isMalicious threat intelligence for AI agents runs on your own machine — the client starts it, so there is no endpoint to ping. 66 installs a week from npm.
Indicator reputation verdicts, CVE lookups (CVSS, EPSS, KEV) and prompt-injection scans for agents
Today is the operative word: we check isMalicious threat intelligence for AI agents every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcp-server -- npx -y @ismalicious/mcp-server
{
"mcpServers": {
"mcp-server": {
"args": [
"-y",
"@ismalicious/mcp-server"
],
"command": "npx"
}
}
}
[mcp_servers.mcp-server]
command = "npx"
args = ["-y", "@ismalicious/mcp-server"]
{
"mcpServers": {
"mcp-server": {
"args": [
"-y",
"@ismalicious/mcp-server"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"mcp-server": {
"args": [
"-y",
"@ismalicious/mcp-server"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
ISMALICIOUS_API_KEY (API key from https://ismalicious.com/app/account. Optional: without it the server starts in bootstrap mode and offers bootstrap_key.), ISMALICIOUS_API_SECRET (API secret paired with the key), ISMALICIOUS_API_BASE (API base URL (defaults to https://ismalicious.com/api)), ISMALICIOUS_TIMEOUT_MS (Replaces every tool's timeout, in milliseconds (defaults: gate 15000, check_indicator 25000, CVE 10000)).
The author declared them in the registry entry; get the values from the project itself.
Real-time threat intel for AI agents: 890K+ IOCs incl. prompt-injection & AI-skill threats
HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.
A real inbox for AI agents: send, receive and thread email, behind a prompt-injection firewall.
Security intelligence via x402 on Base. CVE lookup, IP reputation, secret scanning.
Domain intelligence for DNS, WHOIS/RDAP, TLS, reputation, valuation, and brand protection.
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
Real-time Ethereum liquidation intelligence for AI agents and MEV bots.
Regulatory intelligence for AI agents across jurisdictions
Answers built from our own checks of this server.