Mandatory domain name or URL to check, e.g. 'example.com' or 'https://example.com/path'. The registrable domain is extracted automatically."}}}
Esquema de salida
{'type': 'object', 'required': ['found', 'available', 'domain'], 'properties': {'note': {'type': ['string', 'null']}, 'found': {'type': 'boolean', 'description': 'Whether a registration record was found. Same meaning as the deprecated "available" field.'}, 'domain': {'type': 'string'}, 'reason': {'type': ['string', 'null']}, 'source': {'type': ['string', 'null']}, 'age_days': {'type': ['integer', 'null']}, 'available': {'type': 'boolean', 'description': 'Deprecated — use "found" instead. Kept for backward compatibility.'}, 'registrar': {'type': ['string', 'null']}, 'reason_code': {'enum': ['invalid_domain', 'bootstrap_unavailable', 'unsupported_tld', 'timeout', 'lookup_failed', None], 'type': ['string', 'null']}, 'expiration_date': {'type': ['string', 'null']}, 'newly_registered': {'type': ['boolean', 'null']}, 'registration_date': {'type': ['string', 'null']}}}
check_hostname_reputation
PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, synced daily by the sovereign-threat-pipeline. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for phishing/lookalike-domain screening of a hostname only. Do NOT use for domain registration age (use check_domain_age), general threat-feed indicator lookups (use get_ioc_context), or wallet sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { hostname, verdict, sources, lookalike_of, list_synced_at, checked_at, attribution }. verdict is one of "allowlisted", "listed", "lookalike", or "not_listed" — this tool never returns "safe" or "clean", and a not_listed result means the hostname is not on the eth-phishing-detect lists, not that it is safe. "listed" results include match_type "exact" or "parent_domain" in sources. "lookalike" flags a probable typosquat/homoglyph of a known brand — via confusable-character skeleton matching within the stored tolerance, or a brand keyword embedded with extra words (e.g. metamask-login.com) — even when the hostname itself is not directly listed, and sets lookalike_of to the matched brand domain. A brand's own real domain or a subdomain of it is never flagged as its own lookalike. VALIDATION: accepts exactly one bare hostname per call (no bulk input); a value containing a URL scheme, path, port, spaces, or a wildcard returns an MCP tool error (isError: true, code invalid_hostname) instead of a verdict. Fails loudly (returns an error) if the phishing list data is unreachable or times out, rather than ever reporting not_listed on a data failure. Rate-limited to 60 calls/hour per caller when unauthenticated; a valid Gumroad license key (X-API-KEY header) exempts the limit, same as check_domain_age. List contents are never exposed beyond the single matched entry.
Esquema de entrada
{'type': 'object', 'required': ['hostname'], 'properties': {'hostname': {'type': 'string', 'description': "Mandatory bare hostname to screen, e.g. 'example.com'. Not a URL — no scheme, path, port, spaces, or wildcards. One hostname per call."}}}
Esquema de salida
{'type': 'object', 'required': ['hostname', 'verdict', 'sources', 'lookalike_of', 'list_synced_at', 'checked_at', 'attribution'], 'properties': {'sources': {'type': 'array', 'items': {'type': 'object', 'properties': {'url': {'type': ['string', 'null']}, 'name': {'type': 'string'}, 'match_type': {'enum': ['allowlist', 'exact', 'parent_domain', 'confusable', 'keyword'], 'type': 'string'}}}}, 'verdict': {'enum': ['allowlisted', 'listed', 'lookalike', 'not_listed'], 'type': 'string', 'description': 'Never "safe" or "clean".'}, 'hostname': {'type': 'string', 'description': 'The hostname after normalization (trimmed, lowercased, trailing dot stripped, IDN converted to punycode).'}, 'checked_at': {'type': 'string'}, 'attribution': {'type': 'string'}, 'lookalike_of': {'type': ['string', 'null'], 'description': 'The matched brand/fuzzylist domain for a "lookalike" verdict, otherwise null.'}, 'list_synced_at': {'type': ['string', 'null']}}}
check_wallet_sanctions
PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet/address sanctions screening only. Do NOT use for IP/domain/hash/URL threat lookups (use get_ioc_context) or CVE data (use get_cve_details). BEHAVIOR: Returns { listed: true|false, matches, source, list_last_synced }. A listed:false result means the address is not on the OFAC SDN list as of the reported sync time — it is informational only, not legal or sanctions-compliance advice, and is never phrased as "safe" or "clean". Fails loudly (returns an error) if the sanctions data is empty or unreachable, rather than ever reporting listed:false on a data failure. VALIDATION: if the address does not match a recognised format for any supported currency (EVM, BTC/LTC/BCH/DOGE/DASH/ZEC base58 or bech32/cashaddr, TRON, Monero, Solana), returns an MCP tool error (isError: true, code invalid_address) instead of a result — it never reports listed:false for malformed input.
Esquema de entrada
{'type': 'object', 'required': ['address'], 'properties': {'address': {'type': 'string', 'description': 'Mandatory wallet address to screen, e.g. an EVM 0x address, a bech32 (bc1/tb1/ltc1...) address, or a base58 address.'}, 'currency': {'type': ['string', 'null'], 'description': "Optional currency/chain filter to narrow the match, e.g. 'BTC', 'ETH', 'XMR'."}}}
Esquema de salida
{'type': 'object', 'required': ['address', 'address_normalized', 'listed', 'matches', 'source', 'list_last_synced'], 'properties': {'listed': {'type': 'boolean'}, 'source': {'type': 'string'}, 'address': {'type': 'string', 'description': 'The address exactly as submitted.'}, 'matches': {'type': 'array', 'items': {'type': 'object', 'properties': {'sdn_uid': {'type': ['string', 'number', 'null']}, 'currency': {'type': ['string', 'null']}, 'programs': {'type': 'array', 'items': {'type': 'string'}}, 'sdn_name': {'type': ['string', 'null']}}}}, 'message': {'type': 'string'}, 'disclaimer': {'type': 'string'}, 'list_last_synced': {'type': 'string'}, 'address_normalized': {'type': 'string', 'description': 'The address after normalization, used to match against sanctioned_wallets.'}}}
get_cve_batch
PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA KEV status — same enrichment as get_cve_details, batched. Payment required: $0.01 via x402, sent in params._meta['x402/payment'] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for looking up several known CVE ids at once (e.g. from an SBOM or scan report). Do NOT use for a single CVE (use get_cve_details, lower overhead) or for discovering CVEs by vendor/product (use get_cve_by_product). BEHAVIOR: Accepts up to 20 ids per call; malformed or not-found ids are reported per-entry rather than failing the whole batch.
Esquema de entrada
{'type': 'object', 'required': ['cve_ids'], 'properties': {'cve_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': "Array of CVE identifiers, each formatted 'CVE-YYYY-NNNN'. Max 20 per call."}}}
get_cve_by_product
PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status, sorted by exploitation risk. Sourced from NVD keyword search. Payment required: $0.01 via x402, sent in params._meta["x402/payment"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for discovering CVEs by vendor/product when you do not already have an exact CVE id. Do NOT use for a known CVE id (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Uses NVD keyword search, not strict CPE matching — results may include near-matches. BEHAVIOR: Returns up to 50 results per call.
Esquema de entrada
{'type': 'object', 'required': ['vendor', 'product'], 'properties': {'vendor': {'type': 'string', 'description': "Vendor name, e.g. 'apache'."}, 'product': {'type': 'string', 'description': "Product name, e.g. 'log4j'."}, 'version': {'type': 'string', 'description': "Optional specific version, e.g. '2.14.1'."}, 'only_kev': {'type': 'boolean', 'description': 'If true, only return CVEs on the CISA KEV list.'}}}
get_cve_details
PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile), and the CISA Known Exploited Vulnerabilities catalog (active wild exploitation status). Payment required: $0.01 via x402, sent in params._meta["x402/payment"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for specific CVE lookups. Do NOT use for IP/domain/hash enrichment (use get_ioc_context) or bulk feed ingestion (use get_threat_indicators). USAGE EXCLUSIONS: Does not support wildcard search or threat-actor dossier profiling. BEHAVIOR: If payment is missing or fails, returns a normal tool result with isError: true, the x402 v2 PaymentRequired object in structuredContent and the same JSON in content[0].text; on success the settlement receipt is in result._meta["x402/payment-response"]. Returns 404 if CVE is not found.
