Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

com.threadlinqs/intelthreadlinqs-mcp

NPM · INTELTHREADLINQS-MCP · SCANNED AUG 3

Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs

−4 this week 20 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security37
  • Malware scan not yet available for this package.Unverified
  • Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability0
  • Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Stability & Change Management0
  • Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Tool Coverage0
  • Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Capabilities0
  • Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.Unverified

Unverified: 4 categories

Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · intelthreadlinqs-mcp

# add to Claude Code
claude mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
# add to Codex CLI
codex mcp add com-threadlinqs-intelthreadlinqs-mcp -- npx -y intelthreadlinqs-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-threadlinqs-intelthreadlinqs-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "intelthreadlinqs-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-threadlinqs-intelthreadlinqs-mcp --command npx --arg -y --arg intelthreadlinqs-mcp
# ~/.hermes/config.yaml
mcp_servers:
  com-threadlinqs-intelthreadlinqs-mcp:
    command: "npx"
    args: ["-y", "intelthreadlinqs-mcp"]
// mcp.json
{
  "mcpServers": {
    "com-threadlinqs-intelthreadlinqs-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "intelthreadlinqs-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 −15
    • Malware scan: pass → unverified security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Package version: 7.1.4 → 8.1.1 functional
  • 2 Aug 26 +15
    • Provenance: unverified → fail security
    • Malware scan: pass → unverified security
    • Install scripts: unverified → pass security
    • Known CVEs: unverified → partial security
    • Stability: Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare. security
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Capabilities: Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake. functional
    • Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess. functional
    • Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess. functional
    • Licence: MIT functional
  • 1 Aug 26 +14
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 −18
    • Malware scan: pass → unverified security
  • 27 Jul 26 24

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance none

Ecosystem: npm · Outcome: none

Dependencies 95 packages

95 packages in the resolved dependency tree · 95 deprecated · 29 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 73 exposed · ~7,781 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
get_technique_rules ~80

MITRE ATT&CK technique PAIRS mined from the corpus with support, confidence and lift — which techniques travel together far above chance. Complements predict_mitre_transitions exactly: that answers sequence (what follows what), this answers co-occurrence (what appears alongside what).

NameTypeReqDescription
limitintegerDefault 50, max 200.
NameTypeReqDescription
rulesarrayyes
summaryobject

No examples provided.

get_threat ~95

Get the full detail for a single threat by its ID (e.g. TL-2026-0042): overview, MITRE techniques, IOCs, detections, timeline, and tags. For that threat's malware families, tools, targeted sectors/regions, affected OS and campaigns, call get_threat_enrichment.

NameTypeReqDescription
idstringyesThreat ID (e.g. TL-2026-0042)
NameTypeReqDescription
attributionobject
categorystring
created_atstring
descriptionstring
detectionsarray
idstringyesThreat ID (TL-YYYY-NNNN).
identifiersobject
iocsobject
mitre_attackarray
osintobject|nullCommunity-OSINT summary; null below Red tier or when unscanned.
referencesarray
severityobject
statusstring
summarystring
tagsarray
titlestring
updated_atstring

No examples provided.

get_threat_bundle ~107

One-shot dossier for a threat: the full threat detail plus its simulations and analysis transcripts (include="summary" returns just the threat). Fewer round-trips than calling get_threat + get_threat_simulations + get_threat_transcripts separately.

NameTypeReqDescription
includestring"full" (default) bundles simulations + transcripts; "summary" returns just the threat
threat_idstringyesThreat ID (e.g. TL-2026-0042)
NameTypeReqDescription
simulationsobject|null
threatobjectyes
transcriptsobject|nullOmitted entirely when include='summary'.

No examples provided.

get_threat_enrichment ~115

Reference-grounded enrichment for one threat by ID: the malware families and tools used, targeted sectors/regions, affected operating systems, named campaigns, AI/ML (ATLAS) techniques, and per-technique mitigations + detection data sources. Complements get_threat (overview/MITRE/IOCs/detections) — call this for the "what malware/tools were used and who was targeted" view.

NameTypeReqDescription
idstringyesThreat ID (e.g. TL-2026-0042)
NameTypeReqDescription
atlasarray
campaignsarray
idstringyes
malwarearray
operating_systemsarray
regionsarray
sectorsarray
toolsarray

No examples provided.

get_threat_hunting_bundle ~70

Flagship one-call hunting dossier for a threat: full detail + similar threats + simulations + infrastructure pivots, composed server-side. Best single tool to scope a hunt around one threat.

NameTypeReqDescription
threat_idstringyesThreat ID (e.g. TL-2026-0042)
NameTypeReqDescription
infrastructure_pivotsobject|null
similar_threatsobject|null
simulationsobject|null
threatobjectyes

No examples provided.

get_threat_level ~29

Get the computed current threat-landscape level (a 0–25 rating of overall posture).

