ContrastAPI
Ce que fait ce MCP
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domains, email security, MITRE ATLAS, ATT&CK, and D3FEND.
Outils
Schéma d’entrée
{'type': 'object', 'title': 'asn_lookupArguments', 'required': ['target'], 'properties': {'target': {'type': 'string', 'title': 'Target', 'description': "Domain or IP address to look up ASN for (e.g. 'cloudflare.com', '8.8.8.8')"}, 'include_full_prefixes': {'type': 'boolean', 'title': 'Include Full Prefixes', 'default': False, 'description': 'Return the full announced-prefixes list (default: False, returns first 50). ipv4_count and ipv6_count are always honest pre-truncation totals. Set True for network mapping or BGP route audits — Cloudflare AS13335 announces 2500+ prefixes.'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['target', 'asn'], 'properties': {'asn': {'type': 'integer'}, 'target': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'asn_name': {'type': 'string'}, 'warnings': {'type': 'array'}, 'ipv4_count': {'type': 'integer'}, 'ipv6_count': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'resolved_ip': {'type': ['string', 'null']}, 'ipv4_prefixes': {'type': 'array'}, 'ipv6_prefixes': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'atlas_case_study_lookupArguments', 'required': ['case_study_id'], 'properties': {'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default (omit/empty) returns slim (description truncated to 240 chars). Pass 'full' for the verbose narrative — case-study descriptions can run 1-3KB."}, 'case_study_id': {'type': 'string', 'title': 'Case Study Id', 'description': "MITRE ATLAS case study id, format 'AML.CS####' (e.g. 'AML.CS0000', 'AML.CS0014')."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['case_study_id', 'name'], 'properties': {'name': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'description': {'type': ['string', 'null']}, 'case_study_id': {'type': 'string'}, 'techniques_used': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'atlas_case_study_searchArguments', 'properties': {'limit': {'type': 'integer', 'title': 'Limit', 'default': 50, 'maximum': 200, 'minimum': 1, 'description': 'Max results to return. Range: 1-200.'}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default ('') returns slim records (description truncated to 240 chars). Pass 'full' for full description on every row."}, 'keyword': {'type': 'string', 'title': 'Keyword', 'default': '', 'description': "Substring match against case study name + description (case-insensitive). Min 2 chars. Example: 'evasion', 'data poisoning'. Omit to list all."}, 'technique_id': {'type': 'string', 'title': 'Technique Id', 'default': '', 'description': "Filter to case studies that include this ATLAS technique id, format 'AML.T####' or 'AML.T####.###' (e.g. 'AML.T0051'). Omit for any technique."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'query': {'type': 'object'}, 'total': {'type': 'integer'}, 'results': {'type': 'array'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'atlas_technique_lookupArguments', 'required': ['technique_id'], 'properties': {'technique_id': {'type': 'string', 'title': 'Technique Id', 'description': "MITRE ATLAS technique id, format 'AML.T####' or 'AML.T####.###' for sub-techniques (e.g. 'AML.T0000', 'AML.T0051' LLM Prompt Injection, 'AML.T0000.000')."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['technique_id', 'name'], 'properties': {'name': {'type': 'string'}, 'tactics': {'type': 'array'}, 'verdict': {'type': ['object', 'null']}, 'maturity': {'type': ['string', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'description': {'type': ['string', 'null']}, 'created_date': {'type': ['string', 'null']}, 'technique_id': {'type': 'string'}, 'modified_date': {'type': ['string', 'null']}, 'subtechnique_of': {'type': ['string', 'null']}, 'inherited_tactics': {'type': ['boolean', 'null']}, 'attack_reference_id': {'type': ['string', 'null']}, 'attack_reference_url': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'atlas_technique_searchArguments', 'properties': {'limit': {'type': 'integer', 'title': 'Limit', 'default': 50, 'maximum': 200, 'minimum': 1, 'description': 'Max results to return. Range: 1-200.'}, 'tactic': {'type': 'string', 'title': 'Tactic', 'default': '', 'description': "Filter by ATLAS tactic id, format 'AML.TA####'. Examples: 'AML.TA0002' (Reconnaissance), 'AML.TA0007' (ML Attack Staging). Omit for all tactics."}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default ('') returns slim records (description truncated to 240 chars; drill via atlas_technique_lookup for full text). Pass 'full' for full description on every row — large catalogs (167 techniques) can return ~100KB at full."}, 'keyword': {'type': 'string', 'title': 'Keyword', 'default': '', 'description': "Substring match against technique name + description (case-insensitive). Min 2 chars. Example: 'prompt injection', 'model evasion', 'poisoning'. Omit to list all."}, 'maturity': {'enum': ['', 'demonstrated', 'feasible', 'realized'], 'type': 'string', 'title': 'Maturity', 'default': '', 'description': "Filter by maturity: 'demonstrated' (observed in real attacks), 'feasible' (theoretical), or 'realized' (newer ATLAS classification, treat similar to demonstrated). Omit for all."}, 'exclude_id': {'type': 'string', 'title': 'Exclude Id', 'default': '', 'description': "Optional ATLAS technique id to exclude from results, format 'AML.T####' or 'AML.T####.###'. Useful when chaining from atlas_technique_lookup to fetch siblings without echoing self in the same-tactic search."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'query': {'type': 'object'}, 'total': {'type': 'integer'}, 'results': {'type': 'array'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'audit_domainArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Root domain to audit, without protocol or path (e.g. 'example.com', 'shopify.com')"}, 'include_all_txt': {'type': 'boolean', 'title': 'Include All Txt', 'default': False, 'description': 'Return every TXT record under report.dns.txt (default: False, only SPF/DMARC/DKIM/MTA-STS/TLS-RPT kept). report.dns.total_txt_records is always emitted with the honest pre-filter count. Default filter strips vendor verification strings (google-site-verification, ms=, facebook-domain-verification, etc.) that bloat the response without security signal. Set True only when you need the raw TXT inventory.'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string'}, 'report': {'type': ['object', 'null']}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'live_headers': {'type': 'object'}, 'technologies': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'brand_assetsArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Registrable domain to scrape brand assets for (e.g. 'github.com', 'stripe.com'). No scheme, no path, no port. The bot fetches https://<domain>/ with HTTP fallback."