# PG1 Sovereign Threat Intelligence (remote · pg1-ai-agent.vercel.app)

STIX IOCs, CVE lookups w/ EPSS/KEV, ATT&CK dossiers, OFAC wallet sanctions, domain age checks.

- Trust score: 62/100 (medium)
- Change this week: −2
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `pg1-ai-agent.vercel.app`: 62/100 (this document), [markdown](https://verifymcp.io/servers/project-gifted1-pg1-threat-intel/api-mcp.md), [page](https://verifymcp.io/servers/project-gifted1-pg1-threat-intel/api-mcp)

## Channel facts

- Endpoint: `https://pg1-ai-agent.vercel.app/api/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.12.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 13 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 66/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3304 tokens (~254/item across 13 items; 13 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 8 days we've observed: 0 tool removals, 1 breaking changes, 0 auth/transport breaks, 12 additions.
- **Tool Coverage**: 98/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 92% of tool parameters carry a description.
  - Structured output schemas are declared (23% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 13 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 20/100
  - Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28.

## Install

### How do I install the PG1 Sovereign Threat Intelligence MCP server?

PG1 Sovereign Threat Intelligence is a hosted endpoint at https://pg1-ai-agent.vercel.app/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http project-gifted1-pg1-threat-intel 'https://pg1-ai-agent.vercel.app/api/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "project-gifted1-pg1-threat-intel": {
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "project-gifted1-pg1-threat-intel": {
      "type": "http",
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.project-gifted1-pg1-threat-intel]
url = "https://pg1-ai-agent.vercel.app/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "project-gifted1-pg1-threat-intel": {
      "type": "remote",
      "url": "https://pg1-ai-agent.vercel.app/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add project-gifted1-pg1-threat-intel --url 'https://pg1-ai-agent.vercel.app/api/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  project-gifted1-pg1-threat-intel:
    url: "https://pg1-ai-agent.vercel.app/api/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "project-gifted1-pg1-threat-intel": {
      "Transport": "http",
      "Url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add project-gifted1-pg1-threat-intel -t streamable-http -u 'https://pg1-ai-agent.vercel.app/api/mcp'
```

### Other

```json
{
  "mcpServers": {
    "project-gifted1-pg1-threat-intel": {
      "type": "http",
      "url": "https://pg1-ai-agent.vercel.app/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 62, 0)

- [functional regression] Schema quality: 2808 → 3304
- [functional improvement] Tool coverage: 17% → 23%
- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 62, 0)

- [security] Tool “get_cve_details” rewrote its description, which is the text the model reads
- [security] Tool “get_ioc_batch” rewrote its description, which is the text the model reads
- [security] Tool “get_ioc_context” rewrote its description, which is the text the model reads
- [security] Tool “get_cve_batch” rewrote its description, which is the text the model reads
- [security] Tool “get_cve_by_product” rewrote its description, which is the text the model reads
- [security] Tool “get_threat_actor_profile” rewrote its description, which is the text the model reads
- [security] Tool “get_threat_indicators” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 2184 → 2808
- [functional] First check of Tool coverage: 17
- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server
- [functional] Server version: 1.9.2 → 1.11.0
- [functional] New tool “check_domain_age”
- [functional] New tool “check_wallet_sanctions”

### 2026-09-24 (score 62, 0)

- [security] Tool “get_cve_batch” rewrote its description, which is the text the model reads
- [security] Tool “get_cve_by_product” rewrote its description, which is the text the model reads
- [security] Tool “get_cve_details” rewrote its description, which is the text the model reads
- [security] Tool “get_threat_actor_profile” rewrote its description, which is the text the model reads
- [security] Tool “get_threat_indicators” rewrote its description, which is the text the model reads
- [security] Tool “get_ioc_batch” rewrote its description, which is the text the model reads
- [security] Tool “get_ioc_context” rewrote its description, which is the text the model reads
- [functional] Server version: 1.9.0 → 1.9.2
- [functional] Server version: 1.8.1 → 1.9.0
- [functional] Server version: 1.7.1 → 1.8.1
- [cosmetic] “get_threat_indicators” reworded the description of “type”

