com.threadlinqs/intelthreadlinqs-mcp
NPM · INTELTHREADLINQS-MCP · SCANNED SEP 21
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 28 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability88
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 8204 tokens (~94/item across 87 items; 73 tools + 14 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
- Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 73 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 74 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the com.threadlinqs/intelthreadlinqs-mcp server?
com.threadlinqs/intelthreadlinqs-mcp runs locally as an npm package, launched with npx -y intelthreadlinqs-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · intelthreadlinqs-mcp
claude mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
{
"mcpServers": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"command": "npx",
"args": [
"-y",
"intelthreadlinqs-mcp"
]
}
}
} {
"servers": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"command": "npx",
"args": [
"-y",
"intelthreadlinqs-mcp"
]
}
}
} codex mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"intelthreadlinqs-mcp"
],
"enabled": true
}
}
} openclaw mcp add com-threadlinqs-intelthreadlinqs-mcp --command npx --arg -y --arg intelthreadlinqs-mcp
mcp_servers:
com-threadlinqs-intelthreadlinqs-mcp:
command: "npx"
args: ["-y", "intelthreadlinqs-mcp"] {
"McpServers": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"intelthreadlinqs-mcp"
]
}
}
} assistant mcp add com-threadlinqs-intelthreadlinqs-mcp -t stdio -c npx -a -y intelthreadlinqs-mcp
{
"mcpServers": {
"com-threadlinqs-intelthreadlinqs-mcp": {
"command": "npx",
"args": [
"-y",
"intelthreadlinqs-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −3
- Stability: pass → 0.80 functional
- 16 Sept 26 0
- Stability: 0.97 → pass security
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Analysed npm/intelthreadlinqs-mcp@8.1.1
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 96 packages
| Packages resolved | 96 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_technique_rules Technique Co-occurrence Rules ~80
MITRE ATT&CK technique PAIRS mined from the corpus with support, confidence and lift — which techniques travel together far above chance. Complements predict_mitre_transitions exactly: that answers sequence (what follows what), this answers co-occurrence (what appears alongside what).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Default 50, max 200. |
| Name | Type | Req | Description |
|---|---|---|---|
| rules | array | yes | – |
| summary | object | – | – |
No examples provided.
get_threat Get Threat ~95
Get the full detail for a single threat by its ID (e.g. TL-2026-0042): overview, MITRE techniques, IOCs, detections, timeline, and tags. For that threat's malware families, tools, targeted sectors/regions, affected OS and campaigns, call get_threat_enrichment.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| attribution | object | – | – |
| category | string | – | – |
| created_at | string | – | – |
| description | string | – | – |
| detections | array | – | – |
| id | string | yes | Threat ID (TL-YYYY-NNNN). |
| identifiers | object | – | – |
| iocs | object | – | – |
| mitre_attack | array | – | – |
| osint | object|null | – | Community-OSINT summary; null below Red tier or when unscanned. |
| references | array | – | – |
| severity | object | – | – |
| status | string | – | – |
| summary | string | – | – |
| tags | array | – | – |
| title | string | – | – |
| updated_at | string | – | – |
No examples provided.
get_threat_bundle Get Threat Bundle ~107
One-shot dossier for a threat: the full threat detail plus its simulations and analysis transcripts (include="summary" returns just the threat). Fewer round-trips than calling get_threat + get_threat_simulations + get_threat_transcripts separately.
| Name | Type | Req | Description |
|---|---|---|---|
| include | string | – | "full" (default) bundles simulations + transcripts; "summary" returns just the threat |
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| simulations | object|null | – | – |
| threat | object | yes | – |
| transcripts | object|null | – | Omitted entirely when include='summary'. |
No examples provided.
get_threat_enrichment Threat Enrichment ~115
Reference-grounded enrichment for one threat by ID: the malware families and tools used, targeted sectors/regions, affected operating systems, named campaigns, AI/ML (ATLAS) techniques, and per-technique mitigations + detection data sources. Complements get_threat (overview/MITRE/IOCs/detections) — call this for the "what malware/tools were used and who was targeted" view.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| atlas | array | – | – |
| campaigns | array | – | – |
| id | string | yes | – |
| malware | array | – | – |
| operating_systems | array | – | – |
| regions | array | – | – |
| sectors | array | – | – |
| tools | array | – | – |
No examples provided.
get_threat_hunting_bundle Threat Hunting Bundle ~70
Flagship one-call hunting dossier for a threat: full detail + similar threats + simulations + infrastructure pivots, composed server-side. Best single tool to scope a hunt around one threat.
| Name | Type | Req | Description |
|---|---|---|---|
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| infrastructure_pivots | object|null | – | – |
| similar_threats | object|null | – | – |
| simulations | object|null | – | – |
| threat | object | yes | – |
No examples provided.
get_threat_level Threat Level ~29
Get the computed current threat-landscape level (a 0–25 rating of overall posture).
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| criteria | array | – | – |
| level | string | yes | – |
| max | number | – | – |
| score | number | yes | – |
| threats_observed | integer | – | – |
No examples provided.
get_threat_simulations Threat Simulations ~74
Get the adversary-emulation / simulation playbooks attached to a threat — step-by-step commands by platform for safely reproducing the behavior in a lab. Use to operationalize detection testing for a specific threat.
| Name | Type | Req | Description |
|---|---|---|---|
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| platforms | object | – | – |
| simulations | array | – | – |
| threat_id | string | yes | – |
No examples provided.
get_threat_transcripts Get Threat Transcripts ~55
Get the AI agent analysis transcripts for a threat — the step-by-step reasoning the research agents produced while profiling it.
| Name | Type | Req | Description |
|---|---|---|---|
| threat_id | string | yes | Threat ID (e.g. TL-2026-0042) |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| threat_id | string | yes | – |
| transcripts | array | – | – |
No examples provided.
get_tool_intelligence Tool Intelligence ~94
Pivot on an offensive tool / utility / RMM / LOLBin by name (e.g. "Cobalt Strike", "Mimikatz", "AnyDesk", "PsExec"). Returns the canonical tool + class, prevalence, the threats and actors using it, and its most-common ATT&CK techniques.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Tool name (e.g. "Cobalt Strike", "Mimikatz") |
| Name | Type | Req | Description |
|---|---|---|---|
| actors | array | – | – |
| canonical | string | – | – |
| entity_type | string | – | – |
| matched | boolean | yes | – |
| prevalence | object | – | – |
| query | string | – | – |
| threats | array | – | – |
| top_techniques | array | – | – |
No examples provided.
health Health Check ~34
Lightweight liveness probe: confirms the API is reachable and your key is valid, and returns platform counts + the latest debrief date.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| api_reachable | boolean | – | – |
| latest_debrief_date | string|null | – | – |
| platform_stats | object|null | – | – |
| server_version | string | – | – |
| status | string | yes | 'ok' | 'degraded' |
No examples provided.
hunt Hunt (TLQL) ~183
Run a deterministic SIEM-style query over the pre-joined observation index (~106k rows across tool, malware, ioc, mitre, cve, attribution, dns and infra observations). Use this INSTEAD of chaining many search_threats calls when the question is an aggregate ("how many X grouped by Y") or crosses observation types ("threats using tool A that also have IOC type B"). Append "| stats count by <field>" to aggregate; without it you get matching rows. Call hunt_schema first if you do not know the field names.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Row cap for non-stats queries (default 50, max 150). Ignored in stats mode. |
| query | string | yes | TLQL, e.g. `tool = "cobalt strike" AND sector = "healthcare" | stats count by nation` |
| Name | Type | Req | Description |
|---|---|---|---|
| by | array | – | – |
| columns | array | – | – |
| count | integer | – | – |
| func | string | – | – |
| groups | array | – | – |
| mode | string | yes | 'stats' when the query has a | stats pipe, otherwise rows. |
| query | string | yes | – |
| rows | array | – | – |
| tier_gated_included | boolean | – | True when the caller's tier allows the c2_beacon/dns/infra observation types. |
No examples provided.
hunt_schema Hunt Schema ~58
The hunt query grammar: every filterable field and alias, which fields are scoped observables vs denormalized, the operators, the stats-pipe form, worked examples, and how fresh the index is. Call once before writing a hunt query.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| by_type_json | string | – | JSON string of per-observation-type row counts. |
| duration_ms | integer | – | – |
| grammar | object | yes | – |
| rebuilt_at | string|null | – | – |
| row_count | integer | – | – |
No examples provided.
