Server definition
- Hash
- sha256:a92f52db9a3e02dd93a015654d2f998457dc7cf81dae7f22118b3627766447d7
- What it is
- What a remote MCP server returned when asked what it offers: 14 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap registry for the correct per-TLD RDAP server. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for domain registration/age checks only. Do NOT use for reputation/threat-feed lookups (use get_ioc_context) or sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { found: true, available: true, registration_date, age_days, expiration_date, registrar, newly_registered, source } when available, or { found: false, available: false, reason, reason_code } when the lookup does not resolve — this tool never estimates or guesses an age. \"available\" is a deprecated alias of \"found\", kept for backward compatibility. reason_code is \"unsupported_tld\" when the TLD has no RDAP server in the IANA bootstrap registry, or \"timeout\" / \"lookup_failed\" for other lookup failures. A newly registered domain (age_days < 30) is reported as a common phishing signal, not as proof of malicious intent.",
"inputSchema": {
"properties": {
"domain": {
"description": "Mandatory domain name or URL to check, e.g. 'example.com' or 'https://example.com/path'. The registrable domain is extracted automatically.",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_domain_age",
"outputSchema": {
"properties": {
"age_days": {
"type": [
"integer",
"null"
]
},
"available": {
"description": "Deprecated — use \"found\" instead. Kept for backward compatibility.",
"type": "boolean"
},
"checks": {
"description": "Which underlying sources were checked for this result and whether each one completed.",
"items": {
"properties": {
"checked_at": {
"type": "string"
},
"data_as_of": {
"type": [
"string",
"null"
]
},
"result": {
"enum": [
"ok",
"timeout",
"error",
"skipped"
],
"type": "string"
},
"source": {
"description": "Generic label for the data source checked, never a vendor name.",
"type": "string"
}
},
"required": [
"source",
"result",
"checked_at",
"data_as_of"
],
"type": "object"
},
"type": "array"
},
"domain": {
"type": "string"
},
"expiration_date": {
"type": [
"string",
"null"
]
},
"found": {
"description": "Whether a registration record was found. Same meaning as the deprecated \"available\" field.",
"type": "boolean"
},
"newly_registered": {
"type": [
"boolean",
"null"
]
},
"note": {
"type": [
"string",
"null"
]
},
"reason": {
"type": [
"string",
"null"
]
},
"reason_code": {
"enum": [
"invalid_domain",
"bootstrap_unavailable",
"unsupported_tld",
"timeout",
"lookup_failed",
null
],
"type": [
"string",
"null"
]
},
"reasons": {
"description": "Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.",
"items": {
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"type": "array"
},
"registrar": {
"type": [
"string",
"null"
]
},
"registration_date": {
"type": [
"string",
"null"
]
},
"request_id": {
"description": "UUID for this request, also sent as the X-Request-Id response header.",
"type": "string"
},
"source": {
"type": [
"string",
"null"
]
},
"status": {
"description": "\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.",
"enum": [
"flagged",
"no_flags",
"unknown"
],
"type": "string"
},
"test_fixture": {
"description": "true only when the input was a documented integration test fixture and this response is canned; absent on real results.",
"type": "boolean"
}
},
"required": [
"found",
"available",
"domain"
],
"type": "object"
}
},
{
"description": "PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, synced daily by the sovereign-threat-pipeline. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for phishing/lookalike-domain screening of a hostname only. Do NOT use for domain registration age (use check_domain_age), general threat-feed indicator lookups (use get_ioc_context), or wallet sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { hostname, verdict, sources, lookalike_of, list_synced_at, checked_at, attribution }. verdict is one of \"allowlisted\", \"listed\", \"lookalike\", or \"not_listed\" — this tool never returns \"safe\" or \"clean\", and a not_listed result means the hostname is not on the eth-phishing-detect lists, not that it is safe. \"listed\" results include match_type \"exact\" or \"parent_domain\" in sources. \"lookalike\" flags a probable typosquat/homoglyph of a known brand — via confusable-character skeleton matching within the stored tolerance, or a brand keyword embedded with extra words (e.g. metamask-login.com) — even when the hostname itself is not directly listed, and sets lookalike_of to the matched brand domain. A brand's own real domain or a subdomain of it is never flagged as its own lookalike. VALIDATION: accepts exactly one bare hostname per call (no bulk input); a value containing a URL scheme, path, port, spaces, or a wildcard returns an MCP tool error (isError: true, code invalid_hostname) instead of a verdict. Fails loudly (returns an error) if the phishing list data is unreachable or times out, rather than ever reporting not_listed on a data failure. Rate-limited to 60 calls/hour per caller when unauthenticated; a valid Gumroad license key (X-API-KEY header) exempts the limit, same as check_domain_age. List contents are never exposed beyond the single matched entry.",
"inputSchema": {
"properties": {
"hostname": {
"description": "Mandatory bare hostname to screen, e.g. 'example.com'. Not a URL — no scheme, path, port, spaces, or wildcards. One hostname per call.",
"type": "string"
}
},
"required": [
"hostname"
],
"type": "object"
},
"name": "check_hostname_reputation",
"outputSchema": {
"properties": {
"attribution": {
"type": "string"
},
"checked_at": {
"type": "string"
},
"checks": {
"description": "Which underlying sources were checked for this result and whether each one completed.",
"items": {
"properties": {
"checked_at": {
"type": "string"
},
"data_as_of": {
"type": [
"string",
"null"
]
},
"result": {
"enum": [
"ok",
"timeout",
"error",
"skipped"
],
"type": "string"
},
"source": {
"description": "Generic label for the data source checked, never a vendor name.",
"type": "string"
}
},
"required": [
"source",
"result",
"checked_at",
"data_as_of"
],
"type": "object"
},
"type": "array"
},
"hostname": {
"description": "The hostname after normalization (trimmed, lowercased, trailing dot stripped, IDN converted to punycode).",
"type": "string"
},
"list_synced_at": {
"type": [
"string",
"null"
]
},
"lookalike_of": {
"description": "The matched brand/fuzzylist domain for a \"lookalike\" verdict, otherwise null.",
"type": [
"string",
"null"
]
},
"reasons": {
"description": "Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.",
"items": {
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"type": "array"
},
"request_id": {
"description": "UUID for this request, also sent as the X-Request-Id response header.",
"type": "string"
},
"sources": {
"items": {
"properties": {
"match_type": {
"enum": [
"allowlist",
"exact",
"parent_domain",
"confusable",
"keyword"
],
"type": "string"
},
"name": {
"type": "string"
},
"url": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"type": "array"
},
"status": {
"description": "\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.",
"enum": [
"flagged",
"no_flags",
"unknown"
],
"type": "string"
},
"test_fixture": {
"description": "true only when the input was a documented integration test fixture and this response is canned; absent on real results.",
"type": "boolean"
},
"verdict": {
"description": "Never \"safe\" or \"clean\".",
"enum": [
"allowlisted",
"listed",
"lookalike",
"not_listed"
],
"type": "string"
}
},
"required": [
"hostname",
"verdict",
"sources",
"lookalike_of",
"list_synced_at",
"checked_at",
"attribution"
],
"type": "object"
}
},
{
"description": "PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or out), plus whether the address is a contract. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet age/history only. Do NOT use for sanctions screening (use check_wallet_sanctions), domain age (use check_domain_age), or hostname/phishing reputation (use check_hostname_reputation). BEHAVIOR: Returns { address, chain, found, first_seen, age_days, first_seen_block, first_direction, is_contract, note, source: \"on-chain transfer history\", cached }. A found:false result (with all other fields null except is_contract) means the address has no transfer history on that chain — a normal, common result for a brand-new or never-used address, not an error, and not evidence of legitimacy either way; this tool reports age and history only. Upstream lookup failures or timeouts return an MCP tool error (isError: true) instead of found:false, since a data-source outage must never be read as \"brand-new wallet\". VALIDATION: address must be a 0x-prefixed 40-hex-character EVM address (case-insensitive); chain, if given, must be one of the supported enum values. Malformed input returns an MCP tool error (isError: true, code invalid_address or invalid_chain) instead of a result. Rate-limited to 60 calls/hour per caller when unauthenticated; a valid Gumroad license key (X-API-KEY header) exempts the limit, same as check_domain_age. A found result is cached permanently (it never changes); a found:false result is cached for 10 minutes only, since a wallet can become active at any time.",
"inputSchema": {
"properties": {
"address": {
"description": "Mandatory EVM wallet address to check, formatted '0x' followed by 40 hex characters (case-insensitive).",
"type": "string"
},
"chain": {
"default": "base",
"description": "Optional chain to check: 'base', 'ethereum', 'arbitrum', 'optimism', 'polygon', or 'bsc'. Defaults to 'base'.",
"enum": [
"base",
"ethereum",
"arbitrum",
"optimism",
"polygon",
"bsc",
null
],
"type": [
"string",
"null"
]
}
},
"required": [
"address"
],
"type": "object"
},
"name": "check_wallet_age",
"outputSchema": {
"properties": {
"address": {
"description": "The address, lowercased.",
"type": "string"
},
"age_days": {
"type": [
"integer",
"null"
]
},
"cached": {
"type": "boolean"
},
"chain": {
"type": "string"
},
"checks": {
"description": "Which underlying sources were checked for this result and whether each one completed.",
"items": {
"properties": {
"checked_at": {
"type": "string"
},
"data_as_of": {
"type": [
"string",
"null"
]
},
"result": {
"enum": [
"ok",
"timeout",
"error",
"skipped"
],
"type": "string"
},
"source": {
"description": "Generic label for the data source checked, never a vendor name.",
"type": "string"
}
},
"required": [
"source",
"result",
"checked_at",
"data_as_of"
],
"type": "object"
},
"type": "array"
},
"delegate_address": {
"description": "The lowercased delegate contract address when delegated is true, otherwise null.",
"type": [
"string",
"null"
]
},
"delegated": {
"description": "true when the address currently has an EIP-7702 delegation on this chain (its code is exactly 0xef0100 followed by a 20-byte delegate address), false when it does not, null when the code check did not complete. Checked live on every call, never cached. is_contract is unchanged and is still true for a delegated address.",
"type": [
"boolean",
"null"
]
},
"first_direction": {
"enum": [
"in",
"out",
null
],
"type": [
"string",
"null"
]
},
"first_seen": {
"description": "ISO timestamp of the earliest observed transfer in or out, or null if none found.",
"type": [
"string",
"null"
]
},
"first_seen_block": {
"type": [
"integer",
"null"
]
},
"found": {
"type": "boolean"
},
"is_contract": {
"type": "boolean"
},
"note": {
"type": [
"string",
"null"
]
},
"reasons": {
"description": "Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.",
"items": {
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"type": "array"
},
"request_id": {
"description": "UUID for this request, also sent as the X-Request-Id response header.",
"type": "string"
},
"source": {
"type": "string"
},
"status": {
"description": "\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.",
"enum": [
"flagged",
"no_flags",
"unknown"
],
"type": "string"
},
"test_fixture": {
"description": "true only when the input was a documented integration test fixture and this response is canned; absent on real results.",
"type": "boolean"
}
},
"required": [
"address",
"chain",
"found",
"first_seen",
"age_days",
"first_seen_block",
"first_direction",
"is_contract",
"source",
"cached"
],
"type": "object"
}
},
{
