PG1 Sovereign Threat Intelligence
STIX IOCs, CVE lookups w/ EPSS/KEV, ATT&CK dossiers, OFAC wallet sanctions, domain age checks.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"pg1-threat-intel": {
"url": "https://pg1-ai-agent.vercel.app/api/mcp"
}
}
}Remote-Endpunkte
https://pg1-ai-agent.vercel.app/api/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (13)
🟢get_threat_indicators(since, type, min_score, limit)
PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from ThreatFox, URLhaus, AbuseIPDB, OTX and NVD. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for bulk feed synchronizations. Do NOT use for single-item lookups (use get_ioc_context) or CVE analysis (use get_cve_details). USAGE EXCLUSIONS: Does not provide historical query archival beyond the active ingestion window. BEHAVIOR: Pagination is handled via the limit parameter (max 1000). Returns 402 on payment failure.
Eingabe-Schema
{
"type": "object",
"properties": {
"since": {
"type": [
"string",
"null"
],
"description": "ISO timestamp constraint (e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after this exact timestamp."
},
"type": {
"type": [
"string",
"null"
],
"description": "Indicator category filter. Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or 'FileHash-SHA256'."
},
"min_score": {
"type": [
"integer",
"null"
],
"description": "Confidence score threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise."
},
"limit": {
"type": [
"integer",
"null"
],
"description": "Pagination boundary constraint defining the maximum number of indicators to return in a single payload (integer between 1 and 1000, defaulting to 500).",
"default": 500
}
}
}🟢get_cve_details(cve_id)
PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile), and the CISA Known Exploited Vulnerabilities catalog (active wild exploitation status). Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for specific CVE lookups. Do NOT use for IP/domain/hash enrichment (use get_ioc_context) or bulk feed ingestion (use get_threat_indicators). USAGE EXCLUSIONS: Does not support wildcard search or threat-actor dossier profiling. BEHAVIOR: Returns 402 on payment failure, 404 if CVE is not found.
Eingabe-Schema
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "Mandatory official CVE identifier string strictly formatted as 'CVE-YYYY-NNNN' (e.g., 'CVE-2021-44228')."
}
},
"required": [
"cve_id"
]
}🟢get_ioc_context(value)
PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents before visiting, downloading, or connecting to something. Returns aggregated provenance from ThreatFox, URLhaus, AbuseIPDB, and OTX — reporting sources, observation count, aggregated confidence score, known malware families, tags, and first/last seen timestamps. SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of a single indicator. Do NOT use for bulk intelligence downloads (use get_threat_indicators), multiple indicators at once (use get_ioc_batch), or software vulnerability analysis (use get_cve_details). BEHAVIOR: Returns a normal result shaped { found: true, indicator_type, provenance } or { found: false } — never an error for 'not found'. A found:false result means nothing bad is recorded in PG1's sources; it does NOT mean the indicator is safe, only that it isn't in this dataset. Lookups that return found:false are FREE — no payment or free-tier quota is consumed. Payment (via x402 PAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) is only required when a real record is found.
Eingabe-Schema
{
"type": "object",
"properties": {
"value": {
"type": "string",
"description": "Mandatory exact indicator string value to look up, such as an IPv4 address (198.51.100.1), fully qualified domain, complete URL, or SHA-256 hash string."
}
},
"required": [
"value"
]
}🟢get_cve_batch(cve_ids)
PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA KEV status — same enrichment as get_cve_details, batched. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for looking up several known CVE ids at once (e.g. from an SBOM or scan report). Do NOT use for a single CVE (use get_cve_details, lower overhead) or for discovering CVEs by vendor/product (use get_cve_by_product). BEHAVIOR: Accepts up to 20 ids per call; malformed or not-found ids are reported per-entry rather than failing the whole batch.
Eingabe-Schema
{
"type": "object",
"properties": {
"cve_ids": {
"type": "array",
"items": {
"type": "string"
},
"description": "Array of CVE identifiers, each formatted 'CVE-YYYY-NNNN'. Max 20 per call."
}
},
"required": [
"cve_ids"
]
}🟢get_ioc_batch(values)
PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents. Each returns the same aggregated provenance as get_ioc_context from ThreatFox, URLhaus, AbuseIPDB, and OTX. SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. all URLs an agent is about to visit). Do NOT use for a single indicator (use get_ioc_context, lower overhead) or bulk feed synchronization (use get_threat_indicators). BEHAVIOR: Accepts up to 20 indicators per call. A found:false result for any indicator means nothing bad is recorded in PG1's sources — NOT that it's safe. If NONE of the submitted indicators are found, the whole batch is FREE — no payment or free-tier quota consumed. If at least one indicator is found, the normal payment gate (x402 PAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) applies to the full batch result.
Eingabe-Schema
{
"type": "object",
"properties": {
"values": {
"type": "array",
"items": {
"type": "string"
},
"description": "Array of indicator values (IPv4 addresses, domains, URLs, or hashes) to look up. Max 20 per call."
