io.github.cyanheads/whois-mcp-server
NPM · @CYANHEADS/WHOIS-MCP-SERVER · SCANNED AUG 7
Domain registration, availability, DNS records, and IP/ASN resolution via RDAP and DNS-over-HTTPS.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security88
- No malware found by supply-chain analysis.Pass
- Known CVEs were checked across the 125 of 132 dependencies we could resolve, so this covers what we could see, not the whole tree.Partial
- No install/post-install scripts declared.Pass
- Dependency health was assessed across the 125 of 132 dependencies we could resolve, so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (Apache-2.0).Pass
- Actively maintained (last published 55 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1110 tokens (~185/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · @cyanheads/whois-mcp-server
claude mcp add cyanheads-whois-mcp-server -- npx -y @cyanheads/whois-mcp-server
codex mcp add cyanheads-whois-mcp-server -- npx -y @cyanheads/whois-mcp-server
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cyanheads-whois-mcp-server": {
"type": "local",
"command": [
"npx",
"-y",
"@cyanheads/whois-mcp-server"
],
"enabled": true
}
}
} openclaw mcp add cyanheads-whois-mcp-server --command npx --arg -y --arg @cyanheads/whois-mcp-server
mcp_servers:
cyanheads-whois-mcp-server:
command: "npx"
args: ["-y", "@cyanheads/whois-mcp-server"] {
"mcpServers": {
"cyanheads-whois-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/whois-mcp-server"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 6 Aug 26 +30
- Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
- MCP protocol: unverified → pass ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Tool coverage: 100 functional
- First check of Tool coverage: 100 functional
- First check of Schema quality: fail functional
- First check of Schema quality: excellent functional
- First check of Schema quality: fail functional
- 2 Aug 26 +30
- Provenance: unverified → fail ▼ security
- Install scripts: unverified → pass ▲ security
- Known CVEs: unverified → partial ▲ security
- Malware scan: unverified → pass ▲ security
- Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
- Maintenance: unverified → pass ▲ functional
- License: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
- Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
- Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
- Licence: Apache-2.0 functional
- 1 Aug 26 −10
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 −9
- Provenance: unverified → fail ▼ security
- Malware scan: pass → unverified ▼ security
- Install scripts: unverified → pass ▲ security
- Maintenance: unverified → pass ▲ functional
- License: unverified → pass ▲ functional
- Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess. functional
- Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess. functional
- Licence: Apache-2.0 functional
- 29 Jul 26 −1
- Dependency health: partial → unverified ▼ functional
- 28 Jul 26 +1
- Dependency health: unverified → partial ▲ functional
- Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
- Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
- 27 Jul 26 24
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 7 Aug 2026 · Analysed npm/@cyanheads/[email protected]
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Dependencies 125 packages
| Packages resolved | 125 |
|---|---|
| Deprecated | 112 |
| Stale | 39 |
| Tree resolution | Partial |
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
whois_check_availability Domain Availability Check ~129
Check whether a domain name is registered or available for registration. Returns available: true when the domain is not registered, available: false with registrar and expiry_date when it is registered, and available: null with rdap_coverage: false when the TLD has no RDAP coverage. Designed for "can I register X" and bulk name sweeps. For the full registration record use whois_lookup_domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to check (e.g., "myfuturename.com"). Must be a valid FQDN — labels separated by dots. |
| Name | Type | Req | Description |
|---|---|---|---|
| available | – | yes | True = available for registration. False = registered. Null = rdap_coverage is false — cannot determine availability for this TLD. |
| domain | string | yes | Normalized domain name checked. |
| expiry_date | string | – | Expiry date when available: false. |
| rdap_coverage | boolean | yes | True when a RDAP server was found for this TLD. |
| registrar | string | – | Registrar name when available: false. |
No examples provided.