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'fetched_url', 'status_code'], 'properties': {'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'fetched_url': {'type': 'string'}, 'status_code': {'type': 'integer'}, 'theme_color': {'type': ['string', 'null']}, 'cache_respected': {'type': 'boolean'}, 'logo_url_untrusted': {'type': ['string', 'null']}, 'site_name_untrusted': {'type': ['string', 'null']}, 'favicon_url_untrusted': {'type': ['string', 'null']}, 'og_image_url_untrusted': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'bulk_atlas_technique_lookupArguments', 'required': ['technique_ids'], 'properties': {'technique_ids': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Technique Ids', 'maxItems': 50, 'description': "List of MITRE ATLAS technique ids in format 'AML.T####' or 'AML.T####.###' (e.g. ['AML.T0051', 'AML.T0043', 'AML.T0000.000']). Up to 50 per call. Case-insensitive; normalized + de-duplicated server-side. Each id counts as 1 request toward the rate limit."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'failed': {'type': 'integer'}, 'partial': {'type': 'boolean'}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'processed': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'successful': {'type': 'integer'}, 'skipped_due_to_rate_limit': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'bulk_cve_lookupArguments', 'required': ['cve_ids'], 'properties': {'cve_ids': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Cve Ids', 'description': "List of CVE identifiers in format CVE-YYYY-NNNNN (e.g. ['CVE-2024-3094', 'CVE-2021-44228', 'CVE-2023-44487']). Maximum 50 per request (same cap for Free and Pro)."}, 'include_reference_tags': {'type': 'boolean', 'title': 'Include Reference Tags', 'default': True, 'description': 'Return structured references_full per CVE in the batch [{url, tags, source}]. Same shape as cve_lookup (default: True). Activates tag-first patch detection per item. Set False for legacy clients.'}, 'include_full_references': {'type': 'boolean', 'title': 'Include Full References', 'default': True, 'description': 'Return the full references list for each CVE in the batch (default: True). total_references is always emitted. Set False to truncate each item to first 10 entries when payload-bound.'}, 'include_affected_products': {'type': 'boolean', 'title': 'Include Affected Products', 'default': False, 'description': 'Return the full affected_products list for each CVE in the batch (default: False, each CVE returns first 20). Set True for bulk dependency audits.'}, 'include_severity_breakdown': {'type': 'boolean', 'title': 'Include Severity Breakdown', 'default': True, 'description': 'Return severity_sources/consensus/disagreement per CVE in batch. Same shape as cve_lookup (default: True). cvss_v2 and cvss_v2_vector are always emitted (additive non-opt-in). Set False to skip if downstream cannot tolerate the extra fields.'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'failed': {'type': 'integer'}, 'partial': {'type': 'boolean'}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'processed': {'type': 'integer'}, 'timed_out': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'successful': {'type': 'integer'}, 'skipped_due_to_rate_limit': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'bulk_ioc_lookupArguments', 'required': ['indicators'], 'properties': {'indicators': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Indicators', 'description': "List of indicators of compromise: IP addresses, domains, URLs, or file hashes (e.g. ['8.8.8.8', 'evil.com', 'd41d8cd98f00b204e9800998ecf8427e']). Maximum 50 per request (same cap for Free and Pro). Each indicator type is auto-detected."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'failed': {'type': 'integer'}, 'invalid': {'type': 'integer'}, 'partial': {'type': 'boolean'}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'processed': {'type': 'integer'}, 'timed_out': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'successful': {'type': 'integer'}, 'skipped_due_to_rate_limit': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'bulk_sigma_rule_lookupArguments', 'required': ['rule_ids'], 'properties': {'rule_ids': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Rule Ids', 'maxItems': 50, 'description': "List of Sigma rule UUIDs in RFC 4122 format. Up to 50 per call (same cap for Free and Pro). Each rule_id counts as 1 request toward the hourly quota. Per-item validation: invalid-format ids return status='invalid_format', unknown UUIDs return status='not_found' — the whole call does not fail."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'failed': {'type': 'integer'}, 'partial': {'type': 'boolean'}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'processed': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'successful': {'type': 'integer'}, 'skipped_due_to_rate_limit': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'calculate_risk_scoreArguments', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'title': 'Cve Id', 'description': "CVE identifier in format CVE-YYYY-NNNNN (e.g. 'CVE-2021-44228', 'CVE-2024-3094')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['cve_id', 'score', 'label', 'urgency', 'has_public_poc', 'components', 'recommendation', 'summary'], 'properties': {'label': {'type': 'string'}, 'score': {'type': 'number'}, 'cve_id': {'type': 'string'}, 'summary': {'type': 'string'}, 'urgency': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'components': {'type': 'object'}, 'next_calls': {'type': ['array', 'null']}, 'has_public_poc': {'type': 'boolean'}, 'recommendation': {'type': 'string'}, 'boosters_applied': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'check_dependenciesArguments', 'required': ['packages'], 'properties': {'packages': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'title': 'Packages', 'description': 'List of dependency packages to audit. Each item is an object with \'name\' (required, max 200 chars, e.g. \'lodash\', \'django\', \'log4j-core\') and optional \'version\' (max 100 chars, e.g. \'4.17.0\', \'2.14.1\'). Only \'name\' and \'version\' fields are used; extra fields are ignored. Example: [{"name": "lodash", "version": "4.17.0"}, {"name": "django"}]. Maximum 50 per request (same cap for Free and Pro).'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'findings': {'type': 'array'}, 'processed': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'by_severity': {'type': 'object'}, 'skipped_due_to_rate_limit': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'check_headersArguments', 'required': ['headers'], 'properties': {'headers': {'type': 'string', 'title': 'Headers', 'description': 'JSON string of HTTP header name-value pairs to validate. Example: \'{"Strict-Transport-Security": "max-age=31536000", "X-Frame-Options": "DENY"}\'. Include only security-relevant headers you want to analyze.'}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default ('') returns slim findings — raw header values capped at 500 chars with total_value_length carrying the honest pre-truncation length. Pass 'full' to restore the full raw value. Allowed: '' or 'full'."