Scry

Free IPv4 lookups against a distributed attacker-observation corpus.

使うべきか

品質と安全性

B
説明の品質
92%
スキーマの完全性
73%
命名の品質
80%
ポイズニングのリスク
80%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(4)

  • HIGHTool poisoning patterns detected
  • LOWTool 'scry_tool' description lacks action verbscry_tool 内
  • LOWTool 'scry_campaigns' description lacks action verbscry_campaigns 内
  • LOWTool description contains negative instruction about its own usescry_stats 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~1,242トークン数(ツール定義)
~487 B一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.97%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "scry": {
      "url": "https://mcp.tunnelmind.ai/mcp"
    }
  }
}

リモートエンドポイント

https://mcp.tunnelmind.ai/mcpstreamable-http

できること

ツール一覧

ツール(12)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢scry_stats

Returns aggregate Scry corpus telemetry: total observation count, distinct source IPs, first/last observation timestamps, last-24h activity, and per-protocol breakdowns. Useful as a liveness/density check before issuing per-IP queries — lets an agent decide whether the corpus has enough data to be authoritative. Use this tool when: - An agent is planning a multi-step investigation and wants to know if Scry has corpus density worth querying. - You want a 'corpus health' signal in a dashboard or report. Do NOT use this tool when: - You want details about a specific IP — use `scry_check`. - You want sensor fleet size or node identities — never exposed at any tier. Inputs: none. Returns: total_observations, distinct_source_ips, first_seen_ms, last_seen_ms, observations_last_24h, distinct_source_ips_last_24h, by_protocol, as_of_ms. Cost: free, anonymous, rate-limited. Latency: <100ms typical.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢scry_check(ip)

Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last observed, observation count, protocols and ports targeted, ASN, country, category (actor/scanner/not_observed), and confidence_bucket (low/medium/high). Use when an agent needs IP triage, hostility assessment, or risk signaling. Do NOT use for raw payloads (never exposed) or IPv6 (corpus is v4-only at v0.1).

入力スキーマ

{
  "type": "object",
  "properties": {
    "ip": {
      "type": "string",
      "description": "IPv4 address (e.g. '8.8.8.8')"
    }
  },
  "required": [
    "ip"
  ],
  "additionalProperties": false
}
🟢scry_check_bulk(ips)

Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP.

入力スキーマ

{
  "type": "object",
  "properties": {
    "ips": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "minItems": 1,
      "maxItems": 100
    }
  },
  "required": [
    "ips"
  ],
  "additionalProperties": false
}
⚪scry_top(dimension, since_ms, limit, include_noise)

Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'

入力スキーマ

{
  "type": "object",
  "properties": {
    "dimension": {
      "type": "string",
      "enum": [
        "asn",
        "country",
        "protocol",
        "port"
      ]
    },
    "since_ms": {
      "type": "integer"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100
    },
    "include_noise": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}
🟢scry_timeseries(bucket, since_ms, until_ms)

Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling.

入力スキーマ

{
  "type": "object",
  "properties": {
    "bucket": {
      "type": "string",
      "enum": [
        "minute",
        "hour",
        "day"
      ]
    },
    "since_ms": {
      "type": "integer"
    },
    "until_ms": {
      "type": "integer"
    }
  },
  "additionalProperties": false
}
⚪scry_asn(asn, since_ms)

Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.

入力スキーマ

{
  "type": "object",
  "properties": {
    "asn": {
      "type": "string"
    },
    "since_ms": {
      "type": "integer"
    }
  },
  "required": [
    "asn"
  ],
  "additionalProperties": false
}
⚪scry_country(country, since_ms)

Roll-up of corpus activity by ISO country code. Same shape as scry_asn.

入力スキーマ

{
  "type": "object",
  "properties": {
    "country": {
      "type": "string",
      "pattern": "^[A-Za-z]{2}$"
    },
    "since_ms": {
      "type": "integer"
    }
  },
  "required": [
    "country"
  ],
  "additionalProperties": false
}
🟢scry_tools(protocol, since_ms, limit)

List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors.

入力スキーマ

{
  "type": "object",
  "properties": {
    "protocol": {
      "type": "string"
    },
    "since_ms": {
      "type": "integer"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 200
    }
  },
  "additionalProperties": false
}
⚪scry_tool(id)

Single tool detail by 16-char hex id from scry_tools.

入力スキーマ

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "pattern": "^[0-9a-f]{16}$"
    }
  },
  "required": [
    "id"
  ],
  "additionalProperties": false
}
⚪scry_campaigns(include_inactive, limit)

Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history.

入力スキーマ

{
  "type": "object",
  "properties": {
    "include_inactive": {
      "type": "boolean"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 200
    }
  },
  "additionalProperties": false
}
⚪scry_campaign(id)

Single campaign detail by id (format: c[0-9a-f]{15}).

入力スキーマ

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "pattern": "^c[0-9a-f]{15}$"
    }
  },
  "required": [
    "id"
  ],
  "additionalProperties": false
}
⚪scry_recent(since_ms, limit, protocol, country, include_noise)

Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms.

入力スキーマ

{
  "type": "object",
  "properties": {
    "since_ms": {
      "type": "integer"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 500
    },
    "protocol": {
      "type": "string"
    },
    "country": {
      "type": "string",
      "pattern": "^[A-Za-z]{2}$"
    },
    "include_noise": {
      "type": "boolean"
    }
  },
  "additionalProperties": false
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 12 件
検証済みバージョンは記録されていませんツール 12 件