whois_get_dns DNS Record Lookup ~153
Fetch DNS records for a domain via DNS-over-HTTPS. Supports A, AAAA, MX, TXT, NS, CNAME, SOA, CAA, PTR. Multiple types are fetched in parallel. NXDOMAIN is returned as nxdomain: true in the result, not as an error — it means the domain does not exist in DNS.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name or hostname to query (e.g., "github.com", "mail.example.com"). |
| types | array | – | DNS record types to fetch. Defaults to [A, AAAA, MX, TXT, NS]. Specify more types to expand coverage (e.g., add CAA to check certificate authority authorization). |
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain queried. |
| nxdomain | boolean | yes | True when the domain does not exist in DNS (NXDOMAIN / Status 3). Records will be empty. This is a valid data signal, not an error. |
| records | array | yes | DNS records returned for the requested types. |
| source | string | yes | The DoH resolver that provided results (cloudflare = primary used for most types, nextdns = fallback or CAA). |
No examples provided.
whois_get_dossier Domain Dossier ~185
One-call domain triage: fetches registration record (RDAP) and DNS records (A, MX, NS, TXT) in parallel, returning a single normalized record with factual signals — domain age in days, privacy-redacted flag, registrar, NS provider inferred from NS records, mail provider inferred from MX records. No synthesized scores — factual signals only. Partial results are surfaced when one leg fails (registration or DNS marked with source_error); only when both legs fail does the tool throw both_legs_failed. For the full registration record use whois_lookup_domain. For DNS types beyond A/MX/NS/TXT (e.g., CNAME, CAA, SOA) use whois_get_dns.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name for the triage (e.g., "github.com"). Must be a valid FQDN. |
| Name | Type | Req | Description |
|---|---|---|---|
| a_records | array | yes | IPv4 addresses (A records). Empty when DNS leg failed or NXDOMAIN. |
| age_days | – | yes | Domain age in days since creation_date. Null when created_date is unavailable. |
| created_date | string | – | ISO 8601 registration creation date. |
| dns_nxdomain | – | yes | True when DNS says domain does not exist (NXDOMAIN). Null when DNS leg failed. |
| dns_source_error | string | – | Error message from the DNS leg when it failed. Omitted on success. |
| dnssec_signed | – | yes | True when delegation-signed. Null when RDAP leg unavailable. |
| domain | string | yes | Normalized domain name. |
| expiry_date | string | – | ISO 8601 registration expiry date. |
| mx_provider | – | yes | Mail provider inferred from MX record (e.g., "Google Workspace", "Microsoft 365"). Null when no MX or DNS leg failed. |
| mx_records | array | yes | Mail exchange hostnames (MX data). Empty when DNS leg failed or NXDOMAIN. |
| nameservers | array | yes | Authoritative nameservers. Empty when RDAP leg failed. |
| ns_provider | – | yes | DNS provider inferred from NS record (e.g., "Cloudflare", "AWS Route 53"). Null when unknown or DNS leg failed. |
| ns_records | array | yes | DNS nameservers from live DNS (NS data). Empty when DNS leg failed or NXDOMAIN. |
| privacy_redacted | – | yes | True when registrant contact info is privacy-redacted. Null when RDAP leg unavailable. |
| rdap_coverage | – | yes | True = RDAP server found. False = no RDAP coverage. Null = RDAP leg failed (source_error set). |
| rdap_source_error | string | – | Error message from the RDAP leg when it failed. Omitted on success. |
| registered | – | yes | True when the domain has a registration record. False = RDAP 404 (not registered). Null when RDAP leg failed. |
| registrar | string | – | Registrar name from registration record. |
| status | array | yes | EPP status codes. Empty when RDAP leg failed. |
| txt_records | array | yes | TXT record values (SPF, DKIM hints, etc.). Empty when DNS leg failed or NXDOMAIN. |
No examples provided.
whois_lookup_asn ASN Lookup ~123
Resolve an Autonomous System Number (ASN) to its org name, country, and RIR source via RIR RDAP. Accepts AS-prefixed format (e.g., "AS15169") or bare integer (e.g., "15169"). Distinct from IP lookup — the entry point is the ASN itself, not an IP within its block.