Input schema present but exposes no named parameters.

NameTypeReqDescription
criteriaarray
levelstringyes
maxnumber
scorenumberyes
threats_observedinteger

No examples provided.

get_threat_simulations ~74

Get the adversary-emulation / simulation playbooks attached to a threat — step-by-step commands by platform for safely reproducing the behavior in a lab. Use to operationalize detection testing for a specific threat.

NameTypeReqDescription
threat_idstringyesThreat ID (e.g. TL-2026-0042)
NameTypeReqDescription
platformsobject
simulationsarray
threat_idstringyes

No examples provided.

get_threat_transcripts ~55

Get the AI agent analysis transcripts for a threat — the step-by-step reasoning the research agents produced while profiling it.

NameTypeReqDescription
threat_idstringyesThreat ID (e.g. TL-2026-0042)
NameTypeReqDescription
countinteger
threat_idstringyes
transcriptsarray

No examples provided.

get_tool_intelligence ~94

Pivot on an offensive tool / utility / RMM / LOLBin by name (e.g. "Cobalt Strike", "Mimikatz", "AnyDesk", "PsExec"). Returns the canonical tool + class, prevalence, the threats and actors using it, and its most-common ATT&CK techniques.

NameTypeReqDescription
namestringyesTool name (e.g. "Cobalt Strike", "Mimikatz")
NameTypeReqDescription
actorsarray
canonicalstring
entity_typestring
matchedbooleanyes
prevalenceobject
querystring
threatsarray
top_techniquesarray

No examples provided.

health ~34

Lightweight liveness probe: confirms the API is reachable and your key is valid, and returns platform counts + the latest debrief date.

Input schema present but exposes no named parameters.

NameTypeReqDescription
api_reachableboolean
latest_debrief_datestring|null
platform_statsobject|null
server_versionstring
statusstringyes'ok' | 'degraded'

No examples provided.

hunt ~183

Run a deterministic SIEM-style query over the pre-joined observation index (~106k rows across tool, malware, ioc, mitre, cve, attribution, dns and infra observations). Use this INSTEAD of chaining many search_threats calls when the question is an aggregate ("how many X grouped by Y") or crosses observation types ("threats using tool A that also have IOC type B"). Append "| stats count by <field>" to aggregate; without it you get matching rows. Call hunt_schema first if you do not know the field names.

NameTypeReqDescription
limitintegerRow cap for non-stats queries (default 50, max 150). Ignored in stats mode.
querystringyesTLQL, e.g. `tool = "cobalt strike" AND sector = "healthcare" | stats count by nation`
NameTypeReqDescription
byarray
columnsarray
countinteger
funcstring
groupsarray
modestringyes'stats' when the query has a | stats pipe, otherwise rows.
querystringyes
rowsarray
tier_gated_includedbooleanTrue when the caller's tier allows the c2_beacon/dns/infra observation types.

No examples provided.

hunt_schema ~58

The hunt query grammar: every filterable field and alias, which fields are scoped observables vs denormalized, the operators, the stats-pipe form, worked examples, and how fresh the index is. Call once before writing a hunt query.

Input schema present but exposes no named parameters.

NameTypeReqDescription
by_type_jsonstringJSON string of per-observation-type row counts.
duration_msinteger
grammarobjectyes
rebuilt_atstring|null
row_countinteger

No examples provided.

list_debriefs ~140

List recent daily intelligence debriefs (newest first) with their per-day rollups: new/updated threats, themes, MITRE techniques, IOC breakdown, actors, and severity counts. Use to scan recent days; use get_debrief for the full detail of one date. Pass limit (default 30, max 100); the result includes has_more (true when the page is full, so older debriefs may exist). NOTE: the debriefs endpoint does not yet honor offset — it serves the most recent window.

NameTypeReqDescription
limitnumberMax debriefs to return (default 30, max 100)
NameTypeReqDescription
dataarrayyes
has_morebooleanTrue when another page may exist.
next_cursorstring|nullOpaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
totalintegerTotal matching rows, when the handler reports one.

No examples provided.

list_simulations ~55

List adversary-emulation simulation scenarios across the platform (atomic test commands grouped by threat). Pass limit (default 50, max 200).

NameTypeReqDescription
limitnumberMax results (default 50, max 200)
NameTypeReqDescription
correlationobject
filter_metaobject
threatsarray
totalinteger
total_simulationsinteger

No examples provided.

list_threat_categories ~35

List every threat category with its threat count across the whole corpus. Use to discover valid category filters for search_threats.

