# WhisperGraph (npm · @whisper-security/whisper-graph-mcp)

The internet's infrastructure graph for AI agents - 46B nodes and edges, free trial via 2 HTTP calls

- Trust score: 76/100 (medium)
- Change this week: +27
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `mcp.whisper.security`: 36/100, [markdown](https://verifymcp.io/servers/whisper-sec-whisper-graph/mcp.md), [page](https://verifymcp.io/servers/whisper-sec-whisper-graph/mcp)
- npm · `@whisper-security/whisper-graph-mcp`: 76/100 (this document), [markdown](https://verifymcp.io/servers/whisper-sec-whisper-graph/whisper-security-whisper-graph-mcp.md), [page](https://verifymcp.io/servers/whisper-sec-whisper-graph/whisper-security-whisper-graph-mcp)

## Channel facts

- Registry: `npm`
- Package: `@whisper-security/whisper-graph-mcp`
- Version: `0.2.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects @hono/node-server 1.19.17, reached via @modelcontextprotocol/sdk > @hono/node-server. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 96), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to whisper-sec/whisper-graph-mcp).
  - Clear OSI-approved license (Apache-2.0).
  - Actively maintained (last published 15 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 66/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 7451 tokens (~532/item across 14 items; 8 tools + 6 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 23/100
  - Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add whisper-sec-whisper-graph -- npx -y @whisper-security/whisper-graph-mcp
```

### Codex

```bash
codex mcp add whisper-sec-whisper-graph -- npx -y @whisper-security/whisper-graph-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "whisper-sec-whisper-graph": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@whisper-security/whisper-graph-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add whisper-sec-whisper-graph --command npx --arg -y --arg @whisper-security/whisper-graph-mcp
```

### Hermes

```yaml
mcp_servers:
  whisper-sec-whisper-graph:
    command: "npx"
    args: ["-y", "@whisper-security/whisper-graph-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "whisper-sec-whisper-graph": {
      "command": "npx",
      "args": [
        "-y",
        "@whisper-security/whisper-graph-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 76, +3)

- [functional improvement] Stability: unverified → 0.23

### 2026-08-02 (score 73, +50)

- [security regression] GHSA-frvp-7c67-39w9 affects this package: medium
- [security regression] Known CVEs: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Provenance: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [security] The attested source repository moved: whisper-sec/whisper-graph-mcp
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Schema quality: 100 → unverified
- [functional improvement] Schema quality: unverified → good
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional] Licence: Apache-2.0

### 2026-08-01 (score 23, +18)

- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] Schema quality: unverified → 100

### 2026-07-31 (score 5, −26)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 31, −18)

- [security regression] Malware scan: pass → unverified

### 2026-07-27 (score 49)

First indexed and scored.

## MCP tools (8)

### `query` (~1391 tokens)

WhisperGraph Cypher Query

Execute a Cypher query against WhisperGraph - the internet's largest infrastructure graph database (7.39B nodes, 39B edges, 5.6M threat intel edges). Returns JSON with columns, rows, and statistics.

Use this tool for any question involving domains, hostnames, IPs, DNS, BGP, GeoIP, web links, email infrastructure, WHOIS, DNSSEC, or threat intelligence.

NODE LABELS (20): HOSTNAME (2.6B), IPV4 (619M), IPV6 (820K), PREFIX (2.5M), ASN (116K), ASN_NAME (108K), ORGANIZATION (119M), CITY (54K), TLD (1.7K), COUNTRY (424), RIR (5), DNSSEC_ALGORITHM (8), TLD_OPERATOR (737), REGISTRAR (51K), EMAIL (237M), PHONE (60M), REGISTERED_PREFIX (326K, virtual), ANNOUNCED_PREFIX (1.4M, virtual), FEED_SOURCE (40, virtual), CATEGORY (18, virtual). All nodes have a "name" property. Threat-listed IPV4/IPV6/HOSTNAME nodes also carry: threatScore (Double), threatLevel (NONE/INFO/LOW/MEDIUM/HIGH/CRITICAL), threatSources, threatFirstSeen/threatLastSeen (epoch ms), and 13 boolean flags: isThreat, isAnonymizer, isC2, isMalware, isPhishing, isSpam, isBruteforce, isScanner, isBlacklist, isTor, isProxy, isVpn, isWhitelist. ANNOUNCED_PREFIX adds BGP-enrichment: isMoas, isAnycast, isWithdrawn, wasMoas, hasOriginChanged, threatScore, threatLevel, threatSourceCount, firstSeen, lastSeen. LISTED_IN edges carry firstSeen, lastSeen, weight.

KEY EDGES: RESOLVES_TO (HOSTNAME→IPV4/IPV6, forward only), CHILD_OF (child→parent: HOSTNAME→HOSTNAME→TLD), ALIAS_OF (CNAME), NAMESERVER_FOR / MAIL_FOR (NS/MX → domain - to list a domain's MX use (domain)<-[:MAIL_FOR]-(mx)), SPF_INCLUDE/SPF_IP/SPF_A/SPF_MX/SPF_EXISTS/SPF_REDIRECT (SPF policy; SPF_IP targets IPV4|IPV6|PREFIX), LINKS_TO (web hyperlinks, 10.8B), BELONGS_TO (3 semantics: IPV4/IPV6→PREFIX, PREFIX→RIR, FEED_SOURCE→CATEGORY), LOCATED_IN (IPV4/IPV6→CITY only - for country, chain through HAS_COUNTRY), HAS_COUNTRY (ASN/CITY/IPV4/HOSTNAME/PHONE/ANNOUNCED_PREFIX/REGISTERED_PREFIX→COUNTRY), ANNOUNCED_BY (IPV4/IPV6→ANNOUNCED_PREFIX, then ROUTES→ASN), ROUTES (ASN/ANN…

Input parameters:

- `cypher` (string, required): Cypher query string. Must include LIMIT for exploration queries. Use {name: "value"} property syntax for lookups.

Output parameters:

- `columns` (array)
- `error` (string)
- `errorCode` (string)
- `retryable` (boolean)
- `rows` (array)
- `statistics` (object)
- `success` (boolean)
- `suggestion` (string)

### `list_labels` (~121 tokens)

List WhisperGraph Labels

List all node labels in WhisperGraph with their counts.

Use this BEFORE writing a query when you're not sure which label to anchor on. It rules out hallucinated labels (e.g. there is no DOMAIN or FQDN - only HOSTNAME) and tells you which labels are large (HOSTNAME, IPV4) vs small (RIR, COUNTRY).

Returns: an array of {label, count} rows. Cached server-side for 5 minutes.

Tip: pair with describe_label to verify which properties exist on a label before referencing them in WHERE clauses.

Output parameters:

- `labels` (array)

### `describe_label` (~179 tokens)

Describe WhisperGraph Label

Describe a single label: confirm it exists, get its node count, and enumerate the property keys observed on that label.

Use this BEFORE writing a query that filters on a specific property. If you write WHERE h.fqdn = "..." but describe_label("HOSTNAME") returns properties = ["name", "threatScore", ...], your query will silently scan the entire label. Verify first.

Argument: label (string, required) - uppercase letters, digits, and underscores only.

Returns: {name, exists, count, properties[], edgesDoc}. Cached 5 minutes.

Tip: edge types are NOT in the response - see the whisper://schema/relationships resource for which edges connect this label to others.

Input parameters:

- `label` (string, required): Label name. Uppercase letters, digits, underscores. Examples: HOSTNAME, IPV4, ASN.

Output parameters:

- `count` (number)
- `edgesDoc` (string)
- `error` (string)
- `exists` (boolean)
- `name` (string)
- `properties` (array)
- `propertiesError` (string)
- `suggestion` (string)

### `explain_indicator` (~276 tokens)

Threat Assessment for an Indicator

Run a comprehensive threat assessment on a single indicator. The indicator can be an IPv4, IPv6, hostname, CIDR network, or ASN - the procedure auto-detects the type.

Returns a single structured row: { indicator, type, available, cached, found, score, level (NONE/INFO/LOW/MEDIUM/HIGH/CRITICAL), explanation, factors[], sources[] }. For ASN inputs the row also includes a `breakdown` object with composite sub-scores (threatDensityScore, graphMetricsScore, historicalScore, prefixAgeScore). For CIDR inputs the explanation field carries threat-density stats (listed IPs, density %).

Prefer this tool over manual ASN→PREFIX→IP→LISTED_IN walks - those time out on large ASNs (AWS, GCP, Azure, Cloudflare). Performance: 3-25ms for IP/domain/network, up to ~80ms for ASN.

Argument: indicator (string, required). Allowed characters: letters, digits, '.', '-', ':', '/', '_'. Cypher-special characters are rejected.

Input parameters:

- `indicator` (string, required): IPv4 / IPv6 / hostname / CIDR / ASN. Examples: "185.220.101.1", "google.com", "3.64.0.0/12", "AS13335".

Output parameters:

- `rows` (array)

### `whisper_history` (~259 tokens)

Historical WHOIS / BGP for an Indicator

Retrieve historical WHOIS or BGP data for a single indicator. The indicator can be an IPv4, IPv6, hostname, CIDR, or ASN - the procedure auto-detects the type.

Returns shape varies by indicator type:
  \- IP / prefix (type=routing): { origin, prefix, startTime, endTime, peersSeing }
  \- Domain (type=domain): WHOIS snapshots - { queryTime, createDate, updateDate, expiryDate, registrar, nameServers }
  \- ASN (type=asn): prefix announcement history (slow, ~9s for large ASNs)

On upstream failure (the data source is rate-limiting or temporarily down), the row shape is: { available: false, error: "timeout" | ..., retryAfter: <seconds> }. Surface the retryAfter to the user - DO NOT loop on retry.

Argument: indicator (string, required). Allowed characters: letters, digits, '.', '-', ':', '/', '_'.

Input parameters:

- `indicator` (string, required): IPv4 / IPv6 / hostname / CIDR / ASN. Examples: "8.8.8.8", "google.com", "8.8.8.0/24", "AS15169".

Output parameters:

- `rows` (array)

### `domain_variants` (~392 tokens)

Typosquat / Brand-Protection Variants

Generate typosquatting / brand-protection variants of a domain or brand name and check which ones actually exist in WhisperGraph.

Runs 14 mutation algorithms - character omission, repetition, transposition, QWERTY-adjacent replacement/insertion, vowel-swap, bitsquatting, homoglyph / Unicode confusables, hyphenation, dot insertion/omission, TLD-swap, TLD-addition, and subdomain-add. Unicode input is accepted (and expected) so IDN homoglyph lookalikes resolve correctly.

Returns { rows: [...] }. Each row: { variant, method, exists