### 2026-09-23 (score 62, −1)

- [security] Tool “get_cve_batch” rewrote its description, which is the text the model reads
- [security] Tool “get_cve_details” rewrote its description, which is the text the model reads
- [security] Tool “get_ioc_context” rewrote its description, which is the text the model reads
- [security] Tool “get_threat_indicators” rewrote its description, which is the text the model reads
- [functional regression] Tool coverage: 100% → 91%
- [functional improvement] Schema quality: 234 → 202
- [functional] Server version: 1.6.0 → 1.7.1
- [functional] New tool “get_cve_by_product”
- [functional] New tool “get_usage_status”
- [functional] New tool “submit_indicator”
- [functional] New tool “subscribe_alerts”

### 2026-09-22 (score 63, −1)

- [security regression] Authorization: unverified → fail
- [security regression] Stability: 0.03 → fail
- [security] Tool “get_cve_batch” rewrote its description, which is the text the model reads
- [security] Tool “get_cve_details” rewrote its description, which is the text the model reads
- [security] Tool “get_ioc_context” rewrote its description, which is the text the model reads
- [security] Tool “get_threat_indicators” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: pass → fail
- [functional regression] “get_threat_indicators” changed the type of “limit”: integer → integer|null
- [functional regression] “get_threat_indicators” changed the type of “min_score”: integer → integer|null
- [functional regression] “get_threat_indicators” changed the type of “since”: string → string|null
- [functional regression] “get_threat_indicators” changed the type of “type”: string → string|null
- [functional regression] “get_threat_indicators” changed the type of “limit”: string → integer
- [functional regression] “get_threat_indicators” changed the type of “min_score”: string → integer
- [functional improvement] Schema quality: 168 → 147
- [functional] Server version: 1.5.3 → 1.6.0
- [functional] Server version: 1.5.0 → 1.5.3
- [functional] Server version: 1.3.2 → 1.5.0
- [functional] Server version: 1.3.0 → 1.3.2
- [functional] Server version: 1.2.0 → 1.3.0
- [functional] Server version: 1.1.0 → 1.2.0
- [functional] New tool “get_ioc_batch”
- [functional] New tool “get_cve_batch”
- [functional] New tool “get_threat_actor_profile”
- [functional] New tool “get_ioc_context”
- [functional] New tool “get_cve_details”
- [cosmetic] “get_cve_details” reworded the description of “cve_id”
- [cosmetic] “get_ioc_context” reworded the description of “value”
- [cosmetic] “get_threat_indicators” reworded the description of “limit”
- [cosmetic] “get_threat_indicators” reworded the description of “min_score”
- [cosmetic] “get_threat_indicators” reworded the description of “since”
- [cosmetic] “get_threat_indicators” reworded the description of “type”

### 2026-09-21 (score 64, 0)

- [security] Tool “get_threat_indicators” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 136 → 168
- [functional improvement] Stability: unverified → 0.03
- [functional] Server version: 1.0.0 → 1.1.0

### 2026-09-20 (score 64)

First indexed and scored.

## MCP tools (13)

### `get_threat_indicators` (~331 tokens)

PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from ThreatFox, URLhaus, AbuseIPDB, OTX and NVD. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for bulk feed synchronizations. Do NOT use for single-item lookups (use get_ioc_context) or CVE analysis (use get_cve_details). USAGE EXCLUSIONS: Does not provide historical query archival beyond the active ingestion window. BEHAVIOR: Pagination is handled via the limit parameter (max 1000). Returns 402 on payment failure.

Input parameters:

- `limit` (integer|null): Pagination boundary constraint defining the maximum number of indicators to return in a single payload (integer between 1 and 1000, defaulting to 500).
- `min_score` (integer|null): Confidence score threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise.
- `since` (string|null): ISO timestamp constraint (e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after this exact timestamp.
- `type` (string|null): Indicator category filter. Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or 'FileHash-SHA256'.