}
},
"required": [
"values"
]
}🟢get_threat_actor_profile(actor_name)
PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associated malware/tooling. Sourced from MITRE ATT&CK Enterprise. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for actor/group-level profiling. Do NOT use for single-indicator lookups (use get_ioc_context) or vulnerability data (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Coverage is limited to groups tracked in MITRE ATT&CK — not all threat actors have an entry. BEHAVIOR: Returns 404 if no matching group or alias is found.
Eingabe-Schema
{
"type": "object",
"properties": {
"actor_name": {
"type": "string",
"description": "Group name or known alias, e.g. 'APT29' or 'Cozy Bear'. Matching is case-insensitive against both the group's primary name and its known aliases."
}
},
"required": [
"actor_name"
]
}🟢get_cve_by_product(vendor, product, version, only_kev)
PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status, sorted by exploitation risk. Sourced from NVD keyword search. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for discovering CVEs by vendor/product when you do not already have an exact CVE id. Do NOT use for a known CVE id (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Uses NVD keyword search, not strict CPE matching — results may include near-matches. BEHAVIOR: Returns up to 50 results per call.
Eingabe-Schema
{
"type": "object",
"properties": {
"vendor": {
"type": "string",
"description": "Vendor name, e.g. 'apache'."
},
"product": {
"type": "string",
"description": "Product name, e.g. 'log4j'."
},
"version": {
"type": "string",
"description": "Optional specific version, e.g. '2.14.1'."
},
"only_kev": {
"type": "boolean",
"description": "If true, only return CVEs on the CISA KEV list."
}
},
"required": [
"vendor",
"product"
]
}🟢get_usage_status(identifier, license_key)
PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is always free.
Eingabe-Schema
{
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Optional — the X-API-KEY or identifier to check usage for; defaults to the calling identifier if omitted."
},
"license_key": {
"type": "string",
"description": "Optional — check Gumroad license status alongside free-tier usage."
}
}
}🟢subscribe_alerts(webhook_url, filter)
PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook URL as they're ingested. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402, since it establishes a recurring subscription rather than a single paid call.
Eingabe-Schema
{
"type": "object",
"properties": {
"webhook_url": {
"type": "string",
"description": "HTTPS URL to receive POSTed alert payloads."
},
"filter": {
"type": "object",
"description": "Optional filter object: { indicator_type, min_epss, kev_only }",
"properties": {
"indicator_type": {
"type": "string"
},
"min_epss": {
"type": "number"
},
"kev_only": {
"type": "boolean"
}
}
}
},
"required": [
"webhook_url"
]
}🟡submit_indicator(indicator, indicator_type, malware_family, confidence, source_note)
PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402. Submissions are staged for review, not immediately added to the live feed.
Eingabe-Schema
{
"type": "object",
"properties": {
"indicator": {
"type": "string"
},
"indicator_type": {
"type": "string"
},
"malware_family": {
"type": "string",
"description": "Optional."
},
"confidence": {
"type": "integer",
"description": "Submitter's own confidence, 0-100."
},
"source_note": {
"type": "string",
"description": "Optional free-text on how this was observed."
}
},
"required": [
"indicator",
"indicator_type"
]
}🟢check_wallet_sanctions(address, currency)
PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet/address sanctions screening only. Do NOT use for IP/domain/hash/URL threat lookups (use get_ioc_context) or CVE data (use get_cve_details). BEHAVIOR: Returns { listed: true|false, matches, source, list_last_synced }. A listed:false result means the address is not on the OFAC SDN list as of the reported sync time — it is informational only, not legal or sanctions-compliance advice, and is never phrased as "safe" or "clean". Fails loudly (returns an error) if the sanctions data is empty or unreachable, rather than ever reporting listed:false on a data failure. VALIDATION: if the address does not match a recognised format for any supported currency (EVM, BTC/LTC/BCH/DOGE/DASH/ZEC base58 or bech32/cashaddr, TRON, Monero, Solana), returns an MCP tool error (isError: true, code invalid_address) instead of a result — it never reports listed:false for malformed input.
Eingabe-Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Mandatory wallet address to screen, e.g. an EVM 0x address, a bech32 (bc1/tb1/ltc1...) address, or a base58 address."
},
"currency": {
"type": [
"string",
"null"
],
"description": "Optional currency/chain filter to narrow the match, e.g. 'BTC', 'ETH', 'XMR'."
}
},
"required": [
"address"
]
}Ausgabe-Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "The address exactly as submitted."
},
"address_normalized": {
"type": "string",
"description": "The address after normalization, used to match against sanctioned_wallets."
