Cybersecurity Threat Intelligence MCP
Enables searching and retrieving vulnerability data from the GitHub Advisory Database, including EPSS exploit-likelihood scores and CISA Known Exploited Vulnerabilities status.
Facilitates pay-per-use access to premium features via Solana USDC payments, allowing agents to submit payment transactions to bypass the free tier.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Cybersecurity Threat Intelligence MCPSearch for CVE-2024-3094"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Cybersecurity Threat Intelligence MCP
Cybersecurity threat intelligence for AI agents — CVE search enriched with EPSS exploit-likelihood + CISA known-exploited (KEV) status, plus live IP/domain reputation and a real-time threat feed.
Part of the FoundryNet Data Network. Every result carries verifiable provenance so a buyer can confirm it was produced by this server, unaltered. See also: gov-contracts-mcp, brand-intel-mcp, patent-intel-mcp, financial-signals-mcp, weather-intel-mcp, compliance-mcp.
Connect
MCP endpoint (Streamable HTTP):
https://cyber-intel-mcp-production.up.railway.app/mcpRegistry:
io.github.FoundryNet/cyber-intel-mcpAgent card:
https://cyber-intel-mcp-production.up.railway.app/.well-known/agent-card.json
Claude Desktop / Cursor / Claude Code
claude mcp add --transport http cyber-intel https://cyber-intel-mcp-production.up.railway.app/mcp{ "mcpServers": { "cyber-intel": { "url": "https://cyber-intel-mcp-production.up.railway.app/mcp" } } }Related MCP server: contrastapi
Tools
Tool | Price | What it does |
| $0.01 | CVE search by severity, CVSS, EPSS, attack vector, KEV status |
| free | Full CVE — CVSS breakdown, EPSS, KEV, CWE, affected products, refs |
| $0.01 | IP reputation (AbuseIPDB + OTX) — abuse score, threat type, pulses |
| $0.01 | Domain threat indicators (OTX) |
| $0.05 | All CVEs for a product, sorted by EPSS — "should I worry about this dependency?" |
| $0.01 | Recent threat indicators (IPs/domains/hashes/URLs) |
| $0.50 | Sample of the day's curated threat brief (headline findings) |
| $15 | Full curated daily threat brief — top exploited CVEs, KEV adds, active indicators |
| free | FoundryNet Data Network + provenance/attestation info |
Free tier: 25 paid-tool queries/day per agent. Then metered: the tool returns an
HTTP-402 with a payment request — settle it, re-call with the same args plus
payment_tx=<reference>. An Authorization: Bearer fnet_… key bypasses the paywall.
The edge: EPSS-ranked vulnerabilities
Raw CVE counts are noise. Every vulnerability here carries its EPSS score (the
probability it'll be exploited) and a CISA KEV flag (whether it's actively
exploited). vulnerability_scan sorts a product's CVEs by exploit likelihood — so
an agent triaging a dependency sees what actually matters first.
Sources
Every 6 hours: NVD (CVEs, keyless + throttled), EPSS (exploit probability), CISA KEV (known-exploited catalog), GitHub Advisories. Live on demand: AbuseIPDB (IP reputation) + AlienVault OTX (IP/domain/pulse indicators). Stored in a standalone Supabase project.
Discovery
MCP registry: io.github.FoundryNet/cyber-intel-mcp
Built by FoundryNet · forge@foundrynet.io
Live network activity
Live feed: mint.foundrynet.io/feed
Real-time verified work across 17 servers and autonomous agents, with verifiable provenance on every result.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseAquality-maintenanceProvides real-time threat intelligence including IP risk scores, CVE lookups, and malware hash analysis without requiring an API key. It enables users to monitor active threats, predict CISA KEV additions, and detect pre-attack infrastructure staging through natural language.Last updated8
- AlicenseAqualityAmaintenanceSecurity intelligence API for AI models. CVE lookup with EPSS/KEV, domain recon (DNS, WHOIS, SSL, subdomains, WAF), and code security checks (secrets, injection, headers). 16 tools, no API key required.Last updated5532MIT
- Alicense-qualityDmaintenanceProvides multi-source vulnerability intelligence for AI-powered security operations, combining NVD CVSS, CISA KEV, and EPSS scores without requiring an API key.Last updated1MIT
- AlicenseAqualityCmaintenanceProvides live CVE data from NVD and EPSS without API key, enabling AI assistants to look up CVSS scores, search vulnerabilities, and check product CVEs.Last updated3MIT
Related MCP Connectors
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/FoundryNet/cyber-intel-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server