lookup-disclose-io

Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
100%
命名质量
80%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~440token 数(工具定义)
~1.5 KB典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.34%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "lookup-disclose-io": {
      "url": "https://lookup.disclose.io/mcp"
    }
  }
}

远程端点

https://lookup.disclose.io/mcpstreamable-http

它能做什么

工具清单

工具(2)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢lookup_security_contact(asset, asset_type)

Find security reporting channels for responsible vulnerability disclosure. Takes a domain, IP, URL, package name, repository, container image, mobile app, hardware device, browser extension, desktop app, or organization name. Returns bug bounty programs, security.txt contacts, VDP links, abuse contacts, and national/global CERT fallbacks ordered by applicability to the queried owner and asset. This is informational only — not legal advice.

输入模式

{
  "type": "object",
  "properties": {
    "asset": {
      "type": "string",
      "description": "The asset to look up. Examples: \"cloudflare.com\", \"8.8.8.8\", \"npm:express\", \"gh:facebook/react\", \"app:WhatsApp\", \"hw:Cisco ASA 5505\""
    },
    "asset_type": {
      "description": "Force a specific asset type. Auto-detected if omitted.",
      "type": "string",
      "enum": [
        "domain",
        "ipv4",
        "ipv6",
        "url",
        "email",
        "cidr",
        "asn",
        "package",
        "repository",
        "container",
        "cloud-resource",
        "mobile-app",
        "hardware",
        "extension",
        "desktop-app",
        "organization"
      ]
    }
  },
  "required": [
    "asset"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢classify_asset(input, asset_type)

Classify an input as a domain, IP, package, repository, etc. No network calls — instant response. Useful for understanding what an asset is before performing a full lookup.

输入模式

{
  "type": "object",
  "properties": {
    "input": {
      "type": "string",
      "description": "The input to classify"
    },
    "asset_type": {
      "description": "Interpret as this asset type, preserving the same normalization as lookup.",
      "type": "string",
      "enum": [
        "domain",
        "ipv4",
        "ipv6",
        "url",
        "email",
        "cidr",
        "asn",
        "package",
        "repository",
        "container",
        "cloud-resource",
        "mobile-app",
        "hardware",
        "extension",
        "desktop-app",
        "organization"
      ]
    }
  },
  "required": [
    "input"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

社区

评价此服务器

证据

最近观测

已验证未记录版本2 个工具
已验证未记录版本2 个工具
已验证未记录版本2 个工具