"description": "PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet/address sanctions screening only. Do NOT use for IP/domain/hash/URL threat lookups (use get_ioc_context) or CVE data (use get_cve_details). BEHAVIOR: Returns { listed: true|false, matches, source, list_last_synced }. A listed:false result means the address is not on the OFAC SDN list as of the reported sync time — it is informational only, not legal or sanctions-compliance advice, and is never phrased as \"safe\" or \"clean\". Fails loudly (returns an error) if the sanctions data is empty or unreachable, rather than ever reporting listed:false on a data failure. VALIDATION: if the address does not match a recognised format for any supported currency (EVM, BTC/LTC/BCH/DOGE/DASH/ZEC base58 or bech32/cashaddr, TRON, Monero, Solana), returns an MCP tool error (isError: true, code invalid_address) instead of a result — it never reports listed:false for malformed input.",
"inputSchema": {
"properties": {
"address": {
"description": "Mandatory wallet address to screen, e.g. an EVM 0x address, a bech32 (bc1/tb1/ltc1...) address, or a base58 address.",
"type": "string"
},
"currency": {
"description": "Optional currency/chain filter to narrow the match, e.g. 'BTC', 'ETH', 'XMR'.",
"type": [
"string",
"null"
]
}
},
"required": [
"address"
],
"type": "object"
},
"name": "check_wallet_sanctions",
"outputSchema": {
"properties": {
"address": {
"description": "The address exactly as submitted.",
"type": "string"
},
"address_normalized": {
"description": "The address after normalization, used to match against sanctioned_wallets.",
"type": "string"
},
"checks": {
"description": "Which underlying sources were checked for this result and whether each one completed.",
"items": {
"properties": {
"checked_at": {
"type": "string"
},
"data_as_of": {
"type": [
"string",
"null"
]
},
"result": {
"enum": [
"ok",
"timeout",
"error",
"skipped"
],
"type": "string"
},
"source": {
"description": "Generic label for the data source checked, never a vendor name.",
"type": "string"
}
},
"required": [
"source",
"result",
"checked_at",
"data_as_of"
],
"type": "object"
},
"type": "array"
},
"disclaimer": {
"type": "string"
},
"list_last_synced": {
"type": "string"
},
"listed": {
"type": "boolean"
},
"matches": {
"items": {
"properties": {
"currency": {
"type": [
"string",
"null"
]
},
"programs": {
"items": {
"type": "string"
},
"type": "array"
},
"sdn_name": {
"type": [
"string",
"null"
]
},
"sdn_uid": {
"type": [
"string",
"number",
"null"
]
}
},
"type": "object"
},
"type": "array"
},
"message": {
"type": "string"
},
"reasons": {
"description": "Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.",
"items": {
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"type": "array"
},
"request_id": {
"description": "UUID for this request, also sent as the X-Request-Id response header.",
"type": "string"
},
"source": {
"type": "string"
},
"status": {
"description": "\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.",
"enum": [
"flagged",
"no_flags",
"unknown"
],
"type": "string"
},
"test_fixture": {
"description": "true only when the input was a documented integration test fixture and this response is canned; absent on real results.",
"type": "boolean"
}
},
"required": [
"address",
"address_normalized",
"listed",
"matches",
"source",
"list_last_synced"
],
"type": "object"
}
},
{
"description": "PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA KEV status — same enrichment as get_cve_details, batched. Payment required: $0.01 via x402, sent in params._meta['x402/payment'] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for looking up several known CVE ids at once (e.g. from an SBOM or scan report). Do NOT use for a single CVE (use get_cve_details, lower overhead) or for discovering CVEs by vendor/product (use get_cve_by_product). BEHAVIOR: Accepts up to 20 ids per call; malformed or not-found ids are reported per-entry rather than failing the whole batch.",
"inputSchema": {
"properties": {
"cve_ids": {
"description": "Array of CVE identifiers, each formatted 'CVE-YYYY-NNNN'. Max 20 per call.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"cve_ids"
],
"type": "object"
},
"name": "get_cve_batch",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status, sorted by exploitation risk. Sourced from NVD keyword search. Payment required: $0.01 via x402, sent in params._meta[\"x402/payment\"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for discovering CVEs by vendor/product when you do not already have an exact CVE id. Do NOT use for a known CVE id (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Uses NVD keyword search, not strict CPE matching — results may include near-matches. BEHAVIOR: Returns up to 50 results per call.",
