Fast ThreatIntelCAUTION
AI-Powered Threat Intelligence MCP tool
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/4r9un-fastmcp-threatintel)
[](https://github.com/4R9UN/fastmcp-threatintel/actions/workflows/ci.yml) [](https://codecov.io/gh/4R9UN/fastmcp-threatintel) [](https://badge.fury.io/py/fastmcp-threatintel) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/Apache-2.0) [](https://hub.docker.com/r/arjuntrivedi/fastmcp-threatintel) [](https://mseep.ai/app/09be09c3-bda9-4cb9-82d3-329459fecbc7)
🚀 MCP AI Powered Threat Intelligence - Revolutionizing Cybersecurity Built by Arjun Trivedi (4R9UN) - Enterprise-Grade Threat Intelligence Platform
A comprehensive Model Context Protocol (MCP) server that provides enterprise-grade threat intelligence capabilities through natural language AI prompts. Analyze IPs, domains, URLs, and file hashes across multiple threat intelligence platforms with advanced APT attribution and interactive reporting.
✨ Why FastMCP ThreatIntel?
🎯 Purpose-Built for Modern Security Teams
- 🤖 AI-First Design: Natural language queries with intelligent IOC detection
- 🔗 MCP Integration: Seamless integration with Claude Desktop, VSCode (Roo-Cline), and other AI assistants
- ⚡ Lightning Fast: UV-powered development with optimized async proces
2e602bd24499OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add fastmcp-threatintel --env ABUSEIPDB_API_KEY=${ABUSEIPDB_API_KEY} --env IPINFO_API_KEY=${IPINFO_API_KEY} --env OTX_API_KEY=${OTX_API_KEY} --env VIRUSTOTAL_API_KEY=${VIRUSTOTAL_API_KEY} -- uvx fastmcp-threatintel{
"mcpServers": {
"fastmcp-threatintel": {
"command": "uvx",
"args": [
"fastmcp-threatintel"
],
"env": {
"ABUSEIPDB_API_KEY": "${ABUSEIPDB_API_KEY}",
"IPINFO_API_KEY": "${IPINFO_API_KEY}",
"OTX_API_KEY": "${OTX_API_KEY}",
"VIRUSTOTAL_API_KEY": "${VIRUSTOTAL_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_iocs | read |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (10)
index
28b269b4de4de8cbe98a2243aa501160a6a7ab
7ffc4830a766d7406eed2e1123cd19d5306f91
ff31d8ae9a4464b73981994ee54f9906300d43
f2af7c386caaf86ff77b997e7aaea13b5de18a
.pre-commit-config.yaml
.git_disabled/objects/b6/57ab17467653e32c2019fc81c3cf201e32d3f2
.git_disabled/objects/df/35c5783b2afab12dbd2e61ff43674cf8c1fddb
src/Demo.gif
Gates applied: no_behavioural_pass, no_license.
2e602bd24499full audit observations/trust-audit/mcp-server/4r9un__fast-threatintel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2e602bd24499 | CAUTION | B | 82 | first audit |
Questions
What is the Fast ThreatIntel MCP server?
AI-Powered Threat Intelligence MCP tool
What tools does Fast ThreatIntel expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Fast ThreatIntel safe to connect to an agent?
With care. The audit graded it B (82/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Fast ThreatIntel need?
It reads ABUSEIPDB_API_KEY, IPINFO_API_KEY, OTX_API_KEY and VIRUSTOTAL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (2e602bd24499), read on 2026-10-08. The repository is watched and re-audited when it changes.