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'grade': {'type': 'string'}, 'score': {'type': 'integer'}, 'total': {'type': 'integer'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'findings': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'by_severity': {'type': 'object'}, 'headers_missing': {'type': 'array'}, 'headers_present': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'check_injectionArguments', 'required': ['code'], 'properties': {'code': {'type': 'string', 'title': 'Code', 'description': 'Source code string to scan for injection vulnerabilities (can be a single file or code snippet)'}, 'language': {'enum': ['python', 'javascript', 'typescript', 'java', 'go', 'ruby', 'shell', 'bash', 'generic'], 'type': 'string', 'title': 'Language', 'default': 'generic', 'description': "Programming language of the code. Must be one of: python, javascript, typescript, java, go, ruby, shell, bash, generic. Use 'generic' if unsure."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'findings': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'by_severity': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'check_secretsArguments', 'required': ['code'], 'properties': {'code': {'type': 'string', 'title': 'Code', 'description': 'Source code string to scan for secrets (can be a single file or code snippet)'}, 'language': {'enum': ['python', 'javascript', 'typescript', 'java', 'go', 'ruby', 'shell', 'bash', 'generic'], 'type': 'string', 'title': 'Language', 'default': 'generic', 'description': "Programming language of the code. Must be one of: python, javascript, typescript, java, go, ruby, shell, bash, generic. Use 'generic' if unsure."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'total': {'type': 'integer'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'findings': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'by_severity': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'contrast_scanArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Root domain to scan, without protocol or path (e.g. 'example.com'). Bare IPs and private-resolving domains are rejected."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'dns': {'type': 'object'}, 'ssl': {'type': 'object'}, 'cors': {'type': 'object'}, 'html': {'type': 'object'}, 'grade': {'type': 'string'}, 'dnssec': {'type': 'object'}, 'domain': {'type': 'string'}, 'cookies': {'type': 'object'}, 'headers': {'type': 'object'}, 'methods': {'type': 'object'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'findings': {'type': 'array'}, 'redirect': {'type': 'object'}, 'max_score': {'type': 'integer'}, 'disclosure': {'type': 'object'}, 'enterprise': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'resolved_ip': {'type': ['string', 'null']}, 'total_score': {'type': 'integer'}, 'csp_analysis': {'type': 'object'}, 'findings_count': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'cve_leadingArguments', 'properties': {'limit': {'type': 'integer', 'title': 'Limit', 'default': 50, 'maximum': 200, 'minimum': 1, 'description': 'Maximum results to return. Range: 1-200.'}, 'offset': {'type': 'integer', 'title': 'Offset', 'default': 0, 'maximum': 5000, 'minimum': 0, 'description': 'Skip N results for pagination.'}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Per-result detail level. Default ('') returns slim list items (cve_id, summary, severity, cvss_v3, cwe_id, epss, kev, total_products, published, modified, sources). Pass 'full' to also return description, cvss_breakdown, affected_products, references, first_seen_source, first_seen_at. Slim default avoids description/summary duplication that bloats 50-item leading lists. Verdict is at the response root, not per-row (deduplicated for ~40% payload savings). Allowed: '' or 'full'."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'hint': {'type': ['object', 'null']}, 'count': {'type': 'integer'}, 'total': {'type': 'integer'}, 'offset': {'type': 'integer'}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'truncated': {'type': 'boolean'}, 'next_calls': {'type': ['array', 'null']}, 'query_echo': {'type': ['object', 'null']}, 'next_offset': {'type': ['integer', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'cve_lookupArguments', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'title': 'Cve Id', 'description': "CVE identifier in format CVE-YYYY-NNNNN (e.g. 'CVE-2024-3094', 'CVE-2023-44487')"}, 'include_reference_tags': {'type': 'boolean', 'title': 'Include Reference Tags', 'default': True, 'description': "Return structured references_full field with [{url, tags, source}] objects (NVD reference tags + source provenance) (default: True). Inspects which references are vendor patches (tags=['Patch']) vs exploit PoCs (tags=['Exploit']) vs mailing list discussions. Patch URL detection is tag-first when refs_with_tags is populated; legacy cached rows fall back to regex. Set False to skip the structured shape for legacy clients."}, 'include_full_references': {'type': 'boolean', 'title': 'Include Full References', 'default': True, 'description': 'Return the full references list (default: True, returns all references). total_references is always emitted with the honest count; patch URL detection always runs against the full list, so patch_url/patch_available are unaffected. Set False to truncate to first 10 entries when bandwidth-bound.'}, 'include_affected_products': {'type': 'boolean', 'title': 'Include Affected Products', 'default': False, 'description': 'Return the full affected_products list (default: False, returns first 20). Set True for bulk audits or dependency scanning of Log4j-class CVEs with 50+ products.'}, 'include_severity_breakdown': {'type': 'boolean', 'title': 'Include Severity Breakdown', 'default': True, 'description': 'Return severity_sources, severity_consensus, and severity_disagreement (multi-source severity breakdown) (default: True). Surfaces vendor disputes (e.g. CVE-2023-38545 NVD-CRITICAL vs GHSA-HIGH). cvss_v2 and cvss_v2_vector are always emitted (additive non-opt-in). Consensus uses majority-bucket vote with highest-severity tie-break (CRITICAL > HIGH > MEDIUM > LOW > NONE). Set False to skip if downstream cannot tolerate the extra fields.'