Threat Intelligence MCP Server

MCP serverMonitoring & ops

Lets your agent look up live cyber threats like security incidents, hackers, vulnerabilities, and ransomware victims.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use Threat Intelligence MCP Server

About this server

Live threat intel for agents: incidents, actors, CVEs with KEV/EPSS, ransomware leak-site victims.

Install Threat Intelligence MCP Server

The server’s own address, for the clients that take one directly. Or connect ahel onceand every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.

  • Claude Code

    claude mcp add --transport http --scope user threat-intelligence-mcp-server 'https://threatcluster.io/mcp'

    Run it once in your project, then open /mcp to approve any sign-in the server asks for.

  • Claude Desktop

    https://threatcluster.io/mcp

    Add a custom connector in Settings, paste this address, and approve the sign-in.

  • Cursor

    cursor://anysphere.cursor-deeplink/mcp/install?name=threat-intelligence-mcp-server&config=eyJ1cmwiOiJodHRwczovL3RocmVhdGNsdXN0ZXIuaW8vbWNwIn0=

    Open the link and Cursor adds the server at that address.

  • ChatGPT

    https://threatcluster.io/mcp

    In Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.

  • Codex

    codex mcp add threat-intelligence-mcp-server --url 'https://threatcluster.io/mcp'

    Run it once, then sign in with codex mcp login threat-intelligence-mcp-server if the server asks for an account.

From the project's README

As published by jam0k/threat-intelligence-mcp in README.md.

An MCP server that gives Claude, Cursor, VS Code, Windsurf, Zed and any other MCP client live threat intelligence from ThreatCluster: incident clusters (one deduplicated story per incident, with a threat score, timeline and extracted entities), entity profiles (actors, malware, tools, vendors, CVEs), CVE records with KEV / EPSS / exploit status, and ransomware leak-site victims.

It is a thin, auditable wrapper over the public REST API. Every tool call is one or two GETs to https://threatcluster.io/api/public/v1 with your API key; nothing else leaves your machine, and there is no telemetry.

Published twice from one tool spec, so both are identical:

RuntimeInstallPackage
Python 3.10+uvx threatcluster-mcp (or pipx run threatcluster-mcp)PyPI: threatcluster-mcp
Node 18+npx -y threatcluster-mcpnpm: threatcluster-mcp

1. Get a key

Free keys carry the five read scopes, 100 credits a day, 30 requests a minute and a 7-day lookback: https://threatcluster.io/api. Put it in THREATCLUSTER_API_KEY. If you use the tc CLI and have run tc auth login, the Python server picks that credential up automatically (keyring or the ~/.config/tc-cli/credentials file); the Node server reads the file only.

2. Add the server

Claude Code

claude mcp add threatcluster -e THREATCLUSTER_API_KEY=tc_live_... -- npx -y threatcluster-mcp
# or the Python build:
claude mcp add threatcluster -e THREATCLUSTER_API_KEY=tc_live_... -- uvx threatcluster-mcp

Claude Desktop (claude_desktop_config.json, Settings > Developer > Edit Config)

{
  "mcpServers": {
    "threatcluster": {
      "command": "npx",
      "args": ["-y", "threatcluster-mcp"],
      "env": { "THREATCLUSTER_API_KEY": "tc_live_..." }
    }
  }
}

Cursor — one-click: see listings/cursor-deeplink.md, or add to ~/.cursor/mcp.json / .cursor/mcp.json:

{ "mcpServers": { "threatcluster": { "command": "npx", "args": ["-y", "threatcluster-mcp"], "env": { "THREATCLUSTER_API_KEY": "tc_live_..." } } } }

VS Code (.vscode/mcp.json; the input prompts for the key instead of storing it in the file)

{
  "inputs": [{ "type": "promptString", "id": "tc-key", "description": "ThreatCluster API key", "password": true }],
  "servers": {
    "threatcluster": { "type": "stdio", "command": "npx", "args": ["-y", "threatcluster-mcp"], "env": { "THREATCLUSTER_API_KEY": "${input:tc-key}" } }
  }
}

Windsurf (~/.codeium/windsurf/mcp_config.json) — same mcpServers block as Claude Desktop.

Zed (settings.json)

{ "context_servers": { "threatcluster": { "command": { "path": "npx", "args": ["-y", "threatcluster-mcp"], "env": { "THREATCLUSTER_API_KEY": "tc_live_..." } } } } }

Check a configuration without starting a client: THREATCLUSTER_API_KEY=... npx -y threatcluster-mcp --check (prints where the key came from and where it will be sent — never the key).

3. Tools

Costs are ThreatCluster API credits (free keys: 100 a day). Every result carries cost (credits this call spent), budget (remaining today, from the response headers), as_of, and url fields on every cluster, entity, victim and CVE for citation.

ToolWhat it answersAPI endpoint(s)Credits
search_threatsKeyword search over incident clusters; phrase, then all words, then any word; matched_stage says whichGET /threats?keyword= per term1 per term (max 8 calls)
search_everythingClusters, entity profiles and dark-web hits in one callGET /search5
newest_threatsWhat is new in 1h / 24h / 7d / 30d, by first report or by momentumGET /threats1
get_threatFull record for one cluster: summary, timeline, articles, entities; include_iocs adds validated indicatorsGET /threats/{id} (+ /iocs)1 (+1)
leak_site_victimsRansomware leak-site listings by sector / group / country / victim, plus a tally of the whole windowGET /darkweb/ransomware/victims + /facets2
lookup_entityProfile of an actor, malware, tool, vendor, product, country, industry or CVEGET /entities/search + GET /entities/{type}/{value}2
get_vulnerabilityOne CVE: CVSS, EPSS, KEV with due date, exploits, vendors, productsGET /vulnerabilities/{cve_id}1
exploited_vulnerabilitiesCVEs in a window filtered to KEV / public exploit / severity / vendor / productGET /vulnerabilities1
trending_entitiesActors, malware, tools, vendors, CVEs, countries rising over a windowGET /entities/trending1
api_budgetRemaining credits and rate state from the last responses — no API call—0

One prompt, threatcluster_analyst, carries the analyst rules (tools first, cite every fact with the returned url, say what period you searched, leak-site listings are claims).

Errors come back as MCP tool errors with the API's own message: 401 tells the agent to set THREATCLUSTER_API_KEY and where a free key comes from, 429 carries the Retry-After, 403 names the missing scope or the lookback window and the plan that lifts it.

Security

  • The key is read from THREATCLUSTER_API_KEY (then TC_REFRESH_TOKEN, then the tc-cli store) and sent only as the X-API-Key header (or Authorization: Bearer for a JWT minted by tc login) to THREATCLUSTER_API_BASE.
  • It is never logged, never printed by --check, never written to disk, and scrubbed from every error string; the test suites assert the key is absent from all stdout and stderr bytes, including on a 401 whose body quotes it.
  • stdio only. No outbound connection other than the API. No analytics.
  • All tools are read-only (readOnlyHint: true) and validate arguments against the spec before any request is made.

Environment

VariableDefaultPurpose
THREATCLUSTER_API_KEY—your key (tc_live_…, tc_agent_…) or a bearer from tc login
THREATCLUSTER_API_BASEhttps://threatcluster.io/api/public/v1API base (self-hosted or local test servers)
THREATCLUSTER_SITEhttps://threatcluster.iobase for the url fields in results

Repository layout

tools/tools.json   the single source of truth: tools, schemas, endpoint mapping, credits, prompt
python/            PyPI package (hatchling; mcp + httpx)          -> console script threatcluster-mcp
node/              npm package (TypeScript; @modelcontextprotocol/sdk + zod) -> bin threatcluster-mcp
tests/fixtures/    recorded API responses and tool outputs; both packages must replay them identically
listings/          directory manifests and submission copy (Smithery, MCP registry, Glama, mcp.so, Cursor, VS Code)
.github/workflows/ CI (both suites) and tag-triggered publishing (PyPI trusted publishing, npm provenance)

python3 tools/sync_tools.py copies the spec into both packages; CI fails if the copies drift.

Development

pip install -e "python/[test]" && (cd python && pytest)
cd node && npm install && npm test
# live validation against a real API (spends ~30 credits, re-records tests/fixtures):
THREATCLUSTER_LIVE=1 THREATCLUSTER_API_KEY=... THREATCLUSTER_API_BASE=... pytest python/tests/test_live.py

Related: the tc CLI, the API reference, the agent-tool recipe for a bare tool-calling function, and the integration guide.

GPL-3.0-or-later © ThreatCluster Ltd.

Signals

GitHub stars
1
Last commit
Sep 2026
Weekly downloads
227
Weekly_downloads
41 weekly_downloads
Advanced
Delivery
threatcluster MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
io-github-jam0k-threatcluster
Source
github.com/jam0k/threat-intelligence-mcp
Hosted endpoint
https://threatcluster.io/mcp