Esquema de entrada
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'description': "Mandatory official CVE identifier string strictly formatted as 'CVE-YYYY-NNNN' (e.g., 'CVE-2021-44228')."}}}
get_ioc_batch
PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents. Each returns the same aggregated provenance as get_ioc_context from ThreatFox, URLhaus, and OTX. SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. all URLs an agent is about to visit). Do NOT use for a single indicator (use get_ioc_context, lower overhead) or bulk feed synchronization (use get_threat_indicators). BEHAVIOR: Accepts up to 20 indicators per call. A found:false result for any indicator means nothing bad is recorded in PG1's sources — NOT that it's safe. If NONE of the submitted indicators are found, the whole batch is FREE — no payment or free-tier quota consumed. If at least one indicator is found, the normal payment gate (x402 via params._meta['x402/payment'], with the PAYMENT-SIGNATURE header also accepted, or a Gumroad X-API-KEY license) applies to the full batch result.
Esquema de entrada
{'type': 'object', 'required': ['values'], 'properties': {'values': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Array of indicator values (IPv4 addresses, domains, URLs, or hashes) to look up. Max 20 per call.'}}}
get_ioc_context
PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents before visiting, downloading, or connecting to something. Returns aggregated provenance from ThreatFox, URLhaus, and OTX — reporting sources, observation count, aggregated confidence score, known malware families, tags, and first/last seen timestamps. SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of a single indicator. Do NOT use for bulk intelligence downloads (use get_threat_indicators), multiple indicators at once (use get_ioc_batch), or software vulnerability analysis (use get_cve_details). BEHAVIOR: Returns a normal result shaped { found: true, indicator_type, provenance } or { found: false } — never an error for 'not found'. A found:false result means nothing bad is recorded in PG1's sources; it does NOT mean the indicator is safe, only that it isn't in this dataset. Lookups that return found:false are FREE — no payment or free-tier quota is consumed. Payment (x402 via params._meta['x402/payment'], with the PAYMENT-SIGNATURE header also accepted, or a Gumroad X-API-KEY license) is only required when a real record is found. If payment is required but missing or fails, the result has isError: true with the x402 v2 PaymentRequired object in structuredContent.
Esquema de entrada
{'type': 'object', 'required': ['value'], 'properties': {'value': {'type': 'string', 'description': 'Mandatory exact indicator string value to look up, such as an IPv4 address (198.51.100.1), fully qualified domain, complete URL, or SHA-256 hash string.'}}}
get_threat_actor_profile
PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associated malware/tooling. Sourced from MITRE ATT&CK Enterprise. Payment required: $0.01 via x402, sent in params._meta['x402/payment'] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for actor/group-level profiling. Do NOT use for single-indicator lookups (use get_ioc_context) or vulnerability data (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Coverage is limited to groups tracked in MITRE ATT&CK — not all threat actors have an entry. BEHAVIOR: Returns 404 if no matching group or alias is found.
Esquema de entrada
{'type': 'object', 'required': ['actor_name'], 'properties': {'actor_name': {'type': 'string', 'description': "Group name or known alias, e.g. 'APT29' or 'Cozy Bear'. Matching is case-insensitive against both the group's primary name and its known aliases."}}}
get_threat_indicators
PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from ThreatFox, URLhaus, OTX and NVD. Payment required: $0.01 via x402, sent in params._meta["x402/payment"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for bulk feed synchronizations. Do NOT use for single-item lookups (use get_ioc_context) or CVE analysis (use get_cve_details). USAGE EXCLUSIONS: Does not provide historical query archival beyond the active ingestion window. BEHAVIOR: Pagination is handled via the limit parameter (max 1000). If payment is missing or fails, returns a normal tool result with isError: true, the x402 v2 PaymentRequired object in structuredContent and the same JSON in content[0].text; on success the settlement receipt is in result._meta["x402/payment-response"].
