MCP Threatintel runs on your own machine — the client starts it, so there is no endpoint to ping. 81 installs a week from npm. Last commit 9 Aug 2026.
Unified threat intel - OTX, AbuseIPDB, GreyNoise, abuse.ch, Feodo Tracker
Today is the operative word: we check MCP Threatintel every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcp-threatintel -- npx -y mcp-threatintel-server
{
"mcpServers": {
"mcp-threatintel": {
"args": [
"-y",
"mcp-threatintel-server"
],
"command": "npx"
}
}
}
[mcp_servers.mcp-threatintel]
command = "npx"
args = ["-y", "mcp-threatintel-server"]
{
"mcpServers": {
"mcp-threatintel": {
"args": [
"-y",
"mcp-threatintel-server"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"mcp-threatintel": {
"args": [
"-y",
"mcp-threatintel-server"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
OTX_API_KEY (AlienVault OTX API key (free at otx.alienvault.com)), ABUSEIPDB_API_KEY (AbuseIPDB API key (free at abuseipdb.com)), GREYNOISE_API_KEY (GreyNoise API key (free at greynoise.io)), ABUSECH_AUTH_KEY (abuse.ch Auth Key for URLhaus, MalwareBazaar, ThreatFox (free at auth.abuse.ch)).
The author declared them in the registry entry; get the values from the project itself.
abuse.ch Feodo Tracker botnet C&C IP blocklist
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
MCP server for GreyNoise API - Check if IPs are internet background noise or targeted attacks
Multi-CI security scanner with a live threat-intel feed of compromised CI components
GreyNoise Community MCP — internet scanner classification (free tier with key)
AI Incident Reporting Compliance MCP. Unified classification + reporting-clock tracker across EU...
Google Search Console + Bing + GA4 + AdSense — unified SEO intelligence for AI agents.
Character-precise unified diff + patch application + patch parsing.
Answers built from our own checks of this server.