Server definition
- Hash
- sha256:cf91853ef4050a86b0172a5f595ba54b13a11b3c6be6b9d03fbc9705dca4d5be
- What it is
- What a remote MCP server returned when asked what it offers: 12 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"asn": {
"type": "string"
},
"since_ms": {
"type": "integer"
}
},
"required": [
"asn"
],
"type": "object"
},
"name": "scry_asn",
"outputSchema": null
},
{
"description": "Single campaign detail by id (format: c[0-9a-f]{15}).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"id": {
"pattern": "^c[0-9a-f]{15}$",
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"name": "scry_campaign",
"outputSchema": null
},
{
"description": "Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"include_inactive": {
"type": "boolean"
},
"limit": {
"maximum": 200,
"minimum": 1,
"type": "integer"
}
},
"type": "object"
},
"name": "scry_campaigns",
"outputSchema": null
},
{
"description": "Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last\nobserved, observation count, protocols and ports targeted, ASN, country, category\n(actor/scanner/not_observed), and confidence_bucket (low/medium/high).\n\nUse when an agent needs IP triage, hostility assessment, or risk signaling.\nDo NOT use for raw payloads (never exposed) or IPv6 (corpus is v4-only at v0.1).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"ip": {
"description": "IPv4 address (e.g. '8.8.8.8')",
"type": "string"
}
},
"required": [
"ip"
],
"type": "object"
},
"name": "scry_check",
"outputSchema": null
},
{
"description": "Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"ips": {
"items": {
"type": "string"
},
"maxItems": 100,
"minItems": 1,
"type": "array"
}
},
"required": [
"ips"
],
"type": "object"
},
"name": "scry_check_bulk",
"outputSchema": null
},
{
"description": "Roll-up of corpus activity by ISO country code. Same shape as scry_asn.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"country": {
"pattern": "^[A-Za-z]{2}$",
"type": "string"
},
"since_ms": {
"type": "integer"
}
},
"required": [
"country"
],
"type": "object"
},
"name": "scry_country",
"outputSchema": null
},
{
"description": "Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"country": {
"pattern": "^[A-Za-z]{2}$",
"type": "string"
},
"include_noise": {
"type": "boolean"
},
"limit": {
"maximum": 500,
"minimum": 1,
"type": "integer"
},
"protocol": {
"type": "string"
},
"since_ms": {
"type": "integer"
}
},
"type": "object"
},
"name": "scry_recent",
"outputSchema": null
},
{
"description": "Returns aggregate Scry corpus telemetry: total observation count, distinct\nsource IPs, first/last observation timestamps, last-24h activity, and\nper-protocol breakdowns. Useful as a liveness/density check before issuing\nper-IP queries — lets an agent decide whether the corpus has enough data\nto be authoritative.\n\nUse this tool when:\n- An agent is planning a multi-step investigation and wants to know if Scry\n has corpus density worth querying.\n- You want a 'corpus health' signal in a dashboard or report.\n\nDo NOT use this tool when:\n- You want details about a specific IP — use `scry_check`.\n- You want sensor fleet size or node identities — never exposed at any tier.\n\nInputs: none.\nReturns: total_observations, distinct_source_ips, first_seen_ms, last_seen_ms, observations_last_24h, distinct_source_ips_last_24h, by_protocol, as_of_ms.\nCost: free, anonymous, rate-limited.\nLatency: <100ms typical.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "scry_stats",
"outputSchema": null
},
{
"description": "Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"bucket": {
"enum": [
"minute",
"hour",
"day"
],
"type": "string"
},
"since_ms": {
"type": "integer"
},
"until_ms": {
"type": "integer"
}
},
"type": "object"
},
"name": "scry_timeseries",
"outputSchema": null
},
{
"description": "Single tool detail by 16-char hex id from scry_tools.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"id": {
"pattern": "^[0-9a-f]{16}$",
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"name": "scry_tool",
"outputSchema": null
},
{
"description": "List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"limit": {
"maximum": 200,
"minimum": 1,
"type": "integer"
},
"protocol": {
"type": "string"
},
"since_ms": {
"type": "integer"
}
},
"type": "object"
},
"name": "scry_tools",
"outputSchema": null
},
{
"description": "Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'",
"inputSchema": {
"additionalProperties": false,
"properties": {
"dimension": {
"enum": [
"asn",
"country",
"protocol",
"port"
],
"type": "string"
},
"include_noise": {
"type": "boolean"
},
"limit": {
"maximum": 100,
"minimum": 1,
"type": "integer"
},
"since_ms": {
"type": "integer"
}
},
"type": "object"
},
"name": "scry_top",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:cf91853ef4050a86b0172a5f595ba54b13a11b3c6be6b9d03fbc9705dca4d5be | sha256sum