MCP server for OSINT and indicator of compromise (IoC) lookups using VirusTotal, Shodan, AbuseIPDB, AlienVault OTX, and URLhaus APIs
IoCMCP server provides 8 tools for OSINT lookups (VirusTotal and Shodan APIs). Tools have basic descriptions and visible parameter schemas, but significant quality gaps prevent a higher score. All tools follow a consistent pattern and accept API keys as parameters (critical security issue). Descriptions are present but generic and lack actionable context for LLM selection. Parameter descriptions are minimal (1-5 words each). No output schemas are documented. Error handling returns structured dicts but lacks guidance for recovery or retry strategy. The server uses FastMCP with STDIO transport, which is not remotely accessible.
Look up domain information using the Shodan API.
Look up exploit information using the Shodan Exploits API.
Search hosts using the Shodan API.
Look up IP address information using the Shodan API.
Look up domain information using the VirusTotal API.
Look up file information using the VirusTotal API.
API keys exposed as tool parameters
No output schema documentation
Parameter descriptions are minimal (1-5 words) and lack context
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 20 | - | v1 |
Look up IP address information using the VirusTotal API.
Look up URL information using the VirusTotal API.
Tool descriptions are generic and do not explain when to use each tool vs alternatives
Error handling does not guide LLM on recovery actions
No pagination or result limiting mechanism for list/search results
shodan_exploit_lookup naming is ambiguous, does not clearly indicate it searches exploits by CVE