list_debriefs List Debriefs ~140
List recent daily intelligence debriefs (newest first) with their per-day rollups: new/updated threats, themes, MITRE techniques, IOC breakdown, actors, and severity counts. Use to scan recent days; use get_debrief for the full detail of one date. Pass limit (default 30, max 100); the result includes has_more (true when the page is full, so older debriefs may exist). NOTE: the debriefs endpoint does not yet honor offset — it serves the most recent window.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max debriefs to return (default 30, max 100) |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
| has_more | boolean | – | True when another page may exist. |
| next_cursor | string|null | – | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | – | Total matching rows, when the handler reports one. |
No examples provided.
list_simulations List Simulations ~55
List adversary-emulation simulation scenarios across the platform (atomic test commands grouped by threat). Pass limit (default 50, max 200).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 50, max 200) |
| Name | Type | Req | Description |
|---|---|---|---|
| correlation | object | – | – |
| filter_meta | object | – | – |
| threats | array | – | – |
| total | integer | – | – |
| total_simulations | integer | – | – |
No examples provided.
list_threat_categories List Threat Categories ~35
List every threat category with its threat count across the whole corpus. Use to discover valid category filters for search_threats.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
| total_categories | integer | – | – |
No examples provided.
predict_mitre_transitions Predict MITRE Transitions ~142
Predict the MITRE ATT&CK techniques most likely to follow (or precede) a given technique, with observed probabilities and example threats. Use forward to anticipate the next step in a kill chain; reverse to infer what came before. Pair with get_mitre_technique for the technique definition.
| Name | Type | Req | Description |
|---|---|---|---|
| direction | string | – | 'forward' = techniques that typically follow (default); 'reverse' = techniques that typically precede |
| technique_id | string | – | Source technique ID (e.g. T1059 or T1059.001) |
| top_n | number | – | Max transitions to return (default 5, max 20) |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | – | – |
| direction | string | – | – |
| technique_id | string | yes | – |
| total | integer | – | – |
| transitions | array | – | – |
No examples provided.
resolve_entity Resolve Canonical Name ~122
Normalize an actor / malware / tool / sector / region / technique name or alias to its canonical reference form + stable UUID (e.g. "fancy bear" → "APT28"). Call this BEFORE pivoting (get_actor / get_malware_intelligence / get_tool_intelligence / search_threats) when unsure of the canonical name. Optional type narrows the lookup.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Name or alias to resolve |
| type | string | – | Optional: actor|malware|tool|sector|region|technique|campaign |
| Name | Type | Req | Description |
|---|---|---|---|
| canonical | string | – | Canonical name — feed to get_actor / get_malware_intelligence / get_tool_intelligence. |
| entity_type | string | – | – |
| matched | boolean | yes | – |
| matched_via | string | – | – |
| query | string | yes | – |
| uuid | string | – | – |
No examples provided.
search_actors List Actors ~155
List attributed threat actors with aggregate stats (threat_count, severity levels, categories, nation_state). Returns the full roster in one call, or narrow it with the optional tool / malware / sector filters (e.g. tool="Cobalt Strike" → only actors that used it). Use get_actor for a single actor's full profile. Not paginated; the response carries a total count.
| Name | Type | Req | Description |
|---|---|---|---|
| malware | string | – | Only actors with a threat deploying this malware family (e.g. "LockBit") |
| sector | string | – | Only actors with a threat targeting this sector (e.g. "Healthcare") |
| tool | string | – | Only actors with a threat using this tool (e.g. "Cobalt Strike") |
| Name | Type | Req | Description |
|---|---|---|---|
| actors | array | – | – |
| has_more | boolean | – | True when another page may exist. |
| next_cursor | string|null | – | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | – | Total matching rows, when the handler reports one. |
No examples provided.
search_corpus_semantic Semantic Corpus Search ~104
Vector + rerank retrieval over the whole corpus, returning ranked source cards. Use when keyword search fails — conceptual or paraphrased questions where the exact terms do not appear in the text. Complements search_threats, which is boolean/exact over structured filters. Depends on the AI Search binding and is rate-limited; a 503 means the index is unavailable, not that nothing matched.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | A natural-language question or concept. |
| Name | Type | Req | Description |
|---|---|---|---|
| chunks | array | – | – |
| query | string | – | – |
| results | array | – | – |
No examples provided.
