PG1 Sovereign Threat Intelligence

STIX IOCs, CVE lookups w/ EPSS/KEV, ATT&CK dossiers, OFAC wallet sanctions, domain age checks.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
98%
이름 품질
100%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~4,248토큰 (도구 정의)
~1.5 KB일반적인 응답 크기
상당한 주의 영향 (128k 컨텍스트의 3.32%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "pg1-threat-intel": {
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}

원격 엔드포인트

https://pg1-ai-agent.vercel.app/api/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (13)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢get_threat_indicators(since, type, min_score, limit)

PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from ThreatFox, URLhaus, AbuseIPDB, OTX and NVD. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for bulk feed synchronizations. Do NOT use for single-item lookups (use get_ioc_context) or CVE analysis (use get_cve_details). USAGE EXCLUSIONS: Does not provide historical query archival beyond the active ingestion window. BEHAVIOR: Pagination is handled via the limit parameter (max 1000). Returns 402 on payment failure.

입력 스키마

{
  "type": "object",
  "properties": {
    "since": {
      "type": [
        "string",
        "null"
      ],
      "description": "ISO timestamp constraint (e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after this exact timestamp."
    },
    "type": {
      "type": [
        "string",
        "null"
      ],
      "description": "Indicator category filter. Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or 'FileHash-SHA256'."
    },
    "min_score": {
      "type": [
        "integer",
        "null"
      ],
      "description": "Confidence score threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise."
    },
    "limit": {
      "type": [
        "integer",
        "null"
      ],
      "description": "Pagination boundary constraint defining the maximum number of indicators to return in a single payload (integer between 1 and 1000, defaulting to 500).",
      "default": 500
    }
  }
}
🟢get_cve_details(cve_id)

PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile), and the CISA Known Exploited Vulnerabilities catalog (active wild exploitation status). Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for specific CVE lookups. Do NOT use for IP/domain/hash enrichment (use get_ioc_context) or bulk feed ingestion (use get_threat_indicators). USAGE EXCLUSIONS: Does not support wildcard search or threat-actor dossier profiling. BEHAVIOR: Returns 402 on payment failure, 404 if CVE is not found.

입력 스키마

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "Mandatory official CVE identifier string strictly formatted as 'CVE-YYYY-NNNN' (e.g., 'CVE-2021-44228')."
    }
  },
  "required": [
    "cve_id"
  ]
}
🟢get_ioc_context(value)

PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents before visiting, downloading, or connecting to something. Returns aggregated provenance from ThreatFox, URLhaus, AbuseIPDB, and OTX — reporting sources, observation count, aggregated confidence score, known malware families, tags, and first/last seen timestamps. SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of a single indicator. Do NOT use for bulk intelligence downloads (use get_threat_indicators), multiple indicators at once (use get_ioc_batch), or software vulnerability analysis (use get_cve_details). BEHAVIOR: Returns a normal result shaped { found: true, indicator_type, provenance } or { found: false } — never an error for 'not found'. A found:false result means nothing bad is recorded in PG1's sources; it does NOT mean the indicator is safe, only that it isn't in this dataset. Lookups that return found:false are FREE — no payment or free-tier quota is consumed. Payment (via x402 PAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) is only required when a real record is found.

입력 스키마

{
  "type": "object",
  "properties": {
    "value": {
      "type": "string",
      "description": "Mandatory exact indicator string value to look up, such as an IPv4 address (198.51.100.1), fully qualified domain, complete URL, or SHA-256 hash string."
    }
  },
  "required": [
    "value"
  ]
}
🟢get_cve_batch(cve_ids)

PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA KEV status — same enrichment as get_cve_details, batched. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for looking up several known CVE ids at once (e.g. from an SBOM or scan report). Do NOT use for a single CVE (use get_cve_details, lower overhead) or for discovering CVEs by vendor/product (use get_cve_by_product). BEHAVIOR: Accepts up to 20 ids per call; malformed or not-found ids are reported per-entry rather than failing the whole batch.

입력 스키마

{
  "type": "object",
  "properties": {
    "cve_ids": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Array of CVE identifiers, each formatted 'CVE-YYYY-NNNN'. Max 20 per call."
    }
  },
  "required": [
    "cve_ids"
  ]
}
🟢get_ioc_batch(values)

PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents. Each returns the same aggregated provenance as get_ioc_context from ThreatFox, URLhaus, AbuseIPDB, and OTX. SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. all URLs an agent is about to visit). Do NOT use for a single indicator (use get_ioc_context, lower overhead) or bulk feed synchronization (use get_threat_indicators). BEHAVIOR: Accepts up to 20 indicators per call. A found:false result for any indicator means nothing bad is recorded in PG1's sources — NOT that it's safe. If NONE of the submitted indicators are found, the whole batch is FREE — no payment or free-tier quota consumed. If at least one indicator is found, the normal payment gate (x402 PAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) applies to the full batch result.

입력 스키마

{
  "type": "object",
  "properties": {
    "values": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Array of indicator values (IPv4 addresses, domains, URLs, or hashes) to look up. Max 20 per call."
    }
  },
  "required": [
    "values"
  ]
}
🟢get_threat_actor_profile(actor_name)

PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associated malware/tooling. Sourced from MITRE ATT&CK Enterprise. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for actor/group-level profiling. Do NOT use for single-indicator lookups (use get_ioc_context) or vulnerability data (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Coverage is limited to groups tracked in MITRE ATT&CK — not all threat actors have an entry. BEHAVIOR: Returns 404 if no matching group or alias is found.

입력 스키마

{
  "type": "object",
  "properties": {
    "actor_name": {
      "type": "string",
      "description": "Group name or known alias, e.g. 'APT29' or 'Cozy Bear'. Matching is case-insensitive against both the group's primary name and its known aliases."
    }
  },
  "required": [
    "actor_name"
  ]
}
🟢get_cve_by_product(vendor, product, version, only_kev)

PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status, sorted by exploitation risk. Sourced from NVD keyword search. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for discovering CVEs by vendor/product when you do not already have an exact CVE id. Do NOT use for a known CVE id (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Uses NVD keyword search, not strict CPE matching — results may include near-matches. BEHAVIOR: Returns up to 50 results per call.

입력 스키마

{
  "type": "object",
  "properties": {
    "vendor": {
      "type": "string",
      "description": "Vendor name, e.g. 'apache'."
    },
    "product": {
      "type": "string",
      "description": "Product name, e.g. 'log4j'."
    },
    "version": {
      "type": "string",
      "description": "Optional specific version, e.g. '2.14.1'."
    },
    "only_kev": {
      "type": "boolean",
      "description": "If true, only return CVEs on the CISA KEV list."
    }
  },
  "required": [
    "vendor",
    "product"
  ]
}
🟢get_usage_status(identifier, license_key)

PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is always free.

입력 스키마

{
  "type": "object",
  "properties": {
    "identifier": {
      "type": "string",
      "description": "Optional — the X-API-KEY or identifier to check usage for; defaults to the calling identifier if omitted."
    },
    "license_key": {
      "type": "string",
      "description": "Optional — check Gumroad license status alongside free-tier usage."
    }
  }
}
🟢subscribe_alerts(webhook_url, filter)

PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook URL as they're ingested. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402, since it establishes a recurring subscription rather than a single paid call.

입력 스키마

{
  "type": "object",
  "properties": {
    "webhook_url": {
      "type": "string",
      "description": "HTTPS URL to receive POSTed alert payloads."
    },
    "filter": {
      "type": "object",
      "description": "Optional filter object: { indicator_type, min_epss, kev_only }",
      "properties": {
        "indicator_type": {
          "type": "string"
        },
        "min_epss": {
          "type": "number"
        },
        "kev_only": {
          "type": "boolean"
        }
      }
    }
  },
  "required": [
    "webhook_url"
  ]
}
🟡submit_indicator(indicator, indicator_type, malware_family, confidence, source_note)

PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402. Submissions are staged for review, not immediately added to the live feed.