"inputSchema": {
"properties": {
"only_kev": {
"description": "If true, only return CVEs on the CISA KEV list.",
"type": "boolean"
},
"product": {
"description": "Product name, e.g. 'log4j'.",
"type": "string"
},
"vendor": {
"description": "Vendor name, e.g. 'apache'.",
"type": "string"
},
"version": {
"description": "Optional specific version, e.g. '2.14.1'.",
"type": "string"
}
},
"required": [
"vendor",
"product"
],
"type": "object"
},
"name": "get_cve_by_product",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile), and the CISA Known Exploited Vulnerabilities catalog (active wild exploitation status). Payment required: $0.01 via x402, sent in params._meta[\"x402/payment\"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for specific CVE lookups. Do NOT use for IP/domain/hash enrichment (use get_ioc_context) or bulk feed ingestion (use get_threat_indicators). USAGE EXCLUSIONS: Does not support wildcard search or threat-actor dossier profiling. BEHAVIOR: If payment is missing or fails, returns a normal tool result with isError: true, the x402 v2 PaymentRequired object in structuredContent and the same JSON in content[0].text; on success the settlement receipt is in result._meta[\"x402/payment-response\"]. Returns 404 if CVE is not found.",
"inputSchema": {
"properties": {
"cve_id": {
"description": "Mandatory official CVE identifier string strictly formatted as 'CVE-YYYY-NNNN' (e.g., 'CVE-2021-44228').",
"type": "string"
}
},
"required": [
"cve_id"
],
"type": "object"
},
"name": "get_cve_details",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents. Each returns the same aggregated provenance as get_ioc_context from ThreatFox, URLhaus, and OTX. SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. all URLs an agent is about to visit). Do NOT use for a single indicator (use get_ioc_context, lower overhead) or bulk feed synchronization (use get_threat_indicators). BEHAVIOR: Accepts up to 20 indicators per call. A found:false result for any indicator means nothing bad is recorded in PG1's sources — NOT that it's safe. If NONE of the submitted indicators are found, the whole batch is FREE — no payment or free-tier quota consumed. If at least one indicator is found, the normal payment gate (x402 via params._meta['x402/payment'], with the PAYMENT-SIGNATURE header also accepted, or a Gumroad X-API-KEY license) applies to the full batch result.",
"inputSchema": {
"properties": {
"values": {
"description": "Array of indicator values (IPv4 addresses, domains, URLs, or hashes) to look up. Max 20 per call.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"values"
],
"type": "object"
},
"name": "get_ioc_batch",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents before visiting, downloading, or connecting to something. Returns aggregated provenance from ThreatFox, URLhaus, and OTX — reporting sources, observation count, aggregated confidence score, known malware families, tags, and first/last seen timestamps. SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of a single indicator. Do NOT use for bulk intelligence downloads (use get_threat_indicators), multiple indicators at once (use get_ioc_batch), or software vulnerability analysis (use get_cve_details). BEHAVIOR: Returns a normal result shaped { found: true, indicator_type, provenance } or { found: false } — never an error for 'not found'. A found:false result means nothing bad is recorded in PG1's sources; it does NOT mean the indicator is safe, only that it isn't in this dataset. Lookups that return found:false are FREE — no payment or free-tier quota is consumed. Payment (x402 via params._meta['x402/payment'], with the PAYMENT-SIGNATURE header also accepted, or a Gumroad X-API-KEY license) is only required when a real record is found. If payment is required but missing or fails, the result has isError: true with the x402 v2 PaymentRequired object in structuredContent.",
"inputSchema": {
"properties": {
"value": {
"description": "Mandatory exact indicator string value to look up, such as an IPv4 address (198.51.100.1), fully qualified domain, complete URL, or SHA-256 hash string.",
"type": "string"
}
},
"required": [
"value"
],
"type": "object"
},
