A cybersecurity-focused MCP server that provides threat intelligence and vulnerability research tools. Integrates with NVD, VirusTotal, AbuseIPDB, Shodan, and MITRE ATT&CK.
This MCP server exhibits significant gaps across naming, description completeness, schema formalization, and output documentation. While all 8 tools are READ_ONLY and have brief descriptions, they lack the rigor expected of production-grade agent tooling. Tool names are adequate but not optimally action-oriented. Descriptions exist but are often vague about prerequisites, return structures, and error recovery paths. Critically, no input schemas or output schemas are visible in the provided source code, only high-level descriptions in the tool registry. Parameter definitions reference types (string, integer) but lack validation constraints, format specifications, or enum constraints. The server processes external APIs (NVD, VirusTotal, AbuseIPDB, Shodan, MITRE, MalwareBazaar, Hybrid Analysis) but does not document expected error conditions or recovery guidance. No tool includes dry-run, confirmation, or idempotency hints. The frontend React code shows tool invocation but not the actual schema definitions or response validation.
Query AbuseIPDB for IP reputation data. Returns abuse confidence score, total reports, usage type, and country information.
Perform deep enrichment on an IP address using Shodan. Discovers open ports, running services, and technologies, then cross-references services with NVD to identify related CVEs.
Query the MITRE ATT&CK framework for detailed information about an attack technique. Returns technique description, tactics, detection methods, and mitigation strategies.
Query the NVD (National Vulnerability Database) for detailed information about a specific CVE ID. Returns vulnerability details, CVSS scores, affected products, and references.
Check an Indicator of Compromise (IOC) against VirusTotal. Supports IP addresses, domains, URLs, and file hashes. Returns detection stats and vendor verdicts.
No visible JSON Schema definitions for tool inputs. All 8 tools show parameter type hints (string, integer) but lack formal JSON Schema with properties, required arrays, constraints, and pattern definitions. Code references 'Input: {...}' inline but does not show full schema registration with jsonschema validation or constraint enforcement.
No output schema documentation. Tools return data from external APIs (NVD, VirusTotal, MITRE ATT&CK, MalwareBazaar, Hybrid Analysis) but no schema defines expected response fields, types, pagination structure, or error formats. LLMs cannot plan downstream tool chains or extract required data reliably.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 47 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 56 | - | v1 |
Search MalwareBazaar for malware samples matching a family tag. Returns a table of matching samples including SHA-256 hashes, file names, malware family signatures, and first-seen dates.
Search the NVD for CVEs affecting a specific software product and version. Useful for vulnerability assessments and patch management.
Fetch public malware sandbox data and generate an AI-powered threat profile report. Queries MalwareBazaar and/or Hybrid Analysis for an existing sandbox report, then uses GPT-4o to produce a structured Markdown threat profile with behavior summary, MITRE ATT&CK mapping, IoCs, risk score, and remediation steps.
Descriptions lack prerequisite hints and error recovery guidance. E.g., 'lookup_cve' states 'Query the NVD' but does not explain: What happens if CVE_ID is invalid? How many results? What fields are returned? Should the agent call search_nvd first if unsure? Descriptions range 60 - 200 chars but omit actionable context for LLM decision-making.
Parameters lack validation constraints and format specs. 'cve_id' accepts 'string' but does not enforce pattern (CVE-YYYY-NNNNN). 'ip' field accepts 'IPv4 or IPv6' but no regex or enum. 'limit' on search_malware_samples states 'Maximum number of results (1-100, default 10)' in description but no minItems/maxItems in schema. LLMs cannot validate input and may pass invalid values.
No error handling guidance. Tools call external APIs (VirusTotal, Shodan, MITRE, MalwareBazaar, etc.) but descriptions do not indicate: What if the API is rate-limited? What if a CVE/IOC/IP is not found? What if Shodan has no data for an IP? Agents have no recovery path.
Pagination not documented. search_nvd and search_malware_samples accept 'limit' but do not describe: Are results paginated? Is there an offset or cursor? How many total results exist? Without pagination info, large result sets may silently truncate or blow context windows.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). All tools are READ_ONLY and safe to retry, but this is not formally declared. Modern MCP agents benefit from explicit hints to avoid unnecessary caution or unsafe parallelization.
summarize_malware accepts 'source' enum ('bazaar', 'hybrid', 'full') but this is buried in description text, not a formal enum in the schema. LLMs may hallucinate values like 'both' or 'merge' instead of picking from the documented set.