Subdomain API
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"subdomains": {
"url": "https://api.subdomain.app/mcp"
}
}
}远程端点
https://api.subdomain.app/mcpstreamable-http它能做什么
工具清单
工具(2)
🟢find_subdomains(domain, limit)
List known subdomains (hostnames) of a root domain. Data is passive (not active scanning): results are historic observations and may include subdomains that no longer resolve or are no longer live. Results are a point-in-time snapshot that changes over time as new subdomains are observed — re-query rather than caching the result. Use for attack-surface mapping, security recon, asset inventory, or SEO host discovery. Hostnames are returned most-recently-seen first. The response always reports `total` (full distinct count known) and a `truncated` flag, so you can tell when more exist beyond `limit`.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Root (registrable) domain as a bare hostname, e.g. \"example.com\". No scheme, path, port, or leading \"www.\" — these are stripped."
},
"limit": {
"default": 200,
"description": "Max subdomains to return (1-1000, default 200). `total` always reports the full count regardless of this cap.",
"type": "integer",
"minimum": 1,
"maximum": 1000
}
},
"required": [
"domain"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}输出模式
{
"type": "object",
"properties": {
"domain": {
"type": "string"
},
"total": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Total distinct subdomains known."
},
"returned": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Number in `subdomains`."
},
"truncated": {
"type": "boolean",
"description": "True if more exist beyond `limit`."
},
"subdomains": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"domain",
"total",
"returned",
"truncated",
"subdomains"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}🟢count_subdomains(domain)
Return only the total number of distinct subdomains known for a domain — no list. Cheap and low-token. Use when the user asks "how many subdomains" or you only need the size of the attack surface. Count includes historic subdomains that may no longer be live. It is a point-in-time figure that changes over time, so treat it as current-as-of-query, not a fixed value.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Root (registrable) domain as a bare hostname, e.g. \"example.com\". No scheme, path, port, or leading \"www.\" — these are stripped."
}
},
"required": [
"domain"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}输出模式
{
"type": "object",
"properties": {
"domain": {
"type": "string"
},
"total": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Total distinct subdomains known."
}
},
"required": [
"domain",
"total"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}推荐提示词
find_subdomainsfind_subdomains社区
证据