MCP Server

Scry

ai.tunnelmind/scry
Data & Analytics Security Unavailable MCP 2026-07-28

What this MCP does

Provides IPv4 threat-intelligence lookups and aggregate attacker-observation data, including campaigns, protocols, countries, ASNs, and activity trends.

scry_asn
Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.
Input schema
{'type': 'object', 'required': ['asn'], 'properties': {'asn': {'type': 'string'}, 'since_ms': {'type': 'integer'}}, 'additionalProperties': False}
scry_campaign
Single campaign detail by id (format: c[0-9a-f]{15}).
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'pattern': '^c[0-9a-f]{15}$'}}, 'additionalProperties': False}
scry_campaigns
Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history.
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1}, 'include_inactive': {'type': 'boolean'}}, 'additionalProperties': False}
scry_check
Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last observed, observation count, protocols and ports targeted, ASN, country, category (actor/scanner/not_observed), and confidence_bucket (low/medium/high). Use when an agent needs IP triage, hostility assessment, or risk signaling. Do NOT use for raw payloads (never exposed) or IPv6 (corpus is v4-only at v0.1).
Input schema
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'description': "IPv4 address (e.g. '8.8.8.8')"}}, 'additionalProperties': False}
scry_check_bulk
Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP.
Input schema
{'type': 'object', 'required': ['ips'], 'properties': {'ips': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 100, 'minItems': 1}}, 'additionalProperties': False}
scry_country
Roll-up of corpus activity by ISO country code. Same shape as scry_asn.
Input schema
{'type': 'object', 'required': ['country'], 'properties': {'country': {'type': 'string', 'pattern': '^[A-Za-z]{2}$'}, 'since_ms': {'type': 'integer'}}, 'additionalProperties': False}
scry_recent
Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms.
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 500, 'minimum': 1}, 'country': {'type': 'string', 'pattern': '^[A-Za-z]{2}$'}, 'protocol': {'type': 'string'}, 'since_ms': {'type': 'integer'}, 'include_noise': {'type': 'boolean'}}, 'additionalProperties': False}
scry_stats
Returns aggregate Scry corpus telemetry: total observation count, distinct source IPs, first/last observation timestamps, last-24h activity, and per-protocol breakdowns. Useful as a liveness/density check before issuing per-IP queries — lets an agent decide whether the corpus has enough data to be authoritative. Use this tool when: - An agent is planning a multi-step investigation and wants to know if Scry has corpus density worth querying. - You want a 'corpus health' signal in a dashboard or report. Do NOT use this tool when: - You want details about a specific IP — use `scry_check`. - You want sensor fleet size or node identities — never exposed at any tier. Inputs: none. Returns: total_observations, distinct_source_ips, first_seen_ms, last_seen_ms, observations_last_24h, distinct_source_ips_last_24h, by_protocol, as_of_ms. Cost: free, anonymous, rate-limited. Latency: <100ms typical.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
scry_timeseries
Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling.
Input schema
{'type': 'object', 'properties': {'bucket': {'enum': ['minute', 'hour', 'day'], 'type': 'string'}, 'since_ms': {'type': 'integer'}, 'until_ms': {'type': 'integer'}}, 'additionalProperties': False}
scry_tool
Single tool detail by 16-char hex id from scry_tools.
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'pattern': '^[0-9a-f]{16}$'}}, 'additionalProperties': False}
scry_tools
List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors.
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1}, 'protocol': {'type': 'string'}, 'since_ms': {'type': 'integer'}}, 'additionalProperties': False}
scry_top
Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1}, 'since_ms': {'type': 'integer'}, 'dimension': {'enum': ['asn', 'country', 'protocol', 'port'], 'type': 'string'}, 'include_noise': {'type': 'boolean'}}, 'additionalProperties': False}
Added
scry_recent
Sept. 17, 2026, 7:57 a.m.
Added
scry_campaign
Sept. 17, 2026, 7:57 a.m.
Added
scry_campaigns
Sept. 17, 2026, 7:57 a.m.
Added
scry_tool
Sept. 17, 2026, 7:57 a.m.
Added
scry_tools
Sept. 17, 2026, 7:57 a.m.
Added
scry_country
Sept. 17, 2026, 7:57 a.m.
Added
scry_asn
Sept. 17, 2026, 7:57 a.m.
Added
scry_timeseries
Sept. 17, 2026, 7:57 a.m.
Added
scry_top
Sept. 17, 2026, 7:57 a.m.
Added
scry_check_bulk
Sept. 17, 2026, 7:57 a.m.
Added
scry_check
Sept. 17, 2026, 7:57 a.m.
Added
scry_stats
Sept. 17, 2026, 7:57 a.m.

Crypto Bot Audit + Market Data (x402 paid)

io.github.kaminariouji/x402-audit-agent

Audits crypto bot source code and provides paid crypto market, token, gas, stablecoin, and DeFi TVL data.

TunnelMind Data API

ai.tunnelmind/data

Aggregates web, routing, supply-chain, tracker, threat, and agent-registry intelligence into risk verdicts, evidence, receipts, a…

Polyform

org.polyform/polyform

Offers pay-per-call APIs for economic, financial, geographic, healthcare, domain, email, sanctions, blockchain, and business risk…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

SYNTHORA x402 Intelligence Mesh

com.hergertsynthora/synthora-x402

Delivers paid intelligence on markets, crypto, prediction markets, maritime and space risks, domain and wallet exposure, sanction…

Satoshidata Wallet Intel

io.github.wrbtc/wallet-intelligence

Provides Bitcoin wallet intelligence, address labels, trust and risk signals, transaction verification, entity activity, fees, me…

Cloudflare Radar

io.github.pipeworx-io/cloudflare-radar

Provides Cloudflare Radar internet observatory data on DDoS attacks, BGP leaks, domain popularity, internet quality, and traffic …