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['cve_id'], 'properties': {'kev': {'type': 'object'}, 'cwes': {'type': ['array', 'null']}, 'epss': {'type': 'object'}, 'cve_id': {'type': 'string'}, 'cwe_id': {'type': ['string', 'null']}, 'cvss_v2': {'type': ['number', 'null']}, 'cvss_v3': {'type': ['number', 'null']}, 'sources': {'type': 'array'}, 'summary': {'type': ['string', 'null']}, 'verdict': {'type': ['object', 'null']}, 'cve_tags': {'type': ['array', 'null']}, 'modified': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'patch_url': {'type': ['string', 'null']}, 'published': {'type': ['string', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'references': {'type': 'array'}, 'description': {'type': ['string', 'null']}, 'related_cves': {'type': ['array', 'null']}, 'first_seen_at': {'type': ['string', 'null']}, 'cvss_breakdown': {'type': ['object', 'null']}, 'cvss_v2_vector': {'type': ['string', 'null']}, 'total_products': {'type': 'integer'}, 'patch_available': {'type': ['boolean', 'null']}, 'references_full': {'type': ['array', 'null']}, 'severity_sources': {'type': ['array', 'null']}, 'total_references': {'type': 'integer'}, 'affected_products': {'type': 'array'}, 'first_seen_source': {'type': ['string', 'null']}, 'severity_consensus': {'type': ['string', 'null']}, 'vulnerability_status': {'type': ['string', 'null']}, 'severity_disagreement': {'type': ['boolean', 'null']}, 'total_references_unique': {'type': ['integer', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'cve_searchArguments', 'properties': {'kev': {'type': 'boolean', 'title': 'Kev', 'default': False, 'description': 'If true, return only CVEs in the CISA Known Exploited Vulnerabilities (KEV) catalog — these are actively exploited in the wild.'}, 'sort': {'enum': ['', 'published_desc', 'epss_desc', 'cvss_desc'], 'type': 'string', 'title': 'Sort', 'default': '', 'description': 'Sort order for results. Must be one of: published_desc (newest first), epss_desc (most exploitable first), cvss_desc (most severe first). Omit for newest first (default=published_desc).'}, 'limit': {'type': 'integer', 'title': 'Limit', 'default': 50, 'maximum': 200, 'minimum': 1, 'description': 'Maximum results to return. Range: 1-200.'}, 'cwe_id': {'type': 'string', 'title': 'Cwe Id', 'default': '', 'description': 'Filter by CWE weakness ID. Exact match, case-insensitive. Common values: CWE-79 (XSS), CWE-89 (SQL injection), CWE-120 (buffer overflow), CWE-78 (command injection). Format: CWE-<number>. Omit to not filter by CWE.'}, 'offset': {'type': 'integer', 'title': 'Offset', 'default': 0, 'maximum': 5000, 'minimum': 0, 'description': 'Skip N results for pagination. Use with limit to page through results.'}, 'vendor': {'type': 'string', 'title': 'Vendor', 'default': '', 'description': 'Filter by vendor name (case-insensitive). When combined with product, both must match the same CPE row — prevents cross-row false matches. Example: vendor=apache, product=struts.'}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Per-result detail level. Default (omit) returns slim list items (cve_id, summary, severity, cvss_v3, cwe_id, epss, kev, total_products, published, modified, sources). Pass 'full' to also return description, cvss_breakdown, affected_products, references, first_seen_source, first_seen_at — only do this when the user explicitly wants drill-down on every result. Even with 'full', per-result affected_products and references may be truncated (the per-result total_products/total_references report the honest counts); use cve_lookup for the guaranteed-complete per-CVE lists. For single-CVE detail prefer cve_lookup; slim default keeps token cost ~70% lower on Log4j-class queries. Note: verdict is at the response root, not per-row (was deduplicated to save ~40% payload)."}, 'product': {'type': 'string', 'title': 'Product', 'default': '', 'description': "Product or vendor token to filter by. EXACT match (case-insensitive) against the NVD-canonical CPE product/vendor token — NOT substring/fuzzy, and NOT necessarily the common project name. Common names, vendor renames, and build-tool artifact ids often differ from the canonical token (e.g. modern nginx CVEs are under 'nginx_open_source'/'nginx_plus', vendor 'f5', not 'nginx'; Maven 'log4j-core' maps to 'log4j'). A low or zero count for a well-known product usually means the token differs — do NOT assume coverage is complete. For dependency/package lists prefer check_dependencies, and for a domain's whole tech stack tech_stack_cve_audit (both auto-normalize tokens). A product match means CVEs exist for that product, not that a specific running version is affected — verify the running version is within each CVE's affected range. Omit to search all products."}, 'cvss_max': {'type': 'number', 'title': 'Cvss Max', 'default': 10.0, 'maximum': 10.0, 'minimum': 0.0, 'description': 'Maximum CVSS v3 base score (0.0-10.0). Default 10.0 = no filter (sentinel, not applied). Set < 10.0 to filter — CVEs with null CVSS are excluded when active. Combine with cvss_min for a range.'}, 'cvss_min': {'type': 'number', 'title': 'Cvss Min', 'default': 0.0, 'maximum': 10.0, 'minimum': 0.0, 'description': 'Minimum CVSS v3 base score (0.0-10.0). Default 0.0 = no filter (sentinel, not applied). Set > 0 to filter — CVEs with null CVSS are excluded when active. Use 7.0 for high+critical, 9.0 for critical only.'}, 'epss_min': {'type': 'number', 'title': 'Epss Min', 'default': 0.0, 'maximum': 1.0, 'minimum': 0.0, 'description': 'Minimum EPSS score filter (0.0-1.0). EPSS predicts exploitation probability. 0.5 = top ~5% most likely to be exploited. 0.0 = no filter.'}, 'severity': {'enum': ['', 'CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'title': 'Severity', 'default': '', 'description': 'CVSS severity level. Must be one of: CRITICAL, HIGH, MEDIUM, LOW. Omit for all severities.'}, 'published_after': {'type': 'string', 'title': 'Published After', 'default': '', 'description': "Inclusive lower bound on publish date as YYYY-MM-DD (UTC). Pick this when the user names a starting point, e.g. 'since 2015' → '2015-01-01', 'after March 2024' → '2024-03-01'. Omit to not bound the lower edge. Combine with published_before for ranges."}, 'published_before': {'type': 'string', 'title': 'Published Before', 'default': '', 'description': "Inclusive upper bound on publish date as YYYY-MM-DD (UTC). Pick this when the user names an ending point, e.g. 'before 2020' → '2019-12-31', 'up to 2023' → '2023-12-31'. Omit to not bound the upper edge. Combine with published_after for ranges."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'hint': {'type': ['object', 'null']}, 'count': {'type': 'integer'}, 'total': {'type': 'integer'}, 'offset': {'type': 'integer'}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'truncated': {'type': 'boolean'}, 'next_calls': {'type': ['array', 'null']}, 'query_echo': {'type': ['object', 'null']}, 'next_offset': {'type': ['integer', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'cwe_lookupArguments', 'required': ['cwe_id'], 'properties': {'cwe_id': {'type': 'string', 'title': 'Cwe Id', 'description': "CWE identifier — accepts 'CWE-79', 'cwe-79', or bare '79'. Common values: CWE-79 (XSS), CWE-89 (SQL injection), CWE-78 (command injection), CWE-502 (deserialization), CWE-22 (path traversal), CWE-120 (buffer overflow)."}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default ('') returns slim record (first 3 mitigations, first 3 examples; extended_description is null). total_mitigations / total_examples are always honest pre-truncation counts. Pass 'full' to populate extended_description and return the full mitigations + examples lists."