### `get_cve_details` (~218 tokens)

PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile), and the CISA Known Exploited Vulnerabilities catalog (active wild exploitation status). Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for specific CVE lookups. Do NOT use for IP/domain/hash enrichment (use get_ioc_context) or bulk feed ingestion (use get_threat_indicators). USAGE EXCLUSIONS: Does not support wildcard search or threat-actor dossier profiling. BEHAVIOR: Returns 402 on payment failure, 404 if CVE is not found.

Input parameters:

- `cve_id` (string, required): Mandatory official CVE identifier string strictly formatted as 'CVE-YYYY-NNNN' (e.g., 'CVE-2021-44228').

### `get_ioc_context` (~311 tokens)

PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents before visiting, downloading, or connecting to something. Returns aggregated provenance from ThreatFox, URLhaus, AbuseIPDB, and OTX — reporting sources, observation count, aggregated confidence score, known malware families, tags, and first/last seen timestamps. SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of a single indicator. Do NOT use for bulk intelligence downloads (use get_threat_indicators), multiple indicators at once (use get_ioc_batch), or software vulnerability analysis (use get_cve_details). BEHAVIOR: Returns a normal result shaped { found: true, indicator_type, provenance } or { found: false } — never an error for 'not found'. A found:false result means nothing bad is recorded in PG1's sources; it does NOT mean the indicator is safe, only that it isn't in this dataset. Lookups that return found:false are FREE — no payment or free-tier quota is consumed. Payment (via x402 PAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) is only required when a real record is found.

Input parameters:

- `value` (string, required): Mandatory exact indicator string value to look up, such as an IPv4 address (198.51.100.1), fully qualified domain, complete URL, or SHA-256 hash string.

### `get_cve_batch` (~221 tokens)

PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA KEV status — same enrichment as get_cve_details, batched. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for looking up several known CVE ids at once (e.g. from an SBOM or scan report). Do NOT use for a single CVE (use get_cve_details, lower overhead) or for discovering CVEs by vendor/product (use get_cve_by_product). BEHAVIOR: Accepts up to 20 ids per call; malformed or not-found ids are reported per-entry rather than failing the whole batch.

Input parameters:

- `cve_ids` (array, required): Array of CVE identifiers, each formatted 'CVE-YYYY-NNNN'. Max 20 per call.

### `get_ioc_batch` (~259 tokens)

PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents. Each returns the same aggregated provenance as get_ioc_context from ThreatFox, URLhaus, AbuseIPDB, and OTX. SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. all URLs an agent is about to visit). Do NOT use for a single indicator (use get_ioc_context, lower overhead) or bulk feed synchronization (use get_threat_indicators). BEHAVIOR: Accepts up to 20 indicators per call. A found:false result for any indicator means nothing bad is recorded in PG1's sources — NOT that it's safe. If NONE of the submitted indicators are found, the whole batch is FREE — no payment or free-tier quota consumed. If at least one indicator is found, the normal payment gate (x402 PAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) applies to the full batch result.

Input parameters:

- `values` (array, required): Array of indicator values (IPv4 addresses, domains, URLs, or hashes) to look up. Max 20 per call.

### `get_threat_actor_profile` (~223 tokens)

PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associated malware/tooling. Sourced from MITRE ATT&CK Enterprise. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for actor/group-level profiling. Do NOT use for single-indicator lookups (use get_ioc_context) or vulnerability data (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Coverage is limited to groups tracked in MITRE ATT&CK — not all threat actors have an entry. BEHAVIOR: Returns 404 if no matching group or alias is found.

Input parameters:

- `actor_name` (string, required): Group name or known alias, e.g. 'APT29' or 'Cozy Bear'. Matching is case-insensitive against both the group's primary name and its known aliases.

### `get_cve_by_product` (~256 tokens)

PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status, sorted by exploitation risk. Sourced from NVD keyword search. Payment required: $0.01 via x402 (PAYMENT-SIGNATURE header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for discovering CVEs by vendor/product when you do not already have an exact CVE id. Do NOT use for a known CVE id (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Uses NVD keyword search, not strict CPE matching — results may include near-matches. BEHAVIOR: Returns up to 50 results per call.

