A Model Context Protocol server for Shodan API queries providing network intelligence and security services including IP lookups, DNS operations, vulnerability intelligence, and device discovery.
The server provides 7 well-structured tools with consistent naming patterns, detailed descriptions, and complete JSON Schema definitions. All tools use action verbs (ip_lookup, shodan_search, cve_lookup, etc.) and descriptions range from 200-400 characters, meeting the production baseline. Input parameters are fully typed with descriptions. However, output schemas are not explicitly documented in the source, only inferred from API responses. No parameter enums are declared, leaving room for input validation improvement. Error handling is present but generic (UserError wrapping). The cves_by_product tool shows good composition with multiple filter options and pagination support.
Search for Common Platform Enumeration (CPE) entries by product name in Shodan's CVEDB. Supports pagination and can return either full CPE details or just the total count. Useful for identifying specific versions and configurations of software and hardware.
Query detailed vulnerability information from Shodan's CVEDB. Returns comprehensive CVE details including CVSS scores (v2/v3), EPSS probability and ranking, KEV status, proposed mitigations, ransomware associations, and affected products (CPEs).
Search for vulnerabilities affecting specific products or CPEs. Supports filtering by KEV status, sorting by EPSS score, date ranges, and pagination. Can search by product name or CPE 2.3 identifier. Returns detailed vulnerability information including severity scores and impact assessments.
Resolve domain names to IP addresses using Shodan's DNS service. Supports batch resolution of multiple hostnames in a single query. Returns IP addresses mapped to their corresponding hostnames.
Retrieve comprehensive information about an IP address, including geolocation, open ports, running services, SSL certificates, hostnames, and cloud provider details if available. Returns service banners and HTTP server information when present.
Output schemas are not documented in tool definitions. The codebase shows that tools wrap Shodan/CVEDB API responses, but the structure of returned objects is not formally declared in the tool schema.
No enum constraints on parameters that accept restricted sets of values. For example, cves_by_product has boolean flags (is_kev, sort_by_epss, count) and date strings without format validation.
Error messages are wrapped generically via UserError but do not provide recovery guidance. For example, 'CVEDB API error' does not suggest next steps or explain why the call failed.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 68 | 2026-07-28+ | v2 |
| 2026-03-09 | C | 66 | - | v1 |
Perform reverse DNS lookups to find hostnames associated with IP addresses. Supports batch lookups of multiple IP addresses in a single query. Returns all known hostnames for each IP address, with clear indication when no hostnames are found.
Search Shodan's database of internet-connected devices. Returns detailed information about matching devices including services, vulnerabilities, and geographic distribution. Supports advanced search filters and returns country-based statistics.
cves_by_product requires either 'cpe23' or 'product' but the parameter descriptions do not explicitly state they are mutually exclusive or which one is preferred.
The formatSslSummary helper in src/helpers.ts and similar output formatters are implementation details not visible in the tool schema. LLMs have no guarantee of the response structure.