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['cwe_id', 'name'], 'properties': {'name': {'type': 'string'}, 'cwe_id': {'type': 'string'}, 'status': {'type': ['string', 'null']}, 'verdict': {'type': ['object', 'null']}, 'examples': {'type': 'array'}, 'cve_count': {'type': 'integer'}, 'child_cwes': {'type': 'array'}, 'likelihood': {'type': ['string', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'parent_cwe': {'type': ['string', 'null']}, 'updated_at': {'type': ['string', 'null']}, 'description': {'type': ['string', 'null']}, 'mitigations': {'type': 'array'}, 'abstract_type': {'type': ['string', 'null']}, 'total_examples': {'type': ['integer', 'null']}, 'total_mitigations': {'type': ['integer', 'null']}, 'extended_description': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'd3fend_attack_coverageArguments', 'required': ['attack_technique_ids'], 'properties': {'attack_technique_ids': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Attack Technique Ids', 'maxItems': 500, 'description': "List of ATT&CK technique ids (T#### or T####.###) to assess. Capped at 500 — extra entries are dropped server-side. Example: ['T1059', 'T1550.001', 'T1190', 'T9999']."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'coverage_by_tactic': {'type': 'object'}, 'queried_techniques': {'type': 'array'}, 'defended_techniques': {'type': 'array'}, 'undefended_techniques': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'd3fend_defense_for_attackArguments', 'required': ['attack_technique_id'], 'properties': {'limit': {'type': 'integer', 'title': 'Limit', 'default': 30, 'maximum': 200, 'minimum': 1, 'description': 'Cap on `defenses` array length. Default 30; popular T-codes (T1059, T1078) map to 30-50+ defenses. `total` and `coverage_by_tactic` always reflect the honest pre-truncation count.'}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default (omit/empty) returns slim rows (drops the deterministic ontology `uri` — popular T-codes with 15+ defenses save ~900 chars). Pass 'full' to get `uri` back on every row."}, 'exclude_id': {'type': 'string', 'title': 'Exclude Id', 'default': '', 'description': "Optional D3FEND defense slug to omit from the defenses list. Used when chaining from d3fend_defense_lookup so the originating defense is not echoed back in its own 'see also' results."}, 'attack_technique_id': {'type': 'string', 'title': 'Attack Technique Id', 'description': "ATT&CK technique id matching 'T####' or 'T####.###' (e.g. 'T1059', 'T1550.001'). Use this to bridge from CVE/ATLAS findings to D3FEND mitigations."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['attack_technique_id'], 'properties': {'total': {'type': 'integer'}, 'verdict': {'type': ['object', 'null']}, 'defenses': {'type': 'array'}, 'truncated': {'type': 'boolean'}, 'next_calls': {'type': ['array', 'null']}, 'coverage_by_tactic': {'type': 'object'}, 'attack_technique_id': {'type': 'string'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'd3fend_defense_lookupArguments', 'required': ['defense_id'], 'properties': {'defense_id': {'type': 'string', 'title': 'Defense Id', 'description': "D3FEND defense slug from the ontology URI fragment (CamelCase), e.g. 'TokenBinding', 'FileHashing', 'CertificatePinning'."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['defense_id', 'label', 'uri', 'tactic'], 'properties': {'uri': {'type': 'string'}, 'label': {'type': 'string'}, 'tactic': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'artifact': {'type': ['string', 'null']}, 'defense_id': {'type': 'string'}, 'next_calls': {'type': ['array', 'null']}, 'description': {'type': ['string', 'null']}, 'parent_label': {'type': ['string', 'null']}, 'attack_techniques': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'd3fend_defense_searchArguments', 'properties': {'limit': {'type': 'integer', 'title': 'Limit', 'default': 50, 'maximum': 200, 'minimum': 1, 'description': 'Max results to return. Range: 1-200.'}, 'tactic': {'enum': ['', 'Model', 'Harden', 'Detect', 'Isolate', 'Deceive', 'Evict', 'Restore'], 'type': 'string', 'title': 'Tactic', 'default': '', 'description': 'Filter by D3FEND tactic. One of: Model, Harden, Detect, Isolate, Deceive, Evict, Restore. Omit for all tactics.'}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default (omit/empty) returns slim rows (drops the deterministic ontology `uri` field, ~60 chars/row saved). Pass 'full' to get `uri` back on every row. The slug `defense_id` is always returned and uniquely identifies the defense."}, 'keyword': {'type': 'string', 'title': 'Keyword', 'default': '', 'description': "Substring match against defense label, description, or parent_label (case-insensitive). Min 2 chars. Example: 'token', 'hashing', 'sandbox'. Omit to list all."}, 'artifact': {'type': 'string', 'title': 'Artifact', 'default': '', 'description': "Filter by exact targeted digital artifact (case-insensitive), e.g. 'Access Token', 'File', 'Process'. Omit for any artifact."}, 'exclude_id': {'type': 'string', 'title': 'Exclude Id', 'default': '', 'description': "Optional D3FEND defense slug (CamelCase, e.g. 'TokenBinding') to omit from results. Useful when chaining from d3fend_defense_lookup so the originating defense is not echoed back in its own siblings list. Omit when not needed."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'query': {'type': 'object'}, 'total': {'type': 'integer'}, 'results': {'type': 'array'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'dns_lookupArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Root domain to query, without protocol or path (e.g. 'example.com', 'cloudflare.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'records'], 'properties': {'domain': {'type': 'string'}, 'records': {'type': 'object'}, 'summary': {'type': ['string', 'null']}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'domain_reportArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Root domain to analyze, without protocol or path (e.g. 'example.com', 'shopify.com')"}, 'include_all_txt': {'type': 'boolean', 'title': 'Include All Txt', 'default': False, 'description': 'Return every TXT record (default: False, only SPF/DMARC/DKIM/MTA-STS/TLS-RPT kept). dns.total_txt_records is always emitted with the honest pre-filter count. Default filter strips vendor verification strings (google-site-verification, ms=, facebook-domain-verification, etc.) that bloat the response without security signal. Set True only when you need the raw TXT inventory.'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'dns': {'type': ['object', 'null']}, 'ssl': {'type': ['object', 'null']}, 'waf': {'type': ['object', 'null']}, 'risk': {'type': ['object', 'null']}, 'whois': {'type': ['object', 'null']}, 'domain': {'type': 'string'}, 'threat': {'type': ['object', 'null']}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'reputation': {'type': ['object', 'null']}, 'subdomains': {'type': ['object', 'null']}, 'reverse_dns': {'type': ['object', 'null']}, 'certificates': {'type': ['object', 'null']}, 'email_security': {'type': ['object', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'email_disposableArguments', 'required': ['email'], 'properties': {'email': {'type': 'string', 'title': 'Email', 'description': "Full email address to check (e.g. 