MCP server for unified threat intelligence - AlienVault OTX, AbuseIPDB, GreyNoise, and abuse.ch feeds
The server provides 17 threat intelligence tools with consistent naming patterns and adequate parameter schemas. All tools are properly registered with input schemas and descriptions. However, descriptions are brief (averaging ~100 chars), several lack context for when to use them vs alternatives, parameters have minimal constraints, and output schemas are not documented. No error handling guidance is provided. The tool set is well-scoped for threat intel, but falls short of production-grade polish.
Check IP reputation on AbuseIPDB - returns abuse confidence score and recent reports
Get active botnet C2 servers from Feodo Tracker (Emotet, Dridex, QakBot, etc.)
Check if an IP is internet background noise or a targeted threat (GreyNoise)
Look up malware sample by hash on MalwareBazaar
Get recent malware samples from MalwareBazaar
Get malware samples by tag (e.g., 'emotet', 'cobalt-strike', 'ransomware')
Output schemas are not documented anywhere in the tool definitions. LLMs cannot plan downstream calls or understand what fields to expect from responses. For example, threatintel_lookup_ip returns data from multiple sources (OTX, AbuseIPDB, GreyNoise, Feodo) but the response structure is opaque to the agent.
Descriptions are minimal and generic. Many lack context about when to use the tool vs. similar alternatives (e.g., threatintel_lookup_ip vs. abuseipdb_check vs. greynoise_ip are all IP lookups but serve different purposes). Baseline expectation is 50-200 chars with explicit use-case framing; most descriptions here are 50-70 chars.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 69 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Get recent threat intelligence pulses from AlienVault OTX
Search OTX pulses by keyword (malware name, campaign, threat actor)
Get recent IOCs from ThreatFox (C2 servers, malware infrastructure)
Search ThreatFox for IOCs by malware family or tag
Look up a domain across threat intelligence sources (OTX, URLhaus)
Look up a file hash (MD5, SHA1, SHA256) across threat intelligence sources (OTX, MalwareBazaar)
Look up an IP address across all configured threat intelligence sources (OTX, AbuseIPDB, GreyNoise, Feodo Tracker)
Look up a URL for malware/phishing indicators (OTX, URLhaus)
Check which threat intelligence sources are configured. Currently available: otx, abuseipdb, greynoise, abusech, feodo
Check if a URL or domain is distributing malware (URLhaus)
Get recent malware URLs from URLhaus
Parameters lack constraints and validation hints. For example, 'limit' parameters in otx_get_pulses, urlhaus_recent, malwarebazaar_recent have no min/max bounds. maxAgeInDays in abuseipdb_check states 'default: 90, max: 365' in the description but provides no enum or constraint in the schema. IP and hash parameters have no regex or format validation hints.
No error handling or recovery guidance. The code includes basic error catching (e.g., 'API error {status}: {text}'), but the tool definitions provide no guidance to the LLM on what errors are possible, when to retry, or how to recover. For instance, if an API key is missing or rate-limited, the agent has no recovery strategy.
Tool naming mixes verb_noun (threatintel_lookup_ip, otx_search_pulses) with no_verb patterns (feodo_tracker, urlhaus_lookup). Consistency matters for LLM pattern recognition. Additionally, some names are redundant: 'threatintel_lookup_*' vs 'abuseipdb_check', 'otx_search_*' overlap in intent but use different verbs ('lookup' vs 'check' vs 'search'). This may confuse LLM selection logic.
Result-limiting and pagination are not addressed. otx_get_pulses, urlhaus_recent, malwarebazaar_recent accept a 'limit' but there is no documented max, no total count in responses, and no cursor for pagination. Large threat intel feeds can easily exceed context windows; the tool interface offers no safe pagination strategy.