69
/ 100
1 month ago
glama

mcp-threatintel

A threat intelligence MCP server for Claude Code that enables lookup of IOCs, threat feeds, breached credentials, CVEs, and dark web data.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 5 credentials: ABUSECH_API_KEY, OTX_API_KEY, HIBP_API_KEY, LEAKCHECK_API_KEY, MCP_THREATINTEL_AUTH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configFASTMCP_PORT
configMCP_PORT
configDB_PATH
🔐 secretABUSECH_API_KEY[abuse.ch](https://abuse.ch/) (URLhaus, MalwareBazaar, ThreatFox, Feodo) Malware URLs, hashes, C2s, botnet IPs Free
🔐 secretOTX_API_KEY[AlienVault OTX](https://otx.alienvault.com/) Community threat pulses, IOC enrichment Free
🔐 secretHIBP_API_KEY[HIBP Email](https://haveibeenpwned.com/API/Key) Email breach lookup $4.50/mo
🔐 secretLEAKCHECK_API_KEY[LeakCheck](https://leakcheck.io/) Dark web breach data (7B+ records) $10/mo
🔐 secretMCP_THREATINTEL_AUTH_TOKENOptional bearer-token auth: set (generate with openssl rand -hex 32) and every HTTP client must send Authorization: Bearer <token>. Unset = no auth (single-host trusted-boundary default).
configFASTMCP_HOST
configMCP_HOST
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/pete-builds-mcp-threatintel-1db1or)](https://m8ven.ai/mcp/pete-builds-mcp-threatintel-1db1or)
commit: d400e733b9aa5d14940efb27d43cc57c101057d8
code hash: 44f5ca2b8f2098b899353f2ff98c75265607e693d364683d051b80f44368da58
verified: 6/21/2026, 10:22:25 AM
view raw JSON →