@pipeworx/greynoise

MCP serverDev tools

GreyNoise lets your AI check whether an IP address is a known internet scanner and find out how that scanner is classified. When unfamiliar IPs come up, your AI can look up their scanner classification for you. It uses the GreyNoise Community free tier, which requires a GreyNoise key.

Available today. Use it from your connected AI after setup.

After adding it, get a GreyNoise Community key and add it to enable the free tier. Then try asking your AI about an IP address you want to check.

Then ask your AI: use the ask pipeworx tool from @pipeworx/greynoise

What your AI can do with it

  • Check whether an IP address is a known internet scanner
  • Look up how a scanner IP is classified
  • Answer questions about unfamiliar IP addresses using GreyNoise Community data

From the project's README

As published by pipeworx-io/mcp-greynoise in README.md.

GreyNoise Community MCP — IP scanner classification.

Part of Pipeworx — an MCP gateway connecting AI agents to 1476+ live data sources.

Tools

  • ip_context(ip) — noise / RIOT classification, name, last seen.

Auth

Data source

https://api.greynoise.io/v3/community/{ip} — header key.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

{
  "mcpServers": {
    "greynoise": {
      "url": "https://gateway.pipeworx.io/greynoise/mcp"
    }
  }
}

What this endpoint actually serves

tools/list at https://gateway.pipeworx.io/greynoise/mcp returns the tools in the table above plus the shared Pipeworx meta-toolsask_pipeworx, discover_tools, search_within, remember/recall and the rest of the gateway-wide set. So the tool count you see is larger than this table: a single-pack endpoint currently lists roughly 30 shared tools alongside the pack's own. The connection's initialize response states its exact scope, and is the authoritative answer for a given day.

This is deliberate, not multiplexing by accident. The meta-tools are what let a scoped connection answer a question this pack does not cover — via ask_pipeworx, which routes across the whole catalog — without you adding a second MCP server. There is currently no way to mount a pack endpoint without them; if the extra schemas cost you more context than the routing is worth, connect to the full gateway once rather than to several pack endpoints.

Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Both URLs reach the same gateway and the same 1476+ data sources. The only difference is which pack's tools are listed directly; ask_pipeworx reaches all of them from either one.

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:

ask_pipeworx({ question: "your question about Greynoise data" })

The gateway picks the right tool and fills the arguments automatically.

More

License

MIT

Tools it offers (32)

What this server listed when ahel dialed its public endpoint in Sep 2026, with no key and no account of yours. The names are the server’s own.

  • ask_pipeworx
  • ask_pipeworx_beta
  • ask_pipeworx_grounded
  • search_within
  • deep_research
  • discover_tools
  • resolve_entity
  • compare_entities
  • subscribe
  • unsubscribe
  • list_subscriptions
  • recent_alerts
  • entity_profile
  • recent_changes
  • validate_claim
  • scan_dependency
  • bet_research
  • polymarket_arbitrage
  • polymarket_edges
  • polymarket_kalshi_spread
  • polymarket_fill_risk
  • polymarket_edge_tracker
  • pipeworx_trending
  • suggest_questions
  • generate_llms_txt
  • ai_visibility_check
  • scan_competitor_ai_presence
  • pipeworx_feedback
  • remember
  • recall

Signals

Last commit
Aug 2026
Advanced
Delivery
greynoise MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
Catalog kind
mcp-server
Gateway key
io-github-pipeworx-io-greynoise
Source
github.com/pipeworx-io/mcp-greynoise
Hosted endpoint
https://gateway.pipeworx.io/greynoise/mcp