AlertsBar

Domain exposure counters: breaches, infostealers, ULP heap, cookies. Counts only, free.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
100%
命名の品質
80%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~2,686トークン数(ツール定義)
~14.1 KB一般的なレスポンスサイズ
注意への影響は大きい(128k コンテキストの 2.10%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "alertsbar": {
      "url": "https://mcp.alerts.bar/mcp"
    }
  }
}

リモートエンドポイント

https://mcp.alerts.bar/mcpstreamable-http

できること

ツール一覧

ツール(2)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢exposure_counts_for_domain(domain)

Credential-exposure counters for a domain. Counts only - no credential values or per-account detail. Sources: known breaches, infostealer infections, unattributed heap of ULP (Url,Login,Password) bundles, stolen cookies. All figures are INDEXATION dates, not incident dates: _month/_week mean 'newly indexed', never 'newly leaked' - the underlying leak may be years old. Windows nest (_total includes _month includes _week) - never sum them. Counters are rebuilt once daily, so figures are up to 24h old and never real-time. Repeated calls for the same input within a day return identical values - do not re-query to check for changes. Accepts a bare domain or a full URL; scheme, path, port, case and a leading www. are stripped and subdomains collapse to the registrable domain (multi-tenant hosting suffixes such as github.io are not collapsed). An IDN must already be in punycode (xn--) form. Invalid input (not a domain, an IP address) returns an error. If the domain is not in the index at all, every counter and both dates are null: that means NO DATA, not that the domain is clean - never report it as 'no exposure'. first_indexed_at and last_indexed_at give the date range of the domain's records; use last_indexed_at as the 'last updated' date for the domain. Free, no auth.