Esquema de entrada
{'type': 'object', 'properties': {'type': {'type': ['string', 'null'], 'description': "Indicator category filter. Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or 'FileHash-SHA256'."}, 'limit': {'type': ['integer', 'null'], 'default': 500, 'description': 'Pagination boundary constraint defining the maximum number of indicators to return in a single payload (integer between 1 and 1000, defaulting to 500).'}, 'since': {'type': ['string', 'null'], 'description': 'ISO timestamp constraint (e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after this exact timestamp.'}, 'min_score': {'type': ['integer', 'null'], 'description': 'Confidence score threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise.'}}}
get_usage_status
PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is always free.
Esquema de entrada
{'type': 'object', 'properties': {'identifier': {'type': 'string', 'description': 'Optional — the X-API-KEY or identifier to check usage for; defaults to the calling identifier if omitted.'}, 'license_key': {'type': 'string', 'description': 'Optional — check Gumroad license status alongside free-tier usage.'}}}
submit_indicator
PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402. Submissions are staged for review, not immediately added to the live feed.
Esquema de entrada
{'type': 'object', 'required': ['indicator', 'indicator_type'], 'properties': {'indicator': {'type': 'string'}, 'confidence': {'type': 'integer', 'description': "Submitter's own confidence, 0-100."}, 'source_note': {'type': 'string', 'description': 'Optional free-text on how this was observed.'}, 'indicator_type': {'type': 'string'}, 'malware_family': {'type': 'string', 'description': 'Optional.'}}}
subscribe_alerts
PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook URL as they're ingested. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402, since it establishes a recurring subscription rather than a single paid call.
Esquema de entrada
{'type': 'object', 'required': ['webhook_url'], 'properties': {'filter': {'type': 'object', 'properties': {'kev_only': {'type': 'boolean'}, 'min_epss': {'type': 'number'}, 'indicator_type': {'type': 'string'}}, 'description': 'Optional filter object: { indicator_type, min_epss, kev_only }'}, 'webhook_url': {'type': 'string', 'description': 'HTTPS URL to receive POSTed alert payloads.'}}}
Modificado
get_cve_by_product
1 de October de 2026 a las 02:42
Modificado
get_threat_actor_profile
1 de October de 2026 a las 02:42
Modificado
get_ioc_batch
1 de October de 2026 a las 02:42
Modificado
get_cve_batch
1 de October de 2026 a las 02:42
Modificado
get_ioc_context
1 de October de 2026 a las 02:42
Modificado
get_cve_details
1 de October de 2026 a las 02:42
Modificado
get_threat_indicators
1 de October de 2026 a las 02:42
Añadido
check_hostname_reputation
29 de September de 2026 a las 02:49
Añadido
check_domain_age
27 de September de 2026 a las 02:41
Añadido
check_wallet_sanctions
27 de September de 2026 a las 02:41
Modificado
get_cve_by_product
27 de September de 2026 a las 02:41
Modificado
get_threat_actor_profile
27 de September de 2026 a las 02:41
Modificado
get_ioc_batch
27 de September de 2026 a las 02:41
Modificado
get_cve_batch
27 de September de 2026 a las 02:41
Modificado
get_ioc_context
27 de September de 2026 a las 02:41
Modificado
get_cve_details
27 de September de 2026 a las 02:41
Modificado
get_threat_indicators
27 de September de 2026 a las 02:41
Añadido
submit_indicator
25 de September de 2026 a las 02:40
Añadido
subscribe_alerts
25 de September de 2026 a las 02:40
Añadido
get_usage_status
25 de September de 2026 a las 02:40
Añadido
get_cve_by_product
25 de September de 2026 a las 02:40
Añadido
get_threat_actor_profile
25 de September de 2026 a las 02:40
Añadido
get_ioc_batch
25 de September de 2026 a las 02:40
Añadido
get_cve_batch
25 de September de 2026 a las 02:40
Añadido
get_ioc_context
25 de September de 2026 a las 02:40
Añadido
get_cve_details
25 de September de 2026 a las 02:40
Añadido
get_threat_indicators
25 de September de 2026 a las 02:40