mcpbeat Sign in

PG1 Sovereign Threat Intelligence MCP Server

by project-gifted1 Your server? Claim it
answering

PG1 Sovereign Threat Intelligence is answering right now. Last checked 10 min ago. It exposes 1 tools. Last commit 22 Sep 2026.

STIX 2.1 threat indicator feed: IPs, domains, URLs, file hashes from ThreatFox, OTX, NVD.

Uptime history 33 hours of history
33 hours agonow
100.0%
Uptime 24h
91 of 91 checks
1
Tools
read from the server
301 ms
Response time
average over 24h
0
Stars
last commit 22 Sep 2026

What the code does

We read the source, 9 h ago · tools taken from the live server · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

      new Function(testCode);
Page executes code built at runtime public/index.html:500
        document.getElementById('chat-container').innerHTML = savedState;

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.

run in your terminal
claude mcp add pg1-threat-intel --transport http https://pg1-ai-agent.vercel.app/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "pg1-threat-intel": {
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.pg1-threat-intel]
url = "https://pg1-ai-agent.vercel.app/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "pg1-threat-intel": {
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "pg1-threat-intel": {
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

threat
get_threat_indicators
PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from ThreatFox, URLhaus, AbuseIPDB, OTX and NVD. Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header).

Endpoints

URLTransportStateLatencyChecked
https://pg1-ai-agent.vercel.app/api/mcp streamable-http answering 199 ms 10 min ago

Alternatives to PG1 Sovereign Threat Intelligence

same job, measured the same way
Maltiverse MCP
by mrfentmen

Threat intelligence for IPs and domains from Maltiverse. No key required.

local only
mlab.sh
by mlab

Threat intelligence: enrich IOCs (IP, domain, URL, hash), search CVEs and actors, scan SBOMs.

answering
Dnstwister MCP
by mrfentmen

DNS twister domain threat intelligence: fuzz domains for typosquatting, check whois.

local only
TweetFeed
by 0xdaniellopez

IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter. No auth, CC0.

14 tools answering
Threatfox
by pipeworx-io

ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)

35 tools answering
Supercolony
by randomblocker

Agent swarm intelligence — real-time feed and consensus signals from 140+ AI agents on-chain

50 installs/wk local only
I
Polarity
by radar989

Real-time threat intelligence lookups and IOC parsing from your self-hosted Polarity instance.

28 installs/wk local only
C
isMalicious threat intelligence for AI agents
by ismalicious

Indicator reputation verdicts, CVE lookups (CVSS, EPSS, KEV) and prompt-injection scans for agents

38 installs/wk local only

PG1 Sovereign Threat Intelligence — questions

Answers built from our own checks of this server.

What can PG1 Sovereign Threat Intelligence do?
It exposes 1 tools, read directly from the server on our last check. Among them: get_threat_indicators. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is PG1 Sovereign Threat Intelligence working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 301 ms. The bar chart above shows every period we have measured.
How do I connect PG1 Sovereign Threat Intelligence?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does PG1 Sovereign Threat Intelligence need an API key?
No. PG1 Sovereign Threat Intelligence completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is PG1 Sovereign Threat Intelligence?
It answers our handshake in 301 ms on average, which is faster than 53% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is PG1 Sovereign Threat Intelligence open source?
We cannot say either way: written in JavaScript and 0 stars on GitHub, but we could not determine the licence, and without one the code is not open source by default.