Atlas / MCP servers / 4r9un / Fast ThreatIntel

Fast ThreatIntelCAUTION

mcp/4r9un/fast-threatintel

AI-Powered Threat Intelligence MCP tool

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
—
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/4r9un-fastmcp-threatintel)

[](https://github.com/4R9UN/fastmcp-threatintel/actions/workflows/ci.yml) [](https://codecov.io/gh/4R9UN/fastmcp-threatintel) [](https://badge.fury.io/py/fastmcp-threatintel) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/Apache-2.0) [](https://hub.docker.com/r/arjuntrivedi/fastmcp-threatintel) [](https://mseep.ai/app/09be09c3-bda9-4cb9-82d3-329459fecbc7)

🚀 MCP AI Powered Threat Intelligence - Revolutionizing Cybersecurity Built by Arjun Trivedi (4R9UN) - Enterprise-Grade Threat Intelligence Platform

A comprehensive Model Context Protocol (MCP) server that provides enterprise-grade threat intelligence capabilities through natural language AI prompts. Analyze IPs, domains, URLs, and file hashes across multiple threat intelligence platforms with advanced APT attribution and interactive reporting.

✨ Why FastMCP ThreatIntel?

🎯 Purpose-Built for Modern Security Teams

  • 🤖 AI-First Design: Natural language queries with intelligent IOC detection
  • 🔗 MCP Integration: Seamless integration with Claude Desktop, VSCode (Roo-Cline), and other AI assistants
  • ⚡ Lightning Fast: UV-powered development with optimized async proces
Read from source at commit 2e602bd24499OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add fastmcp-threatintel --env ABUSEIPDB_API_KEY=${ABUSEIPDB_API_KEY} --env IPINFO_API_KEY=${IPINFO_API_KEY} --env OTX_API_KEY=${OTX_API_KEY} --env VIRUSTOTAL_API_KEY=${VIRUSTOTAL_API_KEY} -- uvx fastmcp-threatintel
claude-desktop
{
  "mcpServers": {
    "fastmcp-threatintel": {
      "command": "uvx",
      "args": [
        "fastmcp-threatintel"
      ],
      "env": {
        "ABUSEIPDB_API_KEY": "${ABUSEIPDB_API_KEY}",
        "IPINFO_API_KEY": "${IPINFO_API_KEY}",
        "OTX_API_KEY": "${OTX_API_KEY}",
        "VIRUSTOTAL_API_KEY": "${VIRUSTOTAL_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_iocsread
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (10)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.git_disabled/index
index
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
.git_disabled/objects/00/28b269b4de4de8cbe98a2243aa501160a6a7ab
28b269b4de4de8cbe98a2243aa501160a6a7ab
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
.git_disabled/objects/03/7ffc4830a766d7406eed2e1123cd19d5306f91
7ffc4830a766d7406eed2e1123cd19d5306f91
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
.git_disabled/objects/04/ff31d8ae9a4464b73981994ee54f9906300d43
ff31d8ae9a4464b73981994ee54f9906300d43
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
.git_disabled/objects/05/f2af7c386caaf86ff77b997e7aaea13b5de18a
f2af7c386caaf86ff77b997e7aaea13b5de18a
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
INFOInventory / provenance · inv.oversize · CWE-1104
.git_disabled/objects/b6/57ab17467653e32c2019fc81c3cf201e32d3f2
.git_disabled/objects/b6/57ab17467653e32c2019fc81c3cf201e32d3f2
Why it matters. 2984972 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
.git_disabled/objects/df/35c5783b2afab12dbd2e61ff43674cf8c1fddb
.git_disabled/objects/df/35c5783b2afab12dbd2e61ff43674cf8c1fddb
Why it matters. 2984076 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/Demo.gif
src/Demo.gif
Why it matters. 3092025 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 2e602bd24499full audit observations/trust-audit/mcp-server/4r9un__fast-threatintel.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082e602bd24499CAUTIONB82first audit
06

Questions

What is the Fast ThreatIntel MCP server?

AI-Powered Threat Intelligence MCP tool

What tools does Fast ThreatIntel expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Fast ThreatIntel safe to connect to an agent?

With care. The audit graded it B (82/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Fast ThreatIntel need?

It reads ABUSEIPDB_API_KEY, IPINFO_API_KEY, OTX_API_KEY and VIRUSTOTAL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (2e602bd24499), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement