Live threat intel for Claude — CVE, KEV predictions, IP lookup, malware hashes. Free, no API key.
{
"mcpServers": {
"com-keyboardcrumbs-mcp": {
"command": "<see-readme>",
"args": []
}
}
}No install config available. Check the server's README for setup instructions.
Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Live threat intel for Claude — CVE, KEV predictions, IP lookup, malware hashes. Free, no API key.
Is it safe?
No package registry to scan.
No authentication — any process on your machine can connect.
License not specified.
Is it maintained?
Last commit 27 days ago.
Will it work with my client?
Transport: stdio. Works with Claude Desktop, Cursor, Claude Code, and most MCP clients.
No automated test available for this server. Check the GitHub README for setup instructions.
No known vulnerabilities.
This server is missing a description. Tools and install config are also missing.If you've used it, help the community.
Add informationHave you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Dynamic problem-solving through sequential thought chains
A Model Context Protocol server for searching and analyzing arXiv papers
An open-source AI agent that brings the power of Gemini directly into your terminal.
The official Python SDK for Model Context Protocol servers and clients
MCP Security Weekly
Get CVE alerts and security updates for com.keyboardcrumbs/mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
mcp-name: com.keyboardcrumbs/mcp
Live threat intelligence tools for Claude Desktop. Free, no API key required.
| Tool | Description |
|------|-------------|
| check_ip | Threat intel for any IP — risk score, geo, ASN, C2 associations, staging clusters |
| check_cve | CVE lookup — CVSS, EPSS, KEV status, exploit availability, patch urgency |
| check_domain | Domain intel — DNS records, WHOIS, malware associations, subdomains |
| check_hash | Malware hash lookup via VirusTotal (68+ engines) + CIRCL (6.3B files) |
| active_threats | Live snapshot — KEV count, active C2s, ransomware victims, data freshness |
| predict_kev | KEV Oracle — top CVEs predicted to be added to CISA KEV before it happens |
| check_staging | GhostWatch — detect pre-attack infrastructure staging for an IP or domain |
| check_ransomware | Ransomware group lookup and victim tracking |
Add to claude_desktop_config.json:
{
"mcpServers": {
"keyboardcrumbs": {
"command": "uvx",
"args": ["--from", "git+https://github.com/keyboardcrumbs/mcp", "keyboardcrumbs-mcp"]
}
}
}
git clone https://github.com/keyboardcrumbs/mcp
cd mcp
uv venv && source .venv/bin/activate
uv add "mcp[cli]" httpx
Add to claude_desktop_config.json:
{
"mcpServers": {
"keyboardcrumbs": {
"command": "uv",
"args": ["--directory", "/path/to/mcp", "run", "server.py"]
}
}
}
Restart Claude Desktop.
Once installed, just ask Claude:
Claude will call the live KeyboardCrumbs API and return real-time threat intelligence.
URLhaus · Feodo Tracker · AlienVault OTX · CISA KEV · NVD · EPSS · ExploitDB · VirusTotal · CIRCL · SANS ISC DShield · Shodan · RIPE · crt.sh · Ransomware.live
Data updates every 15 minutes. No API key. No signup. No rate limits for normal use.