'user@tempmail.com', 'test@guerrillamail.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['email', 'domain'], 'properties': {'email': {'type': 'string'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'provider': {'type': ['string', 'null']}, 'disposable': {'type': 'boolean'}, 'mx_records': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'risk_level': {'type': 'string'}, 'mx_disposable': {'type': 'boolean'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'email_mxArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to analyze email configuration for (e.g. 'example.com', 'google.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'mx_records': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'mail_provider': {'type': ['string', 'null']}, 'email_security': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'email_security_postureArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to audit email authentication posture for (e.g. 'example.com')"}, 'selectors': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Selectors', 'default': None, 'description': 'Optional comma-separated custom DKIM selectors to probe'}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'spf', 'dmarc', 'dkim', 'posture_score', 'posture_grade', 'all_findings', 'summary'], 'properties': {'spf': {'type': 'object'}, 'dkim': {'type': 'object'}, 'dmarc': {'type': 'object'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'all_findings': {'type': 'array'}, 'posture_grade': {'type': 'string'}, 'posture_score': {'type': 'integer'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'email_verifyArguments', 'required': ['email'], 'properties': {'email': {'type': 'string', 'title': 'Email', 'description': "Full email address to verify (e.g. 'admin@example.com', 'user@gmail.com'). Must contain '@'."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['email', 'domain', 'syntax_valid'], 'properties': {'email': {'type': 'string'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'role_type': {'type': ['string', 'null']}, 'disposable': {'type': 'boolean'}, 'mx_records': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'role_address': {'type': 'boolean'}, 'syntax_valid': {'type': 'boolean'}, 'free_provider': {'type': 'boolean'}, 'disposable_provider': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'exploit_lookupArguments', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'title': 'Cve Id', 'description': "CVE identifier in format CVE-YYYY-NNNNN (e.g. 'CVE-2024-3094', 'CVE-2023-44487')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string'}, 'sources': {'type': 'object'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'exploits': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'exploits_found': {'type': 'integer'}, 'has_public_exploit': {'type': 'boolean'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'geo_auditArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Registrable domain to audit for AI-visibility / GEO readiness (e.g. 'example.com', 'shopify.com'). No scheme, no path, no port. Strictly homepage-only — the bot fetches https://<domain>/ with HTTP fallback (we do NOT crawl)."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'fetched_url', 'status_code', 'score'], 'properties': {'score': {'type': 'integer'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'h1_count': {'type': 'integer'}, 'h2_count': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'fetched_url': {'type': 'string'}, 'status_code': {'type': 'integer'}, 'og_tag_count': {'type': 'integer'}, 'schema_types': {'type': 'array'}, 'has_canonical': {'type': 'boolean'}, 'sitemap_count': {'type': 'integer'}, 'cache_respected': {'type': 'boolean'}, 'missing_signals': {'type': 'array'}, 'llms_txt_present': {'type': 'boolean'}, 'render_framework': {'type': ['string', 'null']}, 'ai_crawlers_total': {'type': 'integer'}, 'comparison_content': {'type': 'boolean'}, 'ai_crawlers_allowed': {'type': 'integer'}, 'ai_crawlers_blocked': {'type': 'array'}, 'client_side_rendered': {'type': 'boolean'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'get_cvss_detailsArguments', 'required': ['vector'], 'properties': {'vector': {'type': 'string', 'title': 'Vector', 'description': "CVSS v3.0 or v3.1 vector string, e.g. 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'. v2 vectors are rejected — use the cvss_v2_vector field on cve_lookup if you need v2."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['version', 'vector', 'base_score', 'base_severity', 'metrics', 'summary'], 'properties': {'vector': {'type': 'string'}, 'metrics': {'type': 'object'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'version': {'type': 'string'}, 'base_score': {'type': 'number'}, 'next_calls': {'type': ['array', 'null']}, 'base_severity': {'type': 'string'}, 'temporal_score': {'type': ['number', 'null']}, 'environmental_score': {'type': ['number', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'hash_lookupArguments', 'required': ['file_hash'], 'properties': {'file_hash': {'type': 'string', 'title': 'File Hash', 'description': "File hash to look up. Accepts MD5 (32 chars), SHA-1 (40 chars), or SHA-256 (64 chars). Lowercase hex only, no spaces. Example: 'd41d8cd98f00b204e9800998ecf8427e'"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['hash', 'hash_type'], 'properties': {'hash': {'type': 'string'}, 'tags': {'type': 'array'}, 'found': {'type': 'boolean'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'file_name': {'type': ['string', 'null']}, 'file_size': {'type': ['integer', 'null']}, 'file_type': {'type': ['string', 'null']}, 'hash_type': {'type': 'string'}, 'first_seen': {'type': ['string', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'malware_family': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'ioc_lookupArguments', 'required': ['indicator'], 'properties': {'indicator': {'type': 'string', 'title': 'Indicator', 'description': "Indicator of Compromise: IP address, domain, full URL, or file hash in MD5/SHA1/SHA256 format (e.g. '8.8.8.8', 'evil.com', 'https://evil.com/malware.exe', 'd41d8cd98f00b204e9800998ecf8427e')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['indicator', 'type'], 'properties': {'type': {'type': 'string'}, 'sources': {'type': 'object'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'indicator': {'type': 'string'}, 'next_calls': {'type': ['array', 'null']}, 'threat_level': {'type': 'string'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'ip_lookupArguments', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'title': 'Ip', 'description': "IPv4 or IPv6 address to investigate (e.g. '8.8.8.8', '2606:4700::1111')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string'}, 'asn': {'type': ['integer', 'null']}, 'ptr': {'type': ['string', 'null']}, 'cpes': {'type': 'array'}, 'tags': {'type': 'array'}, 'ports': {'type': 'array'}, 'vulns': {'type': 'array'}, 'country': {'type': ['string', 'null']}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'asn_name': {'type': ['string', 'null']}, 'tor_exit': {'type': 'boolean'}, 'hostnames': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'reputation': {'type': ['object', 'null']}, 'risk_score': {'type': 'integer'}, 'is_datacenter': {'type': 'boolean'}, 'cloud_provider': {'type': ['string', 'null']}, 'severity_label': {'type': 'string'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'kev_detailArguments', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'title': 'Cve Id', 'description': "CVE identifier in format CVE-YYYY-NNNNN (e.g. 