XposedOrNot Breach Intelligence

Real-time data-breach lookup and analytics for emails and domains from XposedOrNot.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
85%
Naming quality
97%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~706Tokens (tool definitions)
~506 BTypical response size
Moderate attention impact (0.55% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "xposedornot": {
      "url": "https://api.xposedornot.com/mcp"
    }
  }
}

Remote endpoints

https://api.xposedornot.com/mcpstreamable-http

What it can do

Tool inventory

Tools (6)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢check_email_breaches(email)

Check whether an email address appears in the XposedOrNot index of known public data breaches. Returns the list of breach names only. Never returns passwords.

Input Schema

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "format": "email",
      "description": "Email address to check for breaches"
    }
  },
  "required": [
    "email"
  ]
}
🟢get_breach_analytics(email)

Get a detailed breach history for one email address: the breaches it appeared in with dates and descriptions, exposure broken down by industry and by year, risk scoring, and any paste exposure. Never returns passwords.

Input Schema

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "format": "email",
      "description": "Email address to get analytics for"
    }
  },
  "required": [
    "email"
  ]
}
🟢list_breaches(domain, breach_id, limit)

List breaches in the XposedOrNot catalog, optionally filtered by the breached company domain or by a specific breach ID. Returns breach name, date, industry, record count, categories of data exposed and a reference URL.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Optional domain of the breached company, for example adobe.com"
    },
    "breach_id": {
      "type": "string",
      "description": "Optional specific breach identifier, for example Adobe"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100,
      "default": 25,
      "description": "Maximum breaches to return, default 25"
    }
  },
  "required": []
}
🟢domain_breach_summary(domain)

Get an aggregate breach summary for a domain, including the number of breaches, affected email accounts, pastes, and the most recent breach date. Returns only counts, not individual email addresses.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to summarize breaches for"
    }
  },
  "required": [
    "domain"
  ]
}
🟢get_breach_metrics

Get system-wide breach statistics: total breaches and records indexed, breaches per year and industry, the largest and most recent breaches, and when the latest breach was added.

Input Schema

{
  "type": "object",
  "properties": {},
  "required": []
}
🟢get_recent_breaches(limit)

Get the breaches most recently added to XposedOrNot, newest first. Returns title, date, a short summary and a URL for each.

Input Schema

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 50,
      "default": 10,
      "description": "Maximum breaches to return, default 10"
    }
  },
  "required": []
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded6 tools