PG1 Sovereign Threat Intelligence is answering right now. Last checked 10 min ago. It exposes 1 tools. Last commit 22 Sep 2026.
STIX 2.1 threat indicator feed: IPs, domains, URLs, file hashes from ThreatFox, OTX, NVD.
We read the source, 9 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
new Function(testCode);
document.getElementById('chat-container').innerHTML = savedState;
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.
claude mcp add pg1-threat-intel --transport http https://pg1-ai-agent.vercel.app/api/mcp
{
"mcpServers": {
"pg1-threat-intel": {
"url": "https://pg1-ai-agent.vercel.app/api/mcp"
}
}
}
[mcp_servers.pg1-threat-intel]
url = "https://pg1-ai-agent.vercel.app/api/mcp"
{
"mcpServers": {
"pg1-threat-intel": {
"url": "https://pg1-ai-agent.vercel.app/api/mcp"
}
}
}
{
"mcpServers": {
"pg1-threat-intel": {
"url": "https://pg1-ai-agent.vercel.app/api/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
get_threat_indicators
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://pg1-ai-agent.vercel.app/api/mcp | streamable-http | answering | 199 ms | 10 min ago |
Threat intelligence for IPs and domains from Maltiverse. No key required.
Threat intelligence: enrich IOCs (IP, domain, URL, hash), search CVEs and actors, scan SBOMs.
DNS twister domain threat intelligence: fuzz domains for typosquatting, check whois.
IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter. No auth, CC0.
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
Agent swarm intelligence — real-time feed and consensus signals from 140+ AI agents on-chain
Real-time threat intelligence lookups and IOC parsing from your self-hosted Polarity instance.
Indicator reputation verdicts, CVE lookups (CVSS, EPSS, KEV) and prompt-injection scans for agents
Answers built from our own checks of this server.