Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,534Letters: 14Defects: 1,322counted 3 min ago
teppi

MCP serverio.github.maco144/nullcone

Real-time threat intel for AI agents: 890K+ IOCs incl.
Read moreReal-time threat intel for AI agents: 890K+ IOCs incl. prompt-injection & AI-skill threats
UNRATEDActivestreamable-httpnullcone.ai

Overview

Score?
UNRATED 0.611
of what a free look can see, on 31 looks
Looks
34
last 5 hr ago
Tools
30

More info

URL
nullcone.ai/mcp
streamable-http
Says it is
Nullcone Threat Intelligence 1.30.0
protocol 2025-06-18
In the record since
32 days ago

Among servers18,413 with a card

0median 0.606 · this server 0.611 · highest on record 0.8561

Toolsfrom sha256:9a3b55c7db…1456de

The tools this server lists, read out of the definition it returned
ToolSchema
check_freshness
Validate that IOC threat intelligence is fresh enough for the named action. Call this before any high-risk agent action to ensure the TI snapshot is not stale. The ch
input · no output
check_prompt
Check a prompt or text fragment for known PROMPT IOC patterns. Uses an in-memory hash set for sub-1ms token-level querying — no network calls after the cache is warme
input · no output
check_prompt_batch
Check multiple prompts for PROMPT IOC patterns in a single call. More efficient than calling check_prompt() in a loop — tokenization overhead is amortized and the cac
input · output
drain_subscription
Drain the buffer of a stateful subscription created by subscribe_threats(). Returns all IOCs delivered to this subscription since the last drain. Each subscription is
input · no output
family_threats
Return all threat signatures associated with a known malware family. Use list_families() first to discover available family names. Args: family_name: Exact m
input · output
fingerprint_tool_metadata
Analyze an MCP tool definition for instruction-injection and malicious patterns. Performs semantic fingerprinting of the tool's description, parameter schemas, and er
input · no output
freshness_limits
Return the configured IOC freshness limits for all action tiers. Shows max staleness, warn threshold, and which actions belong to each tier. Use this to understand wh
input · no output
get_new_threats
Drain the live push-subscription buffer of threats received since the last call. Zero-polling — threats are delivered via SpacetimeDB WebSocket subscription and buffer
input · no output
get_stats
Return aggregate statistics for the threat intelligence database. Includes total signatures, known malware families, active agents, and total detection events.
input · no output
is_ioc_revoked
Check whether an IOC has been revoked. O(1) in-process lookup. Use this before acting on any cached threat intelligence to ensure the IOC has not been retracted since
input · no output
list_families
Return all known malware families in the intelligence database. Each entry includes the family name, description, and category. Use family_threats(family_name) to ret
input · output
list_revocations
List recent IOC revocations, newest first. Args: limit: Maximum number of revocations to return (default 50). since_hours: Only return revocations n
input · no output
list_subscriptions
List all active stateful push subscriptions on this MCP server instance. Returns metadata for each subscription (not the buffered IOCs themselves). Useful for inspect
input · output
lookup_ioc
Look up a threat signature by its exact IOC value. Returns the full signature record if found, including severity, family, detection count, and false positive votes.
input · no output
poll_since
Fetch new threat signatures since a high-water mark ID. This is the recommended sync pattern — one call, get new data, persist next_id, disconnect. No persistent conne
input · no output
prompt_cache_stats
Return PROMPT IOC cache statistics: size, hit rate, latency, refresh status. Use this to verify the cache is warmed and healthy before relying on check_prompt() for r
input · no output
recent_threats
Return the most recently observed threat signatures. Args: limit: Max number of results to return (1-200) min_severity: Minimum severity level (0-1
input · output
registry_flagged_tools
Return all MCP tools that have been flagged as suspicious or malicious. Includes tools flagged on initial ingestion (high-risk fingerprint) and tools that showed sign
input · output
registry_monitor_stats
Return MCP registry monitoring statistics. Shows how many tool definitions are tracked, how many have been flagged, and the current drift detection rate.
input · no output
report_detection
Report that you detected and acted on a known threat signature. Increments the signature's detection count and creates a ThreatEvent visible to all other agents in re
input · no output
revoke_ioc
Revoke an IOC by its value hash, pushing the expiration event to all active subscriptions in real-time. Call this when an IOC is determined to be a false positive, ex
input · no output
scan_skill_content
Pre-execution content scan for skill/instruction files. Analyzes the full text of a skill (markdown, plain text, SKILL.md, etc.) for malicious patterns BEFORE the age
input · no output
search_by_type
Return threat signatures filtered by IOC type. Useful for pulling all known-bad IPs, all malicious domains, all malicious AI skill hashes, etc. Args: ioc
input · output
submit_batch
Submit multiple IOCs in a single call. Preferred over looping submit_ioc for bulk ingest from honeypots, sandboxes, or feed processing. Each dict in `iocs` follows th
input · output
submit_ioc
Submit a threat indicator (IOC) to the shared intelligence network. The IOC is automatically classified into a malware family, metadata is compressed, and deduplicati
input · no output
subscribe_threats
Open a named, stateful subscription to live threat push delivery. Returns a subscription_id. Pass it to drain_subscription() to collect the IOCs that have arrived sin
input · no output
unsubscribe
Cancel a stateful subscription and free its buffer. Call this when you no longer need the subscription to release memory. Subscriptions also auto-expire after 1 hour
input · no output
validate_skill
Synchronous SKILL IOC lookup — call this before loading or invoking any MCP tool/skill to check it against the Nullcone threat feed. This is the pre-invocation enforc
input · no output
vote_false_positive
Flag a threat signature as a likely false positive. When more than 20% of agents vote false positive on a signature, its `is_likely_fp` flag becomes True — a signal t
input · no output
warm_prompt_cache
Load all PROMPT IOCs from SpacetimeDB into the in-memory hash set. Call once at startup (or after a major feed update) to populate the sub-1ms query cache. Subsequent
input · no output
Verify it yourselfnpx teppi-check https://nullcone.ai/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2GHCYBWG8B0E2G0858M6