What this MCP does
Provides domain-level credential exposure counts and limited metadata samples from breaches, infostealers, ULP bundles, and stolen cookies.
Tools
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to check, e.g. example.com. A full URL is accepted and normalized.'}}}
Output schema
{'type': 'object', 'required': ['domain', 'first_indexed_at', 'last_indexed_at', 'breaches_total', 'breaches_month', 'breaches_week', 'cookies_total', 'cookies_month', 'cookies_week', 'stealers_staff_total', 'stealers_staff_month', 'stealers_staff_week', 'stealers_users_total', 'stealers_users_month', 'stealers_users_week', 'heap_staff_total', 'heap_staff_month', 'heap_staff_week', 'heap_users_total', 'heap_users_month', 'heap_users_week'], 'properties': {'domain': {'type': 'string', 'description': 'Normalized domain actually queried. May differ from the input - report this one to the user.'}, 'cookies_week': {'type': ['integer', 'null'], 'description': 'Indexed in last 7d. Subset of cookies_month.'}, 'breaches_week': {'type': ['integer', 'null'], 'description': 'Indexed in last 7d. Subset of breaches_month.'}, 'cookies_month': {'type': ['integer', 'null'], 'description': 'Indexed in last 30d. Subset of cookies_total.'}, 'cookies_total': {'type': ['integer', 'null'], 'description': 'Stolen browser session cookies, indexed all time. Non-zero means session-hijacking risk that a password reset alone does not fix. Cookies are counted here only; they are not included in exposure_samples_for_domain.'}, 'breaches_month': {'type': ['integer', 'null'], 'description': 'Indexed in last 30d. Subset of breaches_total.'}, 'breaches_total': {'type': ['integer', 'null'], 'description': 'Records from known breach incidents, indexed all time.'}, 'heap_staff_week': {'type': ['integer', 'null'], 'description': 'Indexed in last 7d. Subset of heap_staff_month.'}, 'heap_users_week': {'type': ['integer', 'null'], 'description': 'Indexed in last 7d. Subset of heap_users_month.'}, 'last_indexed_at': {'type': ['string', 'null'], 'description': "Date-time (format YYYY-MM-DD HH:MM:SS, UTC) when AlertsBar last indexed a record for this domain. This is the domain's 'last updated' date and the only reliable freshness signal - samples are random and say nothing about recency. Say 'newly indexed', never 'newly leaked'. Null if the domain is not in the index."}, 'first_indexed_at': {'type': ['string', 'null'], 'description': 'Date-time (format YYYY-MM-DD HH:MM:SS, UTC) when AlertsBar first indexed a record for this domain. Indexation date, not incident date - never say the domain was first leaked then. Null if the domain is not in the index.'}, 'heap_staff_month': {'type': ['integer', 'null'], 'description': 'Indexed in last 30d. Subset of heap_staff_total.'}, 'heap_staff_total': {'type': ['integer', 'null'], 'description': 'Staff logins in unattributed heap of ULP (Url,Login,Password) bundles - no linkable breach, device or leak date. Credentials circulating in the wild.'}, 'heap_users_month': {'type': ['integer', 'null'], 'description': 'Indexed in last 30d. Subset of heap_users_total.'}, 'heap_users_total': {'type': ['integer', 'null'], 'description': 'Customer logins in unattributed heap of ULP (Url,Login,Password) bundles - no linkable breach, device or leak date.'}, 'stealers_staff_week': {'type': ['integer', 'null'], 'description': 'Indexed in last 7d. Subset of stealers_staff_month.'}, 'stealers_users_week': {'type': ['integer', 'null'], 'description': 'Indexed in last 7d. Subset of stealers_users_month.'}, 'stealers_staff_month': {'type': ['integer', 'null'], 'description': 'Indexed in last 30d. Subset of stealers_staff_total.'}, 'stealers_staff_total': {'type': ['integer', 'null'], 'description': "Staff logins from infostealer-infected devices, indexed all time. Implies a compromised machine, not just a leaked password. The credentials may be for any site, not only this domain's own systems."}, 'stealers_users_month': {'type': ['integer', 'null'], 'description': 'Indexed in last 30d. Subset of stealers_users_total.'}, 'stealers_users_total': {'type': ['integer', 'null'], 'description': "Customer logins for this domain's site from infostealer-infected devices, indexed all time."}}, 'description': "Counters as of the last daily rebuild. Windows count back from that rebuild, not from request time. Every _total/_month/_week and both dates are by INDEXATION date, not by when the leak or infection happened. All counters and both dates are null when the domain is not in the index (no data - not the same as clean). staff = login is an address at this domain; users = login belongs elsewhere but the record is for this domain's site (customers). For public mailbox providers (e.g. gmail.com, ukr.net) staff means holders of mailboxes at that domain, NOT employees, and the numbers can be huge - do not present them as an employee compromise. Placeholder or test domains (e.g. example.com) also produce staff records that belong to nobody in particular."}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to check, e.g. example.com. A full URL is accepted and normalized, same rules as exposure_counts_for_domain.'}}}
