A lightweight MCP service framework that packages and exposes tools for threat intelligence agents, enabling automated analysis and easy integration.
The CTI MCP server provides 7 threat intelligence lookup tools with consistent naming (verb_noun pattern: *_report) and reasonable descriptions. However, there are significant gaps in parameter validation, output schema documentation, and error handling. All tools follow a simple, read-only pattern (IP/domain lookups) which limits composition concerns but also means limited complexity. Descriptions are adequate (100-150 chars) but could be more specific about return structures and failure modes. Parameter schemas are present for all tools (ip/domain strings, optional filters) but lack explicit validation constraints (regex, format). No tool annotations (readOnlyHint, idempotentHint) are visible despite all being read-only operations. Error handling is minimal, no guidance on quota/rate-limit recovery, invalid input, or API failures.
AbuseIPDB v2 check endpoint (full JSON). Given an IP address, retrieves reputation and (optionally) recent reports. Cost/quota may apply. Use only when necessary.
Kaspersky OpenTIP domain lookup (raw JSON). Cost/quota may apply. Use only when necessary.
Kaspersky OpenTIP IP lookup (raw JSON). Cost/quota may apply. Use only when necessary.
AlienVault OTX domain indicator report (general). Returns full OTX JSON including pulses, reputation, passive DNS, etc.
AlienVault OTX IPv4 indicator report (general). Returns full OTX JSON including pulses, reputation, geo, etc.
VirusTotal v3 domain report (full JSON). given a domain, retrieves the pertinent analysis report including threat reputation and context produced by 70+ antivirus products/blocklists and a myriad of other security tools and datasets. Cost/quota may apply. Use only when necessary.
No output schemas documented. Tools return 'full JSON' from external APIs without documented field structure. LLMs cannot plan downstream extraction or composition.
Parameter validation constraints missing. Descriptions say 'IP address' and 'domain' but lack regex patterns, format specifications, or explicit validation rules (e.g., 'valid IPv4/IPv6 dotted notation').
No error recovery guidance. Descriptions mention 'cost/quota may apply' but tools provide no guidance on handling quota exhaustion, rate limits, or API errors. Agents cannot distinguish retryable from fatal failures.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 57 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 49 | - | v1 |
VirusTotal v3 IP report (full JSON). given an IP address, retrieves the pertinent analysis report including threat reputation and context produced by 70+ antivirus products/blocklists and a myriad of other security tools and datasets. Cost/quota may apply. Use only when necessary.
Tool annotations absent. All tools are read-only and idempotent (no side effects) but lack readOnlyHint or idempotentHint in registration. This forces LLMs to infer safety from descriptions.
Optional parameters (max_age_days, verbose in abuseipdb) lack default values and usage guidance. Unclear whether LLMs should always pass them, what happens if omitted, or what the defaults are.
No chaining metadata. Tools return 'full JSON' but do not explicitly state which fields are returned (e.g., threat_score, country, ASN). Downstream tools (e.g., a 'create_incident' tool) cannot reliably extract and pass forward results.