入力スキーマ

{
  "type": "object",
  "properties": {
    "domain": {
      "description": "Domain to check, e.g. example.com. A full URL is accepted and normalized.",
      "type": "string"
    }
  },
  "required": [
    "domain"
  ]
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "breaches_month": {
      "description": "Indexed in last 30d. Subset of breaches_total.",
      "type": [
        "integer",
        "null"
      ]
    },
    "breaches_total": {
      "description": "Records from known breach incidents, indexed all time.",
      "type": [
        "integer",
        "null"
      ]
    },
    "breaches_week": {
      "description": "Indexed in last 7d. Subset of breaches_month.",
      "type": [
        "integer",
        "null"
      ]
    },
    "cookies_month": {
      "description": "Indexed in last 30d. Subset of cookies_total.",
      "type": [
        "integer",
        "null"
      ]
    },
    "cookies_total": {
      "description": "Stolen browser session cookies, indexed all time. Non-zero means session-hijacking risk that a password reset alone does not fix. Cookies are counted here only; they are not included in exposure_samples_for_domain.",
      "type": [
        "integer",
        "null"
      ]
    },
    "cookies_week": {
      "description": "Indexed in last 7d. Subset of cookies_month.",
      "type": [
        "integer",
        "null"
      ]
    },
    "domain": {
      "description": "Normalized domain actually queried. May differ from the input - report this one to the user.",
      "type": "string"
    },
    "first_indexed_at": {
      "description": "Date-time (format YYYY-MM-DD HH:MM:SS, UTC) when AlertsBar first indexed a record for this domain. Indexation date, not incident date - never say the domain was first leaked then. Null if the domain is not in the index.",
      "type": [
        "string",
        "null"
      ]
    },
    "heap_staff_month": {
      "description": "Indexed in last 30d. Subset of heap_staff_total.",
      "type": [
        "integer",
        "null"
      ]
    },
    "heap_staff_total": {
      "description": "Staff logins in unattributed heap of ULP (Url,Login,Password) bundles - no linkable breach, device or leak date. Credentials circulating in the wild.",
      "type": [
        "integer",
        "null"
      ]
    },
    "heap_staff_week": {
      "description": "Indexed in last 7d. Subset of heap_staff_month.",
      "type": [
        "integer",
        "null"
      ]
    },
    "heap_users_month": {
      "description": "Indexed in last 30d. Subset of heap_users_total.",
      "type": [
        "integer",
        "null"
      ]
    },
    "heap_users_total": {
      "description": "Customer logins in unattributed heap of ULP (Url,Login,Password) bundles - no linkable breach, device or leak date.",
      "type": [
        "integer",
        "null"
      ]
    },
    "heap_users_week": {
      "description": "Indexed in last 7d. Subset of heap_users_month.",
      "type": [
        "integer",
        "null"
      ]
    },
    "last_indexed_at": {
      "description": "Date-time (format YYYY-MM-DD HH:MM:SS, UTC) when AlertsBar last indexed a record for this domain. This is the domain's 'last updated' date and the only reliable freshness signal - samples are random and say nothing about recency. Say 'newly indexed', never 'newly leaked'. Null if the domain is not in the index.",
      "type": [
        "string",
        "null"
      ]
    },
    "stealers_staff_month": {
      "description": "Indexed in last 30d. Subset of stealers_staff_total.",
      "type": [
        "integer",
        "null"
      ]
    },
    "stealers_staff_total": {
      "description": "Staff logins from infostealer-infected devices, indexed all time. Implies a compromised machine, not just a leaked password. The credentials may be for any site, not only this domain's own systems.",
      "type": [
        "integer",
        "null"
      ]
    },
    "stealers_staff_week": {
      "description": "Indexed in last 7d. Subset of stealers_staff_month.",
      "type": [
        "integer",
        "null"
      ]
    },
    "stealers_users_month": {
      "description": "Indexed in last 30d. Subset of stealers_users_total.",
      "type": [
        "integer",
        "null"
      ]
    },
    "stealers_users_total": {
      "description": "Customer logins for this domain's site from infostealer-infected devices, indexed all time.",
      "type": [
        "integer",
        "null"
      ]
    },
    "stealers_users_week": {
      "description": "Indexed in last 7d. Subset of stealers_users_month.",
      "type": [
        "integer",
        "null"
      ]
    }
  },
  "required": [
    "domain",
    "first_indexed_at",
    "last_indexed_at",
    "breaches_total",
    "breaches_month",
    "breaches_week",
    "cookies_total",
    "cookies_month",
    "cookies_week",
    "stealers_staff_total",
    "stealers_staff_month",
    "stealers_staff_week",
    "stealers_users_total",
    "stealers_users_month",
    "stealers_users_week",
    "heap_staff_total",
    "heap_staff_month",
    "heap_staff_week",
    "heap_users_total",
    "heap_users_month",
    "heap_users_week"
  ],
  "description": "Counters as of the last daily rebuild. Windows count back from that rebuild, not from request time. Every _total/_month/_week and both dates are by INDEXATION date, not by when the leak or infection happened. All counters and both dates are null when the domain is not in the index (no data - not the same as clean). staff = login is an address at this domain; users = login belongs elsewhere but the record is for this domain's site (customers). For public mailbox providers (e.g. gmail.com, ukr.net) staff means holders of mailboxes at that domain, NOT employees, and the numbers can be huge - do not present them as an employee compromise. Placeholder or test domains (e.g. example.com) also produce staff records that belong to nobody in particular."
}
🟢exposure_samples_for_domain(domain)

A small RANDOM sample of individual exposure records for a domain - metadata only, capped in number: up to 20 records per type (stealers_users, stealers_staff, heap_users, heap_staff, breaches). Cookies are not sampled - see cookies_* in exposure_counts_for_domain. The sample is neither the newest nor the largest nor the most severe records, and it can differ between calls; identical-looking records can repeat and because of different logins/passwords. Each record says WHICH url was affected, WHICH domain the captured login belonged to, from WHICH source type, roughly when the incident was, and when the record was indexed. It carries NO credentials: no password, no username, and the login's local part is redacted. Use exposure_counts_for_domain first for the scale of the problem and for freshness (last_indexed_at); use this only when the user asks to see concrete examples. Calling again returns another random subset, never the full set - do not call it repeatedly to collect more records.