"name": "get_ioc_context",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associated malware/tooling. Sourced from MITRE ATT&CK Enterprise. Payment required: $0.01 via x402, sent in params._meta['x402/payment'] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for actor/group-level profiling. Do NOT use for single-indicator lookups (use get_ioc_context) or vulnerability data (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Coverage is limited to groups tracked in MITRE ATT&CK — not all threat actors have an entry. BEHAVIOR: Returns 404 if no matching group or alias is found.",
"inputSchema": {
"properties": {
"actor_name": {
"description": "Group name or known alias, e.g. 'APT29' or 'Cozy Bear'. Matching is case-insensitive against both the group's primary name and its known aliases.",
"type": "string"
}
},
"required": [
"actor_name"
],
"type": "object"
},
"name": "get_threat_actor_profile",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from ThreatFox, URLhaus, OTX and NVD. Payment required: $0.01 via x402, sent in params._meta[\"x402/payment\"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for bulk feed synchronizations. Do NOT use for single-item lookups (use get_ioc_context) or CVE analysis (use get_cve_details). USAGE EXCLUSIONS: Does not provide historical query archival beyond the active ingestion window. BEHAVIOR: Pagination is handled via the limit parameter (max 1000). If payment is missing or fails, returns a normal tool result with isError: true, the x402 v2 PaymentRequired object in structuredContent and the same JSON in content[0].text; on success the settlement receipt is in result._meta[\"x402/payment-response\"].",
"inputSchema": {
"properties": {
"limit": {
"default": 500,
"description": "Pagination boundary constraint defining the maximum number of indicators to return in a single payload (integer between 1 and 1000, defaulting to 500).",
"type": [
"integer",
"null"
]
},
"min_score": {
"description": "Confidence score threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise.",
"type": [
"integer",
"null"
]
},
"since": {
"description": "ISO timestamp constraint (e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after this exact timestamp.",
"type": [
"string",
"null"
]
},
"type": {
"description": "Indicator category filter. Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or 'FileHash-SHA256'.",
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"name": "get_threat_indicators",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is always free.",
"inputSchema": {
"properties": {
"identifier": {
"description": "Optional — the X-API-KEY or identifier to check usage for; defaults to the calling identifier if omitted.",
"type": "string"
},
"license_key": {
"description": "Optional — check Gumroad license status alongside free-tier usage.",
"type": "string"
}
},
"type": "object"
},
"name": "get_usage_status",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402. Submissions are staged for review, not immediately added to the live feed.",
"inputSchema": {
"properties": {
"confidence": {
"description": "Submitter's own confidence, 0-100.",
"type": "integer"
},
"indicator": {
"type": "string"
},
"indicator_type": {
"type": "string"
},
"malware_family": {
"description": "Optional.",
"type": "string"
},
"source_note": {
"description": "Optional free-text on how this was observed.",
"type": "string"
}
},
"required": [
"indicator",
"indicator_type"
],
"type": "object"
},
"name": "submit_indicator",
"outputSchema": null
},
{
"description": "PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook URL as they're ingested. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402, since it establishes a recurring subscription rather than a single paid call.",
"inputSchema": {
"properties": {
"filter": {
"description": "Optional filter object: { indicator_type, min_epss, kev_only }",
"properties": {
"indicator_type": {
"type": "string"
},
"kev_only": {
"type": "boolean"
},
"min_epss": {
"type": "number"
}
},
"type": "object"
},
"webhook_url": {
"description": "HTTPS URL to receive POSTed alert payloads.",
"type": "string"
}
},
"required": [
"webhook_url"
],
"type": "object"
},
"name": "subscribe_alerts",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:a92f52db9a3e02dd93a015654d2f998457dc7cf81dae7f22118b3627766447d7 | sha256sum