'CVE-2021-44228', 'CVE-2024-3094')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['cve_id'], 'properties': {'cwes': {'type': 'array'}, 'notes': {'type': ['string', 'null']}, 'cve_id': {'type': 'string'}, 'in_kev': {'type': 'boolean'}, 'product': {'type': ['string', 'null']}, 'verdict': {'type': ['object', 'null']}, 'due_date': {'type': ['string', 'null']}, 'date_added': {'type': ['string', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'updated_at': {'type': ['string', 'null']}, 'date_removed': {'type': ['string', 'null']}, 'date_updated': {'type': ['string', 'null']}, 'vendor_project': {'type': ['string', 'null']}, 'required_action': {'type': ['string', 'null']}, 'short_description': {'type': ['string', 'null']}, 'vulnerability_name': {'type': ['string', 'null']}, 'known_ransomware_use': {'type': 'boolean'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'password_checkArguments', 'required': ['sha1_hash'], 'properties': {'sha1_hash': {'type': 'string', 'title': 'Sha1 Hash', 'description': "Full SHA-1 hash of the password as 40 lowercase hexadecimal characters (e.g. '5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8' for 'password')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['hash_prefix'], 'properties': {'found': {'type': 'boolean'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'hash_prefix': {'type': 'string'}, 'breach_count': {'type': 'integer'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'phishing_checkArguments', 'required': ['url'], 'properties': {'url': {'type': 'string', 'title': 'Url', 'description': "Full URL to check, including protocol (e.g. 'https://suspicious-login.com/verify', 'http://evil.com/payload.exe')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['url', 'host'], 'properties': {'url': {'type': 'string'}, 'host': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'is_stale': {'type': 'boolean'}, 'next_calls': {'type': ['array', 'null']}, 'urlhaus_url': {'type': 'object'}, 'is_malicious': {'type': 'boolean'}, 'threat_level': {'type': 'string'}, 'urlhaus_host': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'phone_lookupArguments', 'required': ['number'], 'properties': {'number': {'type': 'string', 'title': 'Number', 'description': "Phone number in E.164 format: + followed by country code and number, no spaces or dashes. Examples: '+14155552671' (US), '+905551234567' (TR), '+442071234567' (UK). Wrong: '0555-123-4567', '(415) 555-2671'"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'type': {'type': 'string'}, 'error': {'type': ['string', 'null']}, 'valid': {'type': 'boolean'}, 'format': {'type': ['object', 'null']}, 'number': {'type': 'string'}, 'carrier': {'type': ['string', 'null']}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'timezone': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'country_code': {'type': 'string'}, 'country_name': {'type': 'string'}, 'carrier_status': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'redirect_chainArguments', 'required': ['url'], 'properties': {'url': {'type': 'string', 'title': 'Url', 'description': "Full URL whose redirect chain to walk, e.g. 'https://bit.ly/3xyz' or 'http://example.com/old-path'. Must start with http:// or https://. Pass the URL exactly as you'd `curl -L` it; the server handles encoding."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['start_url', 'final_url', 'hop_count', 'final_status'], 'properties': {'hops': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'final_url': {'type': 'string'}, 'hop_count': {'type': 'integer'}, 'start_url': {'type': 'string'}, 'truncated': {'type': 'boolean'}, 'next_calls': {'type': ['array', 'null']}, 'final_status': {'type': 'integer'}, 'loop_detected': {'type': 'boolean'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'robots_txtArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Registrable domain to fetch robots.txt for (e.g. 'example.com', 'github.com'). No scheme, no path, no port. Subdomains accepted; the bot fetches https://<domain>/robots.txt with HTTP fallback."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'fetched_url', 'status_code'], 'properties': {'host': {'type': ['string', 'null']}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'sitemaps': {'type': 'array'}, 'truncated': {'type': 'boolean'}, 'next_calls': {'type': ['array', 'null']}, 'fetched_url': {'type': 'string'}, 'status_code': {'type': 'integer'}, 'user_agents': {'type': 'object'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'scan_headersArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to scan live HTTP headers for (e.g. 'example.com', 'api.github.com')"}, 'include': {'enum': ['', 'full'], 'type': 'string', 'title': 'Include', 'default': '', 'description': "Detail level. Default ('') returns slim findings — raw header values capped at 500 chars with total_value_length carrying the honest pre-truncation length. Pass 'full' to restore the full raw value (useful for inspecting full CSP directives on sites like GitHub where the CSP header exceeds 4 KB). Allowed: '' or 'full'."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'url': {'type': 'string'}, 'grade': {'type': 'string'}, 'score': {'type': 'integer'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'findings': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'status_code': {'type': 'integer'}, 'headers_missing': {'type': 'array'}, 'headers_present': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'seo_auditArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Registrable domain to audit SEO for (e.g. 'example.com', 'shopify.com'). No scheme, no path, no port. Strictly homepage-only — the bot fetches https://<domain>/ with HTTP fallback and audits that single page (we do NOT crawl)."