入力スキーマ

{
  "type": "object",
  "properties": {
    "domain": {
      "description": "Domain to check, e.g. example.com. A full URL is accepted and normalized, same rules as exposure_counts_for_domain.",
      "type": "string"
    }
  },
  "required": [
    "domain"
  ]
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "domain": {
      "description": "Normalized domain actually queried. May differ from the input - report this one to the user.",
      "type": "string"
    },
    "records": {
      "description": "A random subset of up to 20 records per type, listed by indexed_at descending inside this response. NOT the newest records: a recent or old indexed_at here says nothing about the domain's overall recency - use last_indexed_at from exposure_counts_for_domain. Capped server-side; an empty array means nothing is indexed for this domain.",
      "items": {
        "properties": {
          "estimated_incident_at": {
            "description": "Unix seconds or null, and its meaning follows type. stealers_*: ESTIMATED infection date - an estimate, so always say 'around' or 'estimated'. breaches: the date the breach was PUBLISHED, which is later than when it happened - say 'published', never 'happened'. heap_*: always null (unknown) - never render it as a date, say the leak date is unknown.",
            "type": [
              "integer",
              "null"
            ]
          },
          "indexed_at": {
            "description": "Unix seconds (UTC). When AlertsBar indexed this record. Always a fact, unlike estimated_incident_at. A recent indexed_at with an older estimated_incident_at means a long-standing compromise only just discovered - say 'newly discovered', never 'newly leaked'. Many breach records share one identical indexed_at because they were bulk-imported.",
            "type": "integer"
          },
          "login": {
            "description": "The captured login with its LOCAL PART REDACTED, e.g. [email protected] - only the part after @ is real, and no address, name or individual is identified. This is what ties the record to the queried domain: for *_staff the domain part equals the queried domain, meaning an address at this domain was found with credentials for url; for *_users it is usually an outside provider (gmail.com and such), meaning an external person's credentials for this organisation's site were taken. For stealers_users the part after @ can also be a bare host label (e.g. ...@local) or missing entirely (just '...'), and letter case is as captured. Use it to explain WHY a record belongs to this domain. The dots are a redaction, NOT a wildcard: this is one single account, never all addresses at that domain. Full logins are not available through MCP at all - they require domain ownership verification and an API key.",
            "type": "string"
          },
          "source": {
            "description": "Opaque internal id of the source feed or breach inside AlertsBar, shared by every record that came from it - it identifies the feed, not the individual row. It is NOT a name: do not read a stealer family, breach name, vendor or feed out of it, and never guess what it stands for. Its only purpose is follow-up - the user can quote it to AlertsBar support or use it against the REST API to pull the full record. Show it verbatim as a reference id when the user wants to investigate a specific record further, and otherwise leave it out of the summary.",
            "type": "integer"
          },
          "type": {
            "description": "Which source this record came from. stealers_* = credentials taken off a specific infostealer-infected device, so a machine is compromised, not just a password. heap_* = credentials found in an unattributed ULP (Url,Login,Password) bundle, with no linkable incident, device or date. breaches = a record from a known breach incident. *_staff = the login was an address at this domain; *_users = the login belonged elsewhere but the record targets this domain's site (customer). For public mailbox providers (gmail.com, ukr.net) *_staff means a mailbox holder, not an employee. Cookies never appear here.",
            "enum": [
              "stealers_users",
              "stealers_staff",
              "heap_users",
              "heap_staff",
              "breaches"
            ],
            "type": "string"
          },
          "url": {
            "description": "The URL, hostname or app identifier the captured credentials were for, shown as captured and NOT normalized: it may lack a scheme, include a path, be an android:// app id, a localhost/dev address or a placeholder host. For *_users it is normally a system of the queried organisation. For *_staff it is often a THIRD-PARTY site the employee signed in to, not the organisation's own system - do not say the organisation's system was breached unless the host belongs to the queried domain.",
            "type": "string"
          }
        },
        "required": [
          "type",
          "url",
          "login",
          "source",
          "estimated_incident_at",
          "indexed_at"
        ],
        "type": "object"
      },
      "type": "array"
    }
  },
  "required": [
    "domain",
    "records"
  ],
  "description": "A random capped sample of exposure records. Metadata only - no credentials of any kind. This is a SAMPLE, never the full set: the number of records here says nothing about the true volume, which only exposure_counts_for_domain reports. Never describe the count of records in this response as the number of exposures, and never infer how recent the domain's exposure is from this list."
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 2 件
検証済みバージョンは記録されていませんツール 1 件