Threatfox is answering right now. Last checked 5 min ago. It exposes 35 tools. Last commit 13 Sep 2026.
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 8 August 2026. No other catalogue keeps this.
Today is the operative word: we check Threatfox every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 5 min ago.
claude mcp add threatfox --transport http https://gateway.pipeworx.io/threatfox/mcp
{
"mcpServers": {
"threatfox": {
"url": "https://gateway.pipeworx.io/threatfox/mcp"
}
}
}
[mcp_servers.threatfox]
url = "https://gateway.pipeworx.io/threatfox/mcp"
{
"mcpServers": {
"threatfox": {
"url": "https://gateway.pipeworx.io/threatfox/mcp"
}
}
}
{
"mcpServers": {
"threatfox": {
"url": "https://gateway.pipeworx.io/threatfox/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
polymarket_arbitrage
polymarket_edge_tracker
polymarket_edges
polymarket_fill_risk
polymarket_kalshi_spread
ask_pipeworx
ask_pipeworx_beta
ask_pipeworx_grounded
recent_alerts
recent_changes
recent_iocs
pipeworx_feedback
pipeworx_trending
scan_competitor_ai_presence
scan_dependency
bet_research
compare_entities
deep_research
discover_tools
entity_profile
forget
generate_llms_txt
search_hash
search_ioc
search_malware
recall
remember
resolve_entity
subscribe
list_subscriptions
suggest_questions
unsubscribe
validate_claim
ai_visibility_check
search_within
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://gateway.pipeworx.io/threatfox/mcp | streamable-http | answering | 85 ms | 5 min ago |
MalwareBazaar MCP — abuse.ch malware sample database (free, key required)
Free Bing search MCP server - No API key required
Multi-CI security scanner with a live threat-intel feed of compromised CI components
OpenFDA MCP — wraps the openFDA API (free, no auth required)
CoinGecko MCP — wraps CoinGecko free API (no auth required)
the-committee MCP — wraps StupidAPIs (requires X-API-Key)
OWID MCP — Our World in Data chart/indicator access (free, no auth)
Pirate Weather forecast API (Dark Sky-compatible). Free key required.
Answers built from our own checks of this server.