Input schema present but exposes no named parameters.

NameTypeReqDescription
dataarrayyes
total_categoriesinteger

No examples provided.

predict_mitre_transitions ~142

Predict the MITRE ATT&CK techniques most likely to follow (or precede) a given technique, with observed probabilities and example threats. Use forward to anticipate the next step in a kill chain; reverse to infer what came before. Pair with get_mitre_technique for the technique definition.

NameTypeReqDescription
directionstring'forward' = techniques that typically follow (default); 'reverse' = techniques that typically precede
technique_idstringSource technique ID (e.g. T1059 or T1059.001)
top_nnumberMax transitions to return (default 5, max 20)
NameTypeReqDescription
dataarray
directionstring
technique_idstringyes
totalinteger
transitionsarray

No examples provided.

resolve_entity ~122

Normalize an actor / malware / tool / sector / region / technique name or alias to its canonical reference form + stable UUID (e.g. "fancy bear" → "APT28"). Call this BEFORE pivoting (get_actor / get_malware_intelligence / get_tool_intelligence / search_threats) when unsure of the canonical name. Optional type narrows the lookup.

NameTypeReqDescription
namestringyesName or alias to resolve
typestringOptional: actor|malware|tool|sector|region|technique|campaign
NameTypeReqDescription
canonicalstringCanonical name — feed to get_actor / get_malware_intelligence / get_tool_intelligence.
entity_typestring
matchedbooleanyes
matched_viastring
querystringyes
uuidstring

No examples provided.

search_actors ~155

List attributed threat actors with aggregate stats (threat_count, severity levels, categories, nation_state). Returns the full roster in one call, or narrow it with the optional tool / malware / sector filters (e.g. tool="Cobalt Strike" → only actors that used it). Use get_actor for a single actor's full profile. Not paginated; the response carries a total count.

NameTypeReqDescription
malwarestringOnly actors with a threat deploying this malware family (e.g. "LockBit")
sectorstringOnly actors with a threat targeting this sector (e.g. "Healthcare")
toolstringOnly actors with a threat using this tool (e.g. "Cobalt Strike")
NameTypeReqDescription
actorsarray
has_morebooleanTrue when another page may exist.
next_cursorstring|nullOpaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
totalintegerTotal matching rows, when the handler reports one.

No examples provided.

search_corpus_semantic ~104

Vector + rerank retrieval over the whole corpus, returning ranked source cards. Use when keyword search fails — conceptual or paraphrased questions where the exact terms do not appear in the text. Complements search_threats, which is boolean/exact over structured filters. Depends on the AI Search binding and is rate-limited; a 503 means the index is unavailable, not that nothing matched.

NameTypeReqDescription
querystringyesA natural-language question or concept.
NameTypeReqDescription
chunksarray
querystring
resultsarray

No examples provided.

search_detections ~150

Keyword search across detection logic (SPL/KQL/Sigma) by rule text, technique, or threat. Optionally filter by type (spl|kql|sigma) or severity. Paginated via limit (default 25, max 200) + offset.

NameTypeReqDescription
limitnumberMax results (default 25, max 200)
offsetnumberRow offset for pagination (default 0)
querystringyesSearch term (rule text, CVE, technique, etc.)
severitystringFilter by severity: critical, high, medium, low
typestringDetection type: spl, kql, or sigma
NameTypeReqDescription
dataarrayyes

No examples provided.

search_iocs ~131

Search indicators of compromise (IPs, domains, hashes, URLs). Filter by value substring and/or category. Pass limit (default 25, max 100); the result includes has_more (true when the page is full, so more may exist). NOTE: the indicator endpoint does not yet honor offset — narrow with a more specific value/type substring rather than paging.

NameTypeReqDescription
limitnumberMax results (default 25, max 100)
typestringIOC category (e.g. network, file, behavioral)
valuestringSubstring to match against IOC values
NameTypeReqDescription
dataarrayyes
has_morebooleanTrue when another page may exist.
next_cursorstring|nullOpaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
totalintegerTotal matching rows, when the handler reports one.

No examples provided.

search_threats ~681

The deterministic threat-catalog query tool. Returns LEAN summary rows {id, title, severity, category, status, threat_actor, nation_state, affected_products, cves, cvss_score, summary, created} — call get_threat for full detail on a specific id. Combine a free-text `query` with any structured filters; ALL filters AND-combine and apply together (e.g. query="supply chain" + threat_actor="TeamPCP" + category="SUPPLY_CHAIN" returns only matching rows, with affected_products inline). Paginated: limit (default 20, max 100) + offset/cursor; result carries total, has_more, and next_cursor.

