{
  "markdown": "# Cybersecurity Threat Intelligence MCP\n\n**Cybersecurity threat intelligence for AI agents** — CVE search enriched with\nEPSS exploit-likelihood + CISA known-exploited (KEV) status, plus live IP/domain\nreputation and a real-time threat feed.\n\n> Part of the **FoundryNet Data Network**. Every result carries verifiable\n> provenance so a buyer can confirm it was produced by this server, unaltered.\n> See also: **gov-contracts-mcp**, **brand-intel-mcp**, **patent-intel-mcp**,\n> **financial-signals-mcp**, **weather-intel-mcp**, **compliance-mcp**.\n\n## Connect\n\n- **MCP endpoint** (Streamable HTTP): `https://cyber-intel-mcp-production.up.railway.app/mcp`\n- **Registry:** `io.github.FoundryNet/cyber-intel-mcp`\n- **Agent card:** `https://cyber-intel-mcp-production.up.railway.app/.well-known/agent-card.json`\n\n### Claude Desktop / Cursor / Claude Code\n\n```bash\nclaude mcp add --transport http cyber-intel https://cyber-intel-mcp-production.up.railway.app/mcp\n```\n\n```json\n{ \"mcpServers\": { \"cyber-intel\": { \"url\": \"https://cyber-intel-mcp-production.up.railway.app/mcp\" } } }\n```\n\n## Tools\n\n| Tool | Price | What it does |\n|---|---|---|\n| `search_cve` | $0.01 | CVE search by severity, CVSS, **EPSS**, attack vector, KEV status |\n| `cve_detail` | **free** | Full CVE — CVSS breakdown, EPSS, KEV, CWE, affected products, refs |\n| `check_ip` | $0.01 | IP reputation (AbuseIPDB + OTX) — abuse score, threat type, pulses |\n| `check_domain` | $0.01 | Domain threat indicators (OTX) |\n| `vulnerability_scan` | $0.05 | All CVEs for a product, **sorted by EPSS** — \"should I worry about this dependency?\" |\n| `threat_feed` | $0.01 | Recent threat indicators (IPs/domains/hashes/URLs) |\n| `brief_summary` | $0.50 | Sample of the day's curated threat brief (headline findings) |\n| `daily_brief` | $15 | Full curated daily threat brief — top exploited CVEs, KEV adds, active indicators |\n| `mint_info` | **free** | FoundryNet Data Network + provenance/attestation info |\n\n**Free tier:** 25 paid-tool queries/day per agent. Then metered: the tool returns an\nHTTP-402 with a payment request — settle it, re-call with the same args plus\n`payment_tx=<reference>`. An `Authorization: Bearer fnet_…` key bypasses the paywall.\n\n## The edge: EPSS-ranked vulnerabilities\n\nRaw CVE counts are noise. Every vulnerability here carries its **EPSS score** (the\nprobability it'll be exploited) and a **CISA KEV** flag (whether it's *actively*\nexploited). `vulnerability_scan` sorts a product's CVEs by exploit likelihood — so\nan agent triaging a dependency sees what actually matters first.\n\n## Sources\n\nEvery 6 hours: **NVD** (CVEs, keyless + throttled), **EPSS** (exploit probability),\n**CISA KEV** (known-exploited catalog), **GitHub Advisories**. Live on demand:\n**AbuseIPDB** (IP reputation) + **AlienVault OTX** (IP/domain/pulse indicators).\nStored in a standalone Supabase project.\n\n## Discovery\n\nMCP registry: `io.github.FoundryNet/cyber-intel-mcp`\n\nBuilt by [FoundryNet](https://foundrynet.io?utm_source=github&utm_medium=readme&utm_campaign=cyber-intel-mcp) · forge@foundrynet.io\n\n## Live network activity\n\n**Live feed:** [mint.foundrynet.io/feed](https://mint.foundrynet.io/feed)  \nReal-time verified work across 17 servers and autonomous agents, with verifiable provenance on every result.\n",
  "bytes": 3272,
  "sha": "99e586ba01755dde69da28b4fb9f4bf7f31006d552d0708b84b06c61557b6d41",
  "repo_slug": "foundrynet/cyber-intel-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_foundrynet_cyber_intel_mcp_64e7d470/readme"
}