Atlas / MCP servers / kincaidyang / Whois

WhoisCAUTION

mcp/kincaidyang/whois-5

Self-hosted WHOIS/RDAP API and MCP server for domains, IPv4/IPv6, CIDRs and ASNs.

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
—
Transport
streamable-http
License
MIT
Stars
64
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pkg.go.dev/github.com/KincaidYang/whois) [](https://github.com/KincaidYang/whois/actions/workflows/go.yml) [](https://github.com/KincaidYang/whois/actions/workflows/codeql.yml) [](https://codecov.io/gh/KincaidYang/whois) [](https://mcpqueen.com/s/io.github.KincaidYang/whois)

English

介绍

基于 Golang 实现的域名 Whois 查询工具,支持所有允许公开查询的 TLD 后缀的域名、IPv4/v6、ASN 的 Whois 信息查询。 根据 ICANN 《通用顶级域名注册数据临时政策细则(Temporary Specification for gTLD Registration Data)》和欧盟《通用数据保护条例》合规要求,在查询域名信息时,程序只返回了部分必要的信息(详见下方返回结果示例),不会返回所有者的联系方式、地址、电话、邮箱等字段。

演示站点:

使用方法

Docker部署

# 安装 Redis
docker run -d --name redis -p 6379:6379 redis:latest
# 运行 whois
docker run -d --name whois -p 8043:8043 --link redis:redis jinzeyang/whois
# 运行 whois(大陆推荐)
docker run -d --name whois -p 8043:8043 --link redis:redis docker.cnb.cool/kincaidyang/whois

下载

使用二进制文件

您可从 Release 页面下载对应平台的二进制文件。

从源码编译

git clone https://github.com/KincaidYang/whois.git
cd whois
go build

安装依赖

本程序默认使用内存缓存,可直接运行;生产环境或多实例部署建议搭配 Redis 使用,您可参照 https://redis.io/docs/install/install-redis/install-redis-on-linux/ 进行安装。

编辑配置文件

vim config.yaml
⚠️ 配置项按功能分组,键名为 camelCase(与 API 响应字段风格一致)。未知键或旧版(v0.9 之前)的扁平键会在启动时报错并给出迁移提示,不会再静默回退到默认值。
server:
port: 8043                   # 服务监听端口
rateLimit: 60                # 最大并发处理请求数,超出返回 429
upstreamLimit: 60            # 程
Read from source at commit da52312c67b0OBSERVED · 2026-10-07
02

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (2 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (17)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
.ide/Dockerfile:8
rm -rf /var/lib/apt/lists/*
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
.ide/Dockerfile:12
rm -rf /usr/local/go && tar -C /usr/local -xzf go${GO_VERSION}.linux-amd64.tar.gz &&\
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cnb.yml
.cnb.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yml
.goreleaser.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ide/.goreleaser.yml
.goreleaser.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
CHANGELOG.md:24
(RFC 1918 / ULA), link-local (including the `169.254.169.254` cloud
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
internal/netguard/netguard_test.go:19
"169.254.169.254":  true, // cloud metadata
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
internal/netguard/netguard_test.go:43
for _, addr := range []string{"127.0.0.1:443", "[::1]:43", "[fe80::1%eth0]:443", "169.254.169.254:80"} {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
internal/netguard/netguard_test.go:90
if err := CheckRedirect(req("https://169.254.169.254/latest"), httpsVia); !errors.Is(err, ErrBlockedAddress) {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:211
部署后直接通过浏览器访问`http://ip:端口/你想查的域名或ip或asn`,默认端口`8043`,示例`http://1.2.3.4:8043/examlpe.com`,详细示例请参考下方
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:213
> 支持直接查询国际化域名(IDN,含中文、带变音符号等 Unicode 域名),程序会自动转换为 Punycode 后查询,例如 `http://1.2.3.4:8043/例子.cn`。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_EN.md:213
After deployment, access `http://ip:port/domain-or-ip-or-asn` via browser. Default port is `8043`, e.g., `http://1.2.3.4:8043/example.com`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_EN.md:242
> Internationalized domain names (IDN, including Unicode domains with non-ASCII characters) can be queried directly; the program converts them to Punycode automatically, e.g. `http://1.2.3.4:8043/例子.c
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
internal/netguard/netguard_test.go:90
if err := CheckRedirect(req("https://169.254.169.254/latest"), httpsVia); !errors.Is(err, ErrBlockedAddress) {
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README_EN.md:86
keys: []                     # Accepted API keys. Empty (the default) leaves the service open; one or more keys protect every endpoint except /health and /ready. Clients send a key as "Authorization:
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha da52312c67b0full audit observations/trust-audit/mcp-server/kincaidyang__whois-5.json · Report an issue / request a re-scan
03

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07da52312c67b0CAUTIONB83first audit
04

Questions

What is the Whois MCP server?

Self-hosted WHOIS/RDAP API and MCP server for domains, IPv4/IPv6, CIDRs and ASNs.

Is Whois safe to connect to an agent?

With care. The audit graded it B (83/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Whois need?

No credential environment variables were found in its source, so it appears to need none.

How does Whois run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (da52312c67b0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement