Abuse.ch
This MCP server provides threat intelligence analysis by integrating with abuse.ch platforms including MalwareBazaar, URLhaus, and ThreatFox to deliver comprehensive security reports for files, URLs, domains, and IP addresses. Built with Python using FastMCP and aiohttp for async operations, it features structured Pydantic schemas for data validation, concurrent API calls for performance, and automatic response limiting to prevent oversized payloads. The implementation offers four core tools for retrieving detailed threat reports with hash validation, URL formatting, and consolidated intelligence from multiple abuse.ch sources, making it valuable for security analysts, incident responders, and threat hunters who need programmatic access to malware intelligence and IOC enrichment capabilities.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.
Scan details: Circle-IR · 2026-09-28 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- security
- Source
- PulseMCP
- Repository
- github.com/lokallost/abusech-mcp
- Author type
- human
- Last scanned
- 2026-09-28
- Updated
- 2026-09-28
Use via MCP
Resolve Abuse.ch from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.