search_detections Search Detections ~150
Keyword search across detection logic (SPL/KQL/Sigma) by rule text, technique, or threat. Optionally filter by type (spl|kql|sigma) or severity. Paginated via limit (default 25, max 200) + offset.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 25, max 200) |
| offset | number | – | Row offset for pagination (default 0) |
| query | string | yes | Search term (rule text, CVE, technique, etc.) |
| severity | string | – | Filter by severity: critical, high, medium, low |
| type | string | – | Detection type: spl, kql, or sigma |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
No examples provided.
search_iocs Search IOCs ~131
Search indicators of compromise (IPs, domains, hashes, URLs). Filter by value substring and/or category. Pass limit (default 25, max 100); the result includes has_more (true when the page is full, so more may exist). NOTE: the indicator endpoint does not yet honor offset — narrow with a more specific value/type substring rather than paging.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 25, max 100) |
| type | string | – | IOC category (e.g. network, file, behavioral) |
| value | string | – | Substring to match against IOC values |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
| has_more | boolean | – | True when another page may exist. |
| next_cursor | string|null | – | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | – | Total matching rows, when the handler reports one. |
No examples provided.
search_threats Search Threats ~681
The deterministic threat-catalog query tool. Returns LEAN summary rows {id, title, severity, category, status, threat_actor, nation_state, affected_products, cves, cvss_score, summary, created} — call get_threat for full detail on a specific id. Combine a free-text `query` with any structured filters; ALL filters AND-combine and apply together (e.g. query="supply chain" + threat_actor="TeamPCP" + category="SUPPLY_CHAIN" returns only matching rows, with affected_products inline). Paginated: limit (default 20, max 100) + offset/cursor; result carries total, has_more, and next_cursor.
| Name | Type | Req | Description |
|---|---|---|---|
| affected_product | string | – | Filter by affected product/vendor (e.g. "npm", "Microsoft", "VS Code") |
| campaign | string | – | Filter to threats in a named campaign/operation (e.g. "Snowflake campaign") |
| category | string | – | e.g. SUPPLY_CHAIN, MALWARE, RANSOMWARE, VULNERABILITY, APT, PHISHING, ZERO_DAY (call list_threat_categories for the full vocabulary) |
| created_after | string | – | ISO date — only threats created on/after (e.g. 2026-05-01) |
| created_before | string | – | ISO date — only threats created on/before |
| cursor | string | – | Opaque pagination cursor (next_cursor from a prior result); ignored when offset is given. |
| cve | string | – | Filter by CVE id (e.g. CVE-2026-45321) |
| limit | number | – | Max results (default 20, max 100) |
| malware | string | – | Filter to threats deploying a malware family (e.g. "LockBit", "Vidar") |
| mitre_technique | string | – | Filter by MITRE technique id (e.g. T1059) |
| motivation | string | – | Filter by motivation (e.g. financial, espionage) |
| nation_state | string | – | Filter by nation-state (e.g. Russia, China, Iran) |
| offset | number | – | Row offset for pagination (default 0). |
| os | string | – | Filter to threats affecting an operating system (e.g. "Windows", "Linux", "VMware ESXi") |
| query | string | – | Free-text term across title/summary/description/CVE/actor (optional; AND-combined with filters) |
| sector | string | – | Filter by grounded industry sector (e.g. "Healthcare", "Government") |
| severity | string | – | critical | high | medium | low |
| status | string | – | Threat status filter (e.g. active) |
| tag | string | – | Filter by exact tag (e.g. "supply-chain-compromise") |
| target_region | string | – | Filter by targeted region (e.g. APAC, Europe) |
| target_sector | string | – | Filter by targeted sector (e.g. Healthcare, Finance) |
| threat_actor | string | – | Filter by attributed actor name/alias (e.g. "TeamPCP", "APT29") |
| tool | string | – | Filter to threats using a tool (e.g. "Cobalt Strike", "Mimikatz") |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
| has_more | boolean | – | True when another page may exist. |
| next_cursor | string|null | – | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | – | Total matching rows, when the handler reports one. |
No examples provided.