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'fetched_url', 'status_code', 'score'], 'properties': {'score': {'type': 'integer'}, 'domain': {'type': 'string'}, 'og_tags': {'type': 'object'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'h1_count': {'type': 'integer'}, 'h2_count': {'type': 'integer'}, 'h3_count': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'fetched_url': {'type': 'string'}, 'status_code': {'type': 'integer'}, 'h1_untrusted': {'type': 'array'}, 'images_total': {'type': 'integer'}, 'canonical_url': {'type': ['string', 'null']}, 'cache_respected': {'type': 'boolean'}, 'json_ld_present': {'type': 'boolean'}, 'missing_signals': {'type': 'array'}, 'title_untrusted': {'type': ['string', 'null']}, 'images_missing_alt': {'type': 'integer'}, 'external_link_count': {'type': 'integer'}, 'internal_link_count': {'type': 'integer'}, 'meta_description_untrusted': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'sigma_rule_lookupArguments', 'required': ['rule_id'], 'properties': {'rule_id': {'type': 'string', 'title': 'Rule Id', 'maxLength': 50, 'description': "Sigma rule UUID (RFC 4122, 36 chars, hyphenated). Example: '195e1b9d-bfc2-4ffa-ab4e-35aef69815f8'. Obtained from the REST sigma_rule_search endpoint or external SIEM correlation."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['rule'], 'properties': {'rule': {'type': 'object'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'ssl_checkArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to check SSL/TLS certificate for (e.g. 'example.com', 'api.stripe.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'san': {'type': 'array'}, 'chain': {'type': 'array'}, 'grade': {'type': 'string'}, 'valid': {'type': 'boolean'}, 'cipher': {'type': 'object'}, 'domain': {'type': 'string'}, 'issuer': {'type': 'string'}, 'subject': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'protocol': {'type': 'string'}, 'warnings': {'type': 'array'}, 'not_after': {'type': 'string'}, 'next_calls': {'type': ['array', 'null']}, 'not_before': {'type': 'string'}, 'serial_number': {'type': 'string'}, 'days_remaining': {'type': ['integer', 'null']}, 'validation_errors': {'type': 'array'}, 'signature_algorithm': {'type': ['string', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'subdomain_enumArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Root domain to enumerate subdomains for (e.g. 'example.com', 'tesla.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'count': {'type': 'integer'}, 'domain': {'type': 'string'}, 'sources': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'warnings': {'type': 'array'}, 'next_calls': {'type': ['array', 'null']}, 'subdomains': {'type': 'array'}, 'crtsh_status': {'type': 'string'}, 'found_via_crtsh': {'type': 'integer'}, 'wildcard_status': {'type': 'string'}, 'found_via_wordlist': {'type': 'integer'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'tech_fingerprintArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to fingerprint (e.g. 'example.com', 'shopify.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'count': {'type': 'integer'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'categories': {'type': 'object'}, 'next_calls': {'type': ['array', 'null']}, 'technologies': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'tech_stack_cve_auditArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'maxLength': 253, 'minLength': 1, 'description': "Target domain to fingerprint and CVE-audit (e.g. 'example.com'). IPs and internal hostnames are rejected."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'technologies', 'summary'], 'properties': {'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'cves_by_tech': {'type': 'object'}, 'kev_findings': {'type': 'array'}, 'technologies': {'type': 'object'}, 'exploit_findings': {'type': 'array'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'threat_intelArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to check for threats (e.g. 'suspicious-site.com', 'example.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'urlhaus_status'], 'properties': {'tags': {'type': 'array'}, 'urls': {'type': 'array'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'url_count': {'type': 'integer'}, 'next_calls': {'type': ['array', 'null']}, 'urls_online': {'type': 'integer'}, 'threat_types': {'type': 'array'}, 'urlhaus_status': {'type': 'string'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'threat_reportArguments', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'title': 'Ip', 'description': "Public IPv4 or IPv6 address to investigate (e.g. '8.8.8.8', '1.1.1.1'). Private/reserved IPs are rejected."}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string'}, 'asn': {'type': 'object'}, 'ptr': {'type': ['string', 'null']}, 'shodan': {'type': 'object'}, 'country': {'type': ['string', 'null']}, 'firehol': {'type': ['object', 'null']}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'asn_name': {'type': ['string', 'null']}, 'tor_exit': {'type': 'boolean'}, 'abuseipdb': {'type': 'object'}, 'enrichment': {'type': 'object'}, 'next_calls': {'type': ['array', 'null']}, 'risk_score': {'type': 'integer'}, 'threat_level': {'type': 'string'}, 'is_datacenter': {'type': 'boolean'}, 'cloud_provider': {'type': ['string', 'null']}, 'severity_label': {'type': 'string'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'username_lookupArguments', 'required': ['username'], 'properties': {'username': {'type': 'string', 'title': 'Username', 'description': "Username string to search across platforms, without @ prefix (e.g. 'torvalds', 'johndoe', 'elonmusk')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': [], 'properties': {'error': {'type': ['string', 'null']}, 'results': {'type': 'array'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'username': {'type': 'string'}, 'next_calls': {'type': ['array', 'null']}, 'found_count': {'type': 'integer'}, 'checked_count': {'type': 'integer'}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'wayback_lookupArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Domain to look up in web archives (e.g. 'example.com', 'archive.org')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string'}, 'status': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'warnings': {'type': 'array'}, 'last_seen': {'type': ['string', 'null']}, 'snapshots': {'type': 'array'}, 'first_seen': {'type': ['string', 'null']}, 'next_calls': {'type': ['array', 'null']}, 'archive_url': {'type': 'string'}, 'years_online': {'type': ['integer', 'null']}, 'total_snapshots': {'type': ['integer', 'null']}}}}}
Schéma d’entrée
{'type': 'object', 'title': 'whois_lookupArguments', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'description': "Root domain to query WHOIS for (e.g. 'example.com', 'github.com')"}}}
Schéma de sortie
{'type': 'object', 'required': ['result'], 'properties': {'result': {'type': 'object', 'required': ['domain', 'whois'], 'properties': {'whois': {'type': 'object'}, 'domain': {'type': 'string'}, 'summary': {'type': 'string'}, 'verdict': {'type': ['object', 'null']}, 'next_calls': {'type': ['array', 'null']}}}}}
Modifications récentes des outils
Serveurs MCP similaires
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
CipherHUB Cryptography Toolkit
Provides cryptographic operations including key generation, encryption, signing, verification, hashing, certificates, CMS, COSE, …