},
"listed": {
"type": "boolean"
},
"matches": {
"type": "array",
"items": {
"type": "object",
"properties": {
"sdn_name": {
"type": [
"string",
"null"
]
},
"currency": {
"type": [
"string",
"null"
]
},
"programs": {
"type": "array",
"items": {
"type": "string"
}
},
"sdn_uid": {
"type": [
"string",
"number",
"null"
]
}
}
}
},
"source": {
"type": "string"
},
"list_last_synced": {
"type": "string"
},
"message": {
"type": "string"
},
"disclaimer": {
"type": "string"
}
},
"required": [
"address",
"address_normalized",
"listed",
"matches",
"source",
"list_last_synced"
]
}🟢check_domain_age(domain)
PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap registry for the correct per-TLD RDAP server. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for domain registration/age checks only. Do NOT use for reputation/threat-feed lookups (use get_ioc_context) or sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { found: true, available: true, registration_date, age_days, expiration_date, registrar, newly_registered, source } when available, or { found: false, available: false, reason, reason_code } when the lookup does not resolve — this tool never estimates or guesses an age. "available" is a deprecated alias of "found", kept for backward compatibility. reason_code is "unsupported_tld" when the TLD has no RDAP server in the IANA bootstrap registry, or "timeout" / "lookup_failed" for other lookup failures. A newly registered domain (age_days < 30) is reported as a common phishing signal, not as proof of malicious intent.
Eingabe-Schema
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Mandatory domain name or URL to check, e.g. 'example.com' or 'https://example.com/path'. The registrable domain is extracted automatically."
}
},
"required": [
"domain"
]
}Ausgabe-Schema
{
"type": "object",
"properties": {
"found": {
"type": "boolean",
"description": "Whether a registration record was found. Same meaning as the deprecated \"available\" field."
},
"available": {
"type": "boolean",
"description": "Deprecated — use \"found\" instead. Kept for backward compatibility."
},
"domain": {
"type": "string"
},
"registration_date": {
"type": [
"string",
"null"
]
},
"age_days": {
"type": [
"integer",
"null"
]
},
"expiration_date": {
"type": [
"string",
"null"
]
},
"registrar": {
"type": [
"string",
"null"
]
},
"newly_registered": {
"type": [
"boolean",
"null"
]
},
"note": {
"type": [
"string",
"null"
]
},
"source": {
"type": [
"string",
"null"
]
},
"reason": {
"type": [
"string",
"null"
]
},
"reason_code": {
"type": [
"string",
"null"
],
"enum": [
"invalid_domain",
"bootstrap_unavailable",
"unsupported_tld",
"timeout",
"lookup_failed",
null
]
}
},
"required": [
"found",
"available",
"domain"
]
}🟢check_hostname_reputation(hostname)
PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, synced daily by the sovereign-threat-pipeline. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for phishing/lookalike-domain screening of a hostname only. Do NOT use for domain registration age (use check_domain_age), general threat-feed indicator lookups (use get_ioc_context), or wallet sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { hostname, verdict, sources, lookalike_of, list_synced_at, checked_at, attribution }. verdict is one of "allowlisted", "listed", "lookalike", or "not_listed" — this tool never returns "safe" or "clean", and a not_listed result means the hostname is not on the eth-phishing-detect lists, not that it is safe. "listed" results include match_type "exact" or "parent_domain" in sources. "lookalike" flags a probable typosquat/homoglyph of a known brand — via confusable-character skeleton matching within the stored tolerance, or a brand keyword embedded with extra words (e.g. metamask-login.com) — even when the hostname itself is not directly listed, and sets lookalike_of to the matched brand domain. A brand's own real domain or a subdomain of it is never flagged as its own lookalike. VALIDATION: accepts exactly one bare hostname per call (no bulk input); a value containing a URL scheme, path, port, spaces, or a wildcard returns an MCP tool error (isError: true, code invalid_hostname) instead of a verdict. Fails loudly (returns an error) if the phishing list data is unreachable or times out, rather than ever reporting not_listed on a data failure. Rate-limited to 60 calls/hour per caller when unauthenticated; a valid Gumroad license key (X-API-KEY header) exempts the limit, same as check_domain_age. List contents are never exposed beyond the single matched entry.
Eingabe-Schema
{
"type": "object",
"properties": {
"hostname": {
"type": "string",
"description": "Mandatory bare hostname to screen, e.g. 'example.com'. Not a URL — no scheme, path, port, spaces, or wildcards. One hostname per call."
}
},
"required": [
"hostname"
]
}Ausgabe-Schema
{
"type": "object",
"properties": {
"hostname": {
"type": "string",
"description": "The hostname after normalization (trimmed, lowercased, trailing dot stripped, IDN converted to punycode)."
},
"verdict": {
"type": "string",
"enum": [
"allowlisted",
"listed",
"lookalike",
"not_listed"
],
"description": "Never \"safe\" or \"clean\"."
},
"sources": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"url": {
"type": [
"string",
"null"
]
},
"match_type": {
"type": "string",
"enum": [
"allowlist",
"exact",
"parent_domain",
"confusable",
"keyword"
]
}
}
}
},
"lookalike_of": {
"type": [
"string",
"null"
],
"description": "The matched brand/fuzzylist domain for a \"lookalike\" verdict, otherwise null."
},
"list_synced_at": {
"type": [
"string",
"null"
]
},
"checked_at": {
"type": "string"
},
"attribution": {
"type": "string"
}
},
"required": [
"hostname",
"verdict",
"sources",
"lookalike_of",
"list_synced_at",
"checked_at",
"attribution"
]
}Empfohlene Prompts
get_threat_indicatorsget_threat_indicatorsCommunity
Nachweis