search_vulnerabilities Search Vulnerabilities ~354
Query the real-time CVE feed — validated against CVE.org and enriched from open sources (CVSS, EPSS exploitation probability, CISA KEV, public PoCs/exploits, nuclei detection templates, affected products/packages, plus platform-native trending/priority). Sort by trending|latest|priority|cvss|epss; filter by severity, kev (KEV-only), has_poc, nuclei, epss_min, window (days), vendor, cwe, or free-text query. Returns COMPACT cards {cve_id, severity, cvss, epss_percentile, is_kev, has_poc/exploit/nuclei, priority, trending, vendors, age} — call get_cve(id) for full detail.
| Name | Type | Req | Description |
|---|---|---|---|
| cwe | string | – | Weakness id, e.g. CWE-79 |
| epss_min | number | – | Minimum EPSS exploitation probability, 0-1 |
| has_poc | boolean | – | Only CVEs with a public proof-of-concept |
| kev | boolean | – | Only CISA KEV (known-exploited) CVEs |
| limit | number | – | default 30, max 100 |
| nuclei | boolean | – | Only CVEs with a nuclei detection template |
| query | string | – | Free-text: a CVE id or keyword (matches id + description) |
| severity | string | – | CRITICAL | HIGH | MEDIUM | LOW |
| sort | string | – | trending (default) | latest | priority | cvss | epss |
| vendor | string | – | Affected vendor/product substring |
| window | number | – | Only CVEs published within the last N days |
| Name | Type | Req | Description |
|---|---|---|---|
| facets | object | – | – |
| pagination | object | – | – |
| sort | string | – | – |
| total | integer | – | – |
| vulnerabilities | array | yes | – |
No examples provided.
search_xscan_indicators Search Community Indicators ~265
Search the canonical community-indicator set (TL_OSINT_Scan / tweetfeed.live, CC0) — indicators the community reported that were also matched against our corpus. Filter by tag, type, ASN, country, minimum linked-threat count, or a value substring. There is deliberately NO family filter: the upstream AI family field is populated on under 1% of rows, so a family argument would return nothing. Use tag instead (community tags carry the family signal). Community-sourced and heavily concentrated (~73% of recent submissions come from a single reporter) — corroborating, not authoritative.
| Name | Type | Req | Description |
|---|---|---|---|
| asn | string | – | Autonomous system, e.g. AS14061 |
| country | string | – | Two-letter country code, e.g. RU |
| limit | number | – | Max rows (default 25, max 100) |
| min_threats | number | – | Only indicators linked to at least this many of our threats |
| offset | number | – | Row offset for paging |
| q | string | – | Substring match on the indicator value |
| tag | string | – | Community tag substring, case-insensitive and normalized (e.g. phishing, asyncrat, c2) |
| type | string | – | Indicator type |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | – | – |
| has_more | boolean | – | True when another page may exist. |
| next_cursor | string|null | – | Opaque cursor for the next page, or null when this is the last page or the endpoint ignores offset. |
| total | integer | – | Total matching rows, when the handler reports one. |
No examples provided.
What is the com.threadlinqs/intelthreadlinqs-mcp server?
com.threadlinqs/intelthreadlinqs-mcp is listed in the public MCP registry as com.threadlinqs/intelthreadlinqs-mcp. Threadlinqs threat-intelligence MCP, 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs. This page covers its npm package (intelthreadlinqs-mcp).
Is the com.threadlinqs/intelthreadlinqs-mcp server safe to use?
com.threadlinqs/intelthreadlinqs-mcp scores 85 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.threadlinqs/intelthreadlinqs-mcp server expose?
com.threadlinqs/intelthreadlinqs-mcp exposes 73 tools: get_started, search_vulnerabilities, search_threats, get_threat, get_recent_threats, and 68 more. Their descriptions and schemas cost roughly 7,781 tokens of context every time the server is loaded.
Is the com.threadlinqs/intelthreadlinqs-mcp server still maintained?
com.threadlinqs/intelthreadlinqs-mcp is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the com.threadlinqs/intelthreadlinqs-mcp server under?
com.threadlinqs/intelthreadlinqs-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.