| Name | Type | Req | Description |
|---|---|---|---|
| asn | string | yes | Autonomous System Number to look up. Accepts AS-prefixed format (e.g., "AS15169") or bare integer (e.g., "15169"). |
| Name | Type | Req | Description |
|---|---|---|---|
| asn | string | yes | Normalized ASN identifier (AS-prefixed, e.g., "AS15169"). |
| country | string | – | Country code (ISO 3166-1 alpha-2). Omitted when not in RDAP data. |
| end_autnum | number | – | End ASN of the registered range. |
| handle | string | – | RIR handle / object identifier. |
| name | string | – | ASN network name. |
| org_name | string | – | Organization name registered for this ASN. |
| rir | string | – | Regional Internet Registry that manages this ASN (ARIN, RIPE, APNIC, LACNIC, AFRINIC). |
| start_autnum | number | – | Start ASN of the registered range. |
| type | string | – | ASN type (e.g., "DIRECT ALLOCATION"). |
No examples provided.
whois_lookup_domain Domain Registration Lookup ~166
Look up a domain's registration record — registrar, created/expiry dates, nameservers, EPP status codes, DNSSEC flag, and registrant org (where not privacy-redacted). Uses RDAP via IANA bootstrap to auto-select the correct per-TLD RDAP server, returning one normalized shape regardless of TLD. When the TLD has no RDAP coverage, returns rdap_coverage: false. If the domain is not registered, throws domain_not_found — use whois_check_availability to test availability without triggering an error.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to look up (e.g., "example.com", "github.com"). Must be a valid FQDN — labels separated by dots, each label up to 63 chars. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_date | string | – | ISO 8601 domain registration date. |
| dnssec_signed | boolean | yes | True when the domain has DNSSEC delegation signed. |
| domain | string | yes | Normalized domain name (lowercased). |
| expiry_date | string | – | ISO 8601 registration expiry date. |
| handle | string | – | Registry handle / object identifier assigned by the registry. |
| nameservers | array | yes | Authoritative nameservers for this domain. |
| rdap_coverage | boolean | yes | True when a RDAP server was found for this TLD; false when RDAP coverage is absent. |
| rdap_last_updated | string | – | ISO 8601 timestamp of last RDAP database update. |
| registrant_org | string | – | Registrant organization name. Omitted when privacy-redacted. |
| registrant_redacted | boolean | yes | True when registrant contact data is privacy-redacted (common post-GDPR). |
| registrar | string | – | Name of the sponsoring registrar. |
| registrar_iana_id | string | – | IANA registrar ID number. |
| status | array | yes | EPP status codes (e.g., clientTransferProhibited, serverDeleteProhibited). |
| updated_date | string | – | ISO 8601 date of last registration record change. |
No examples provided.
whois_lookup_ip IP Address / Network Lookup ~189
Look up an IP address or CIDR block via RIR RDAP (ARIN, RIPE, APNIC, LACNIC, AFRINIC — auto-routed via IANA bootstrap). Returns netblock, org, country, CIDR, abuse contact email, and reverse DNS (PTR) via DoH. PTR is best-effort — failure returns ptr: null. Private/reserved ranges (RFC 1918, loopback, link-local) return a validation error — no RIR RDAP record exists for them.
| Name | Type | Req | Description |
|---|---|---|---|
| ip | string | yes | IPv4 address (e.g., "8.8.8.8"), IPv6 address (e.g., "2001:4860:4860::8888"), or CIDR notation (e.g., "192.0.2.0/24"). Private/reserved ranges will return a validation error. |
| Name | Type | Req | Description |
|---|---|---|---|
| abuse_email | string | – | Abuse contact email address. |
| cidr | string | – | CIDR notation of the netblock (e.g., "8.8.8.0/24"). |
| country | string | – | Country code (ISO 3166-1 alpha-2). Omitted when not in RDAP data. |
| end_address | string | – | End address of the IP netblock. |
| handle | string | – | RIR handle / object identifier. |
| ip | string | yes | The IP or CIDR queried. |
| ip_version | string | – | IP version: "v4" or "v6". |
| name | string | – | Network name assigned by the RIR. |
| org_name | string | – | Organization name holding the netblock. |
| ptr | – | yes | Reverse DNS hostname (PTR record). Null when PTR lookup fails, returns no answer, or domain is NXDOMAIN. |
| rdap_source | string | – | RIR that provided the RDAP data (ARIN, RIPE, APNIC, LACNIC, AFRINIC). |
| start_address | string | – | Start address of the IP netblock. |
| type | string | – | Network type (e.g., "DIRECT ALLOCATION"). |
No examples provided.