입력 스키마

{
  "type": "object",
  "properties": {
    "indicator": {
      "type": "string"
    },
    "indicator_type": {
      "type": "string"
    },
    "malware_family": {
      "type": "string",
      "description": "Optional."
    },
    "confidence": {
      "type": "integer",
      "description": "Submitter's own confidence, 0-100."
    },
    "source_note": {
      "type": "string",
      "description": "Optional free-text on how this was observed."
    }
  },
  "required": [
    "indicator",
    "indicator_type"
  ]
}
🟢check_wallet_sanctions(address, currency)

PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet/address sanctions screening only. Do NOT use for IP/domain/hash/URL threat lookups (use get_ioc_context) or CVE data (use get_cve_details). BEHAVIOR: Returns { listed: true|false, matches, source, list_last_synced }. A listed:false result means the address is not on the OFAC SDN list as of the reported sync time — it is informational only, not legal or sanctions-compliance advice, and is never phrased as "safe" or "clean". Fails loudly (returns an error) if the sanctions data is empty or unreachable, rather than ever reporting listed:false on a data failure. VALIDATION: if the address does not match a recognised format for any supported currency (EVM, BTC/LTC/BCH/DOGE/DASH/ZEC base58 or bech32/cashaddr, TRON, Monero, Solana), returns an MCP tool error (isError: true, code invalid_address) instead of a result — it never reports listed:false for malformed input.

입력 스키마

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "Mandatory wallet address to screen, e.g. an EVM 0x address, a bech32 (bc1/tb1/ltc1...) address, or a base58 address."
    },
    "currency": {
      "type": [
        "string",
        "null"
      ],
      "description": "Optional currency/chain filter to narrow the match, e.g. 'BTC', 'ETH', 'XMR'."
    }
  },
  "required": [
    "address"
  ]
}

출력 스키마

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "The address exactly as submitted."
    },
    "address_normalized": {
      "type": "string",
      "description": "The address after normalization, used to match against sanctioned_wallets."
    },
    "listed": {
      "type": "boolean"
    },
    "matches": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "sdn_name": {
            "type": [
              "string",
              "null"
            ]
          },
          "currency": {
            "type": [
              "string",
              "null"
            ]
          },
          "programs": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "sdn_uid": {
            "type": [
              "string",
              "number",
              "null"
            ]
          }
        }
      }
    },
    "source": {
      "type": "string"
    },
    "list_last_synced": {
      "type": "string"
    },
    "message": {
      "type": "string"
    },
    "disclaimer": {
      "type": "string"
    }
  },
  "required": [
    "address",
    "address_normalized",
    "listed",
    "matches",
    "source",
    "list_last_synced"
  ]
}
🟢check_domain_age(domain)

PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap registry for the correct per-TLD RDAP server. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for domain registration/age checks only. Do NOT use for reputation/threat-feed lookups (use get_ioc_context) or sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { found: true, available: true, registration_date, age_days, expiration_date, registrar, newly_registered, source } when available, or { found: false, available: false, reason, reason_code } when the lookup does not resolve — this tool never estimates or guesses an age. "available" is a deprecated alias of "found", kept for backward compatibility. reason_code is "unsupported_tld" when the TLD has no RDAP server in the IANA bootstrap registry, or "timeout" / "lookup_failed" for other lookup failures. A newly registered domain (age_days < 30) is reported as a common phishing signal, not as proof of malicious intent.

입력 스키마

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Mandatory domain name or URL to check, e.g. 'example.com' or 'https://example.com/path'. The registrable domain is extracted automatically."
    }
  },
  "required": [
    "domain"
  ]
}