Output schema
{'type': 'object', 'required': ['domain', 'records'], 'properties': {'domain': {'type': 'string', 'description': 'Normalized domain actually queried. May differ from the input - report this one to the user.'}, 'records': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'url', 'login', 'source', 'estimated_incident_at', 'indexed_at'], 'properties': {'url': {'type': 'string', 'description': "The URL, hostname or app identifier the captured credentials were for, shown as captured and NOT normalized: it may lack a scheme, include a path, be an android:// app id, a localhost/dev address or a placeholder host. For *_users it is normally a system of the queried organisation. For *_staff it is often a THIRD-PARTY site the employee signed in to, not the organisation's own system - do not say the organisation's system was breached unless the host belongs to the queried domain."}, 'type': {'enum': ['stealers_users', 'stealers_staff', 'heap_users', 'heap_staff', 'breaches'], 'type': 'string', 'description': "Which source this record came from. stealers_* = credentials taken off a specific infostealer-infected device, so a machine is compromised, not just a password. heap_* = credentials found in an unattributed ULP (Url,Login,Password) bundle, with no linkable incident, device or date. breaches = a record from a known breach incident. *_staff = the login was an address at this domain; *_users = the login belonged elsewhere but the record targets this domain's site (customer). For public mailbox providers (gmail.com, ukr.net) *_staff means a mailbox holder, not an employee. Cookies never appear here."}, 'login': {'type': 'string', 'description': "The captured login with its LOCAL PART REDACTED, e.g. ...@company.com - only the part after @ is real, and no address, name or individual is identified. This is what ties the record to the queried domain: for *_staff the domain part equals the queried domain, meaning an address at this domain was found with credentials for url; for *_users it is usually an outside provider (gmail.com and such), meaning an external person's credentials for this organisation's site were taken. For stealers_users the part after @ can also be a bare host label (e.g. ...@local) or missing entirely (just '...'), and letter case is as captured. Use it to explain WHY a record belongs to this domain. The dots are a redaction, NOT a wildcard: this is one single account, never all addresses at that domain. Full logins are not available through MCP at all - they require domain ownership verification and an API key."}, 'source': {'type': 'integer', 'description': 'Opaque internal id of the source feed or breach inside AlertsBar, shared by every record that came from it - it identifies the feed, not the individual row. It is NOT a name: do not read a stealer family, breach name, vendor or feed out of it, and never guess what it stands for. Its only purpose is follow-up - the user can quote it to AlertsBar support or use it against the REST API to pull the full record. Show it verbatim as a reference id when the user wants to investigate a specific record further, and otherwise leave it out of the summary.'}, 'indexed_at': {'type': 'integer', 'description': "Unix seconds (UTC). When AlertsBar indexed this record. Always a fact, unlike estimated_incident_at. A recent indexed_at with an older estimated_incident_at means a long-standing compromise only just discovered - say 'newly discovered', never 'newly leaked'. Many breach records share one identical indexed_at because they were bulk-imported."}, 'estimated_incident_at': {'type': ['integer', 'null'], 'description': "Unix seconds or null, and its meaning follows type. stealers_*: ESTIMATED infection date - an estimate, so always say 'around' or 'estimated'. breaches: the date the breach was PUBLISHED, which is later than when it happened - say 'published', never 'happened'. heap_*: always null (unknown) - never render it as a date, say the leak date is unknown."}}}, 'description': "A random subset of up to 20 records per type, listed by indexed_at descending inside this response. NOT the newest records: a recent or old indexed_at here says nothing about the domain's overall recency - use last_indexed_at from exposure_counts_for_domain. Capped server-side; an empty array means nothing is indexed for this domain."}}, 'description': "A random capped sample of exposure records. Metadata only - no credentials of any kind. This is a SAMPLE, never the full set: the number of records here says nothing about the true volume, which only exposure_counts_for_domain reports. Never describe the count of records in this response as the number of exposures, and never infer how recent the domain's exposure is from this list."}
Recent tool changes
Similar MCP servers
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…