Input parameters:

- `only_kev` (boolean): If true, only return CVEs on the CISA KEV list.
- `product` (string, required): Product name, e.g. 'log4j'.
- `vendor` (string, required): Vendor name, e.g. 'apache'.
- `version` (string): Optional specific version, e.g. '2.14.1'.

### `get_usage_status` (~89 tokens)

PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is always free.

Input parameters:

- `identifier` (string): Optional — the X-API-KEY or identifier to check usage for; defaults to the calling identifier if omitted.
- `license_key` (string): Optional — check Gumroad license status alongside free-tier usage.

### `subscribe_alerts` (~127 tokens)

PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook URL as they're ingested. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402, since it establishes a recurring subscription rather than a single paid call.

Input parameters:

- `filter` (object): Optional filter object: { indicator_type, min_epss, kev_only }
- `webhook_url` (string, required): HTTPS URL to receive POSTed alert payloads.

### `submit_indicator` (~128 tokens)

PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402. Submissions are staged for review, not immediately added to the live feed.

Input parameters:

- `confidence` (integer): Submitter's own confidence, 0-100.
- `indicator` (string, required)
- `indicator_type` (string, required)
- `malware_family` (string): Optional.
- `source_note` (string): Optional free-text on how this was observed.

### `check_wallet_sanctions` (~356 tokens)

PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet/address sanctions screening only. Do NOT use for IP/domain/hash/URL threat lookups (use get_ioc_context) or CVE data (use get_cve_details). BEHAVIOR: Returns { listed: true|false, matches, source, list_last_synced }. A listed:false result means the address is not on the OFAC SDN list as of the reported sync time — it is informational only, not legal or sanctions-compliance advice, and is never phrased as "safe" or "clean". Fails loudly (returns an error) if the sanctions data is empty or unreachable, rather than ever reporting listed:false on a data failure. VALIDATION: if the address does not match a recognised format for any supported currency (EVM, BTC/LTC/BCH/DOGE/DASH/ZEC base58 or bech32/cashaddr, TRON, Monero, Solana), returns an MCP tool error (isError: true, code invalid_address) instead of a result — it never reports listed:false for malformed input.

Input parameters:

- `address` (string, required): Mandatory wallet address to screen, e.g. an EVM 0x address, a bech32 (bc1/tb1/ltc1...) address, or a base58 address.
- `currency` (string|null): Optional currency/chain filter to narrow the match, e.g. 'BTC', 'ETH', 'XMR'.

Output parameters:

- `address` (string): The address exactly as submitted.
- `address_normalized` (string): The address after normalization, used to match against sanctioned_wallets.
- `disclaimer` (string)
- `list_last_synced` (string)
- `listed` (boolean)
- `matches` (array)
- `message` (string)
- `source` (string)

### `check_domain_age` (~289 tokens)

PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap registry for the correct per-TLD RDAP server. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for domain registration/age checks only. Do NOT use for reputation/threat-feed lookups (use get_ioc_context) or sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { found: true, available: true, registration_date, age_days, expiration_date, registrar, newly_registered, source } when available, or { found: false, available: false, reason, reason_code } when the lookup does not resolve — this tool never estimates or guesses an age. "available" is a deprecated alias of "found", kept for backward compatibility. reason_code is "unsupported_tld" when the TLD has no RDAP server in the IANA bootstrap registry, or "timeout" / "lookup_failed" for other lookup failures. A newly registered domain (age_days < 30) is reported as a common phishing signal, not as proof of malicious intent.

Input parameters:

- `domain` (string, required): Mandatory domain name or URL to check, e.g. 'example.com' or 'https://example.com/path'. The registrable domain is extracted automatically.