출력 스키마

{
  "type": "object",
  "properties": {
    "found": {
      "type": "boolean",
      "description": "Whether a registration record was found. Same meaning as the deprecated \"available\" field."
    },
    "available": {
      "type": "boolean",
      "description": "Deprecated — use \"found\" instead. Kept for backward compatibility."
    },
    "domain": {
      "type": "string"
    },
    "registration_date": {
      "type": [
        "string",
        "null"
      ]
    },
    "age_days": {
      "type": [
        "integer",
        "null"
      ]
    },
    "expiration_date": {
      "type": [
        "string",
        "null"
      ]
    },
    "registrar": {
      "type": [
        "string",
        "null"
      ]
    },
    "newly_registered": {
      "type": [
        "boolean",
        "null"
      ]
    },
    "note": {
      "type": [
        "string",
        "null"
      ]
    },
    "source": {
      "type": [
        "string",
        "null"
      ]
    },
    "reason": {
      "type": [
        "string",
        "null"
      ]
    },
    "reason_code": {
      "type": [
        "string",
        "null"
      ],
      "enum": [
        "invalid_domain",
        "bootstrap_unavailable",
        "unsupported_tld",
        "timeout",
        "lookup_failed",
        null
      ]
    }
  },
  "required": [
    "found",
    "available",
    "domain"
  ]
}
🟢check_hostname_reputation(hostname)

PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, synced daily by the sovereign-threat-pipeline. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for phishing/lookalike-domain screening of a hostname only. Do NOT use for domain registration age (use check_domain_age), general threat-feed indicator lookups (use get_ioc_context), or wallet sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { hostname, verdict, sources, lookalike_of, list_synced_at, checked_at, attribution }. verdict is one of "allowlisted", "listed", "lookalike", or "not_listed" — this tool never returns "safe" or "clean", and a not_listed result means the hostname is not on the eth-phishing-detect lists, not that it is safe. "listed" results include match_type "exact" or "parent_domain" in sources. "lookalike" flags a probable typosquat/homoglyph of a known brand — via confusable-character skeleton matching within the stored tolerance, or a brand keyword embedded with extra words (e.g. metamask-login.com) — even when the hostname itself is not directly listed, and sets lookalike_of to the matched brand domain. A brand's own real domain or a subdomain of it is never flagged as its own lookalike. VALIDATION: accepts exactly one bare hostname per call (no bulk input); a value containing a URL scheme, path, port, spaces, or a wildcard returns an MCP tool error (isError: true, code invalid_hostname) instead of a verdict. Fails loudly (returns an error) if the phishing list data is unreachable or times out, rather than ever reporting not_listed on a data failure. Rate-limited to 60 calls/hour per caller when unauthenticated; a valid Gumroad license key (X-API-KEY header) exempts the limit, same as check_domain_age. List contents are never exposed beyond the single matched entry.

입력 스키마

{
  "type": "object",
  "properties": {
    "hostname": {
      "type": "string",
      "description": "Mandatory bare hostname to screen, e.g. 'example.com'. Not a URL — no scheme, path, port, spaces, or wildcards. One hostname per call."
    }
  },
  "required": [
    "hostname"
  ]
}

출력 스키마

{
  "type": "object",
  "properties": {
    "hostname": {
      "type": "string",
      "description": "The hostname after normalization (trimmed, lowercased, trailing dot stripped, IDN converted to punycode)."
    },
    "verdict": {
      "type": "string",
      "enum": [
        "allowlisted",
        "listed",
        "lookalike",
        "not_listed"
      ],
      "description": "Never \"safe\" or \"clean\"."
    },
    "sources": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string"
          },
          "url": {
            "type": [
              "string",
              "null"
            ]
          },
          "match_type": {
            "type": "string",
            "enum": [
              "allowlist",
              "exact",
              "parent_domain",
              "confusable",
              "keyword"
            ]
          }
        }
      }
    },
    "lookalike_of": {
      "type": [
        "string",
        "null"
      ],
      "description": "The matched brand/fuzzylist domain for a \"lookalike\" verdict, otherwise null."
    },
    "list_synced_at": {
      "type": [
        "string",
        "null"
      ]
    },
    "checked_at": {
      "type": "string"
    },
    "attribution": {
      "type": "string"
    }
  },
  "required": [
    "hostname",
    "verdict",
    "sources",
    "lookalike_of",
    "list_synced_at",
    "checked_at",
    "attribution"
  ]
}

권장 프롬프트

retrieve_data
Get details about [item] from PG1 Sovereign Threat Intelligence
예상 도구: get_threat_indicators
fetch_info
Fetch [information type] using PG1 Sovereign Threat Intelligence
예상 도구: get_threat_indicators

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 13개
검증됨버전이 기록되지 않음도구 1개