lookup-disclose-io

Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~440Tokens (tool definitions)
~1.5 KBTypical response size
Minimal attention impact (0.34% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "lookup-disclose-io": {
      "url": "https://lookup.disclose.io/mcp"
    }
  }
}

Remote endpoints

https://lookup.disclose.io/mcpstreamable-http

What it can do

Tool inventory

Tools (2)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢lookup_security_contact(asset, asset_type)

Find security reporting channels for responsible vulnerability disclosure. Takes a domain, IP, URL, package name, repository, container image, mobile app, hardware device, browser extension, desktop app, or organization name. Returns bug bounty programs, security.txt contacts, VDP links, abuse contacts, and national/global CERT fallbacks ordered by applicability to the queried owner and asset. This is informational only — not legal advice.

Input Schema

{
  "type": "object",
  "properties": {
    "asset": {
      "type": "string",
      "description": "The asset to look up. Examples: \"cloudflare.com\", \"8.8.8.8\", \"npm:express\", \"gh:facebook/react\", \"app:WhatsApp\", \"hw:Cisco ASA 5505\""
    },
    "asset_type": {
      "description": "Force a specific asset type. Auto-detected if omitted.",
      "type": "string",
      "enum": [
        "domain",
        "ipv4",
        "ipv6",
        "url",
        "email",
        "cidr",
        "asn",
        "package",
        "repository",
        "container",
        "cloud-resource",
        "mobile-app",
        "hardware",
        "extension",
        "desktop-app",
        "organization"
      ]
    }
  },
  "required": [
    "asset"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢classify_asset(input, asset_type)

Classify an input as a domain, IP, package, repository, etc. No network calls — instant response. Useful for understanding what an asset is before performing a full lookup.

Input Schema

{
  "type": "object",
  "properties": {
    "input": {
      "type": "string",
      "description": "The input to classify"
    },
    "asset_type": {
      "description": "Interpret as this asset type, preserving the same normalization as lookup.",
      "type": "string",
      "enum": [
        "domain",
        "ipv4",
        "ipv6",
        "url",
        "email",
        "cidr",
        "asn",
        "package",
        "repository",
        "container",
        "cloud-resource",
        "mobile-app",
        "hardware",
        "extension",
        "desktop-app",
        "organization"
      ]
    }
  },
  "required": [
    "input"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded2 tools
verifiedversion not recorded2 tools
verifiedversion not recorded2 tools