Skip to main content
Glama
FoundryNet

Cybersecurity Threat Intelligence MCP

by FoundryNet

Cybersecurity Threat Intelligence MCP

Cybersecurity threat intelligence for AI agents — CVE search enriched with EPSS exploit-likelihood + CISA known-exploited (KEV) status, plus live IP/domain reputation and a real-time threat feed.

Part of the FoundryNet Data Network. Every result carries verifiable provenance so a buyer can confirm it was produced by this server, unaltered. See also: gov-contracts-mcp, brand-intel-mcp, patent-intel-mcp, financial-signals-mcp, weather-intel-mcp, compliance-mcp.

Connect

  • MCP endpoint (Streamable HTTP): https://cyber-intel-mcp-production.up.railway.app/mcp

  • Registry: io.github.FoundryNet/cyber-intel-mcp

  • Agent card: https://cyber-intel-mcp-production.up.railway.app/.well-known/agent-card.json

Claude Desktop / Cursor / Claude Code

claude mcp add --transport http cyber-intel https://cyber-intel-mcp-production.up.railway.app/mcp
{ "mcpServers": { "cyber-intel": { "url": "https://cyber-intel-mcp-production.up.railway.app/mcp" } } }

Related MCP server: contrastapi

Tools

Tool

Price

What it does

search_cve

$0.01

CVE search by severity, CVSS, EPSS, attack vector, KEV status

cve_detail

free

Full CVE — CVSS breakdown, EPSS, KEV, CWE, affected products, refs

check_ip

$0.01

IP reputation (AbuseIPDB + OTX) — abuse score, threat type, pulses

check_domain

$0.01

Domain threat indicators (OTX)

vulnerability_scan

$0.05

All CVEs for a product, sorted by EPSS — "should I worry about this dependency?"

threat_feed

$0.01

Recent threat indicators (IPs/domains/hashes/URLs)

brief_summary

$0.50

Sample of the day's curated threat brief (headline findings)

daily_brief

$15

Full curated daily threat brief — top exploited CVEs, KEV adds, active indicators

mint_info

free

FoundryNet Data Network + provenance/attestation info

Free tier: 25 paid-tool queries/day per agent. Then metered: the tool returns an HTTP-402 with a payment request — settle it, re-call with the same args plus payment_tx=<reference>. An Authorization: Bearer fnet_… key bypasses the paywall.

The edge: EPSS-ranked vulnerabilities

Raw CVE counts are noise. Every vulnerability here carries its EPSS score (the probability it'll be exploited) and a CISA KEV flag (whether it's actively exploited). vulnerability_scan sorts a product's CVEs by exploit likelihood — so an agent triaging a dependency sees what actually matters first.

Sources

Every 6 hours: NVD (CVEs, keyless + throttled), EPSS (exploit probability), CISA KEV (known-exploited catalog), GitHub Advisories. Live on demand: AbuseIPDB (IP reputation) + AlienVault OTX (IP/domain/pulse indicators). Stored in a standalone Supabase project.

Discovery

MCP registry: io.github.FoundryNet/cyber-intel-mcp

Built by FoundryNet · forge@foundrynet.io

Live network activity

Live feed: mint.foundrynet.io/feed
Real-time verified work across 17 servers and autonomous agents, with verifiable provenance on every result.

A
license - permissive license
-
quality - not tested
A
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    A
    quality
    -
    maintenance
    Provides real-time threat intelligence including IP risk scores, CVE lookups, and malware hash analysis without requiring an API key. It enables users to monitor active threats, predict CISA KEV additions, and detect pre-attack infrastructure staging through natural language.
    Last updated
    8
  • A
    license
    A
    quality
    A
    maintenance
    Security intelligence API for AI models. CVE lookup with EPSS/KEV, domain recon (DNS, WHOIS, SSL, subdomains, WAF), and code security checks (secrets, injection, headers). 16 tools, no API key required.
    Last updated
    55
    32
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Provides live CVE data from NVD and EPSS without API key, enabling AI assistants to look up CVSS scores, search vulnerabilities, and check product CVEs.
    Last updated
    3
    MIT

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/FoundryNet/cyber-intel-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server