NameTypeReqDescription
affected_productstringFilter by affected product/vendor (e.g. "npm", "Microsoft", "VS Code")
campaignstringFilter to threats in a named campaign/operation (e.g. "Snowflake campaign")
categorystringe.g. SUPPLY_CHAIN, MALWARE, RANSOMWARE, VULNERABILITY, APT, PHISHING, ZERO_DAY (call list_threat_categories for the full vocabulary)
created_afterstringISO date — only threats created on/after (e.g. 2026-05-01)
created_beforestringISO date — only threats created on/before
cursorstringOpaque pagination cursor (next_cursor from a prior result); ignored when offset is given.
cvestringFilter by CVE id (e.g. CVE-2026-45321)
limitnumberMax results (default 20, max 100)
malwarestringFilter to threats deploying a malware family (e.g. "LockBit", "Vidar")
mitre_techniquestringFilter by MITRE technique id (e.g. T1059)
motivationstringFilter by motivation (e.g. financial, espionage)
nation_statestringFilter by nation-state (e.g. Russia, China, Iran)
offsetnumberRow offset for pagination (default 0).
osstringFilter to threats affecting an operating system (e.g. "Windows", "Linux", "VMware ESXi")
querystringFree-text term across title/summary/description/CVE/actor (optional; AND-combined with filters)
sectorstringFilter by grounded industry sector (e.g. "Healthcare", "Government")
severitystringcritical | high | medium | low
statusstringThreat status filter (e.g. active)
tagstringFilter by exact tag (e.g. "supply-chain-compromise")
target_regionstringFilter by targeted region (e.g. APAC, Europe)
target_sectorstringFilter by targeted sector (e.g. Healthcare, Finance)
threat_actorstringFilter by attributed actor name/alias (e.g. "TeamPCP", "APT29")
toolstringFilter to threats using a tool (e.g. "Cobalt Strike", "Mimikatz")
NameTypeReqDescription
dataarrayyes
has_morebooleanTrue when another page may exist.
next_cursorstring|nullOpaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
totalintegerTotal matching rows, when the handler reports one.

No examples provided.

search_vulnerabilities ~354

Query the real-time CVE feed — validated against CVE.org and enriched from open sources (CVSS, EPSS exploitation probability, CISA KEV, public PoCs/exploits, nuclei detection templates, affected products/packages, plus platform-native trending/priority). Sort by trending|latest|priority|cvss|epss; filter by severity, kev (KEV-only), has_poc, nuclei, epss_min, window (days), vendor, cwe, or free-text query. Returns COMPACT cards {cve_id, severity, cvss, epss_percentile, is_kev, has_poc/exploit/nuclei, priority, trending, vendors, age} — call get_cve(id) for full detail.

NameTypeReqDescription
cwestringWeakness id, e.g. CWE-79
epss_minnumberMinimum EPSS exploitation probability, 0-1
has_pocbooleanOnly CVEs with a public proof-of-concept
kevbooleanOnly CISA KEV (known-exploited) CVEs
limitnumberdefault 30, max 100
nucleibooleanOnly CVEs with a nuclei detection template
querystringFree-text: a CVE id or keyword (matches id + description)
severitystringCRITICAL | HIGH | MEDIUM | LOW
sortstringtrending (default) | latest | priority | cvss | epss
vendorstringAffected vendor/product substring
windownumberOnly CVEs published within the last N days
NameTypeReqDescription
facetsobject
paginationobject
sortstring
totalinteger
vulnerabilitiesarrayyes

No examples provided.

search_xscan_indicators ~265

Search the canonical community-indicator set (TL_OSINT_Scan / tweetfeed.live, CC0) — indicators the community reported that were also matched against our corpus. Filter by tag, type, ASN, country, minimum linked-threat count, or a value substring. There is deliberately NO family filter: the upstream AI family field is populated on under 1% of rows, so a family argument would return nothing. Use tag instead (community tags carry the family signal). Community-sourced and heavily concentrated (~73% of recent submissions come from a single reporter) — corroborating, not authoritative.

NameTypeReqDescription
asnstringAutonomous system, e.g. AS14061
countrystringTwo-letter country code, e.g. RU
limitnumberMax rows (default 25, max 100)
min_threatsnumberOnly indicators linked to at least this many of our threats
offsetnumberRow offset for paging
qstringSubstring match on the indicator value
tagstringCommunity tag substring, case-insensitive and normalized (e.g. phishing, asyncrat, c2)
typestringIndicator type
NameTypeReqDescription
dataarray
has_morebooleanTrue when another page may exist.
next_cursorstring|nullOpaque cursor for the next page, or null when this is the last page or the endpoint ignores offset.
totalintegerTotal matching rows, when the handler reports one.

No examples provided.