Output parameters:

- `age_days` (integer|null)
- `available` (boolean): Deprecated — use "found" instead. Kept for backward compatibility.
- `domain` (string)
- `expiration_date` (string|null)
- `found` (boolean): Whether a registration record was found. Same meaning as the deprecated "available" field.
- `newly_registered` (boolean|null)
- `note` (string|null)
- `reason` (string|null)
- `reason_code` (string|null)
- `registrar` (string|null)
- `registration_date` (string|null)
- `source` (string|null)

### `check_hostname_reputation` (~496 tokens)

PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, synced daily by the sovereign-threat-pipeline. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for phishing/lookalike-domain screening of a hostname only. Do NOT use for domain registration age (use check_domain_age), general threat-feed indicator lookups (use get_ioc_context), or wallet sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { hostname, verdict, sources, lookalike_of, list_synced_at, checked_at, attribution }. verdict is one of "allowlisted", "listed", "lookalike", or "not_listed" — this tool never returns "safe" or "clean", and a not_listed result means the hostname is not on the eth-phishing-detect lists, not that it is safe. "listed" results include match_type "exact" or "parent_domain" in sources. "lookalike" flags a probable typosquat/homoglyph of a known brand — via confusable-character skeleton matching within the stored tolerance, or a brand keyword embedded with extra words (e.g. metamask-login.com) — even when the hostname itself is not directly listed, and sets lookalike_of to the matched brand domain. A brand's own real domain or a subdomain of it is never flagged as its own lookalike. VALIDATION: accepts exactly one bare hostname per call (no bulk input); a value containing a URL scheme, path, port, spaces, or a wildcard returns an MCP tool error (isError: true, code invalid_hostname) instead of a verdict. Fails loudly (returns an error) if the phishing list data is unreachable or times out, rather than ever reporting not_listed on a data failure. Rate-limited to 60 calls/hour per caller when unauthenticated; a valid Gumroad license key (X-API-KEY header) exempts the limit, same as check_domain_age. List contents are never exposed beyond the single matched entry.

Input parameters:

- `hostname` (string, required): Mandatory bare hostname to screen, e.g. 'example.com'. Not a URL — no scheme, path, port, spaces, or wildcards. One hostname per call.

Output parameters:

- `attribution` (string)
- `checked_at` (string)
- `hostname` (string): The hostname after normalization (trimmed, lowercased, trailing dot stripped, IDN converted to punycode).
- `list_synced_at` (string|null)
- `lookalike_of` (string|null): The matched brand/fuzzylist domain for a "lookalike" verdict, otherwise null.
- `sources` (array)
- `verdict` (string): Never "safe" or "clean".

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/project-gifted1-pg1-threat-intel/api-mcp#diagnostics

## Score history

- 2026-09-28: 62
- 2026-09-27: 62
- 2026-09-26: 62
- 2026-09-25: 62
- 2026-09-24: 62
- 2026-09-23: 62
- 2026-09-22: 63
- 2026-09-21: 64
- 2026-09-20: 64

## Common questions

### What is the PG1 Sovereign Threat Intelligence MCP server?

PG1 Sovereign Threat Intelligence is an MCP server listed in the public MCP registry as io.github.Project-Gifted1/pg1-threat-intel. STIX IOCs, CVE lookups w/ EPSS/KEV, ATT&CK dossiers, OFAC wallet sanctions, domain age checks. This page covers its hosted endpoint (https://pg1-ai-agent.vercel.app/api/mcp).

### Is the PG1 Sovereign Threat Intelligence MCP server safe to use?

PG1 Sovereign Threat Intelligence scores 62 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the PG1 Sovereign Threat Intelligence MCP server expose?

PG1 Sovereign Threat Intelligence exposes 13 tools: get_threat_indicators, get_cve_details, get_ioc_context, get_cve_batch, get_ioc_batch, and 8 more. Their descriptions and schemas cost roughly 3,304 tokens of context every time the server is loaded.

### Does the PG1 Sovereign Threat Intelligence MCP server require authentication?

No. We connected to PG1 Sovereign Threat Intelligence without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the PG1 Sovereign Threat Intelligence MCP server still maintained?

PG1 Sovereign Threat Intelligence is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://pg1-ai-agent.vercel.app/api/mcp
- Repository: https://github.com/Project-Gifted1/pg1-ai-agent
- Changelog RSS feed: https://verifymcp.io/servers/project-gifted1-pg1-threat-intel/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/project-gifted1-pg1-threat-intel/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/project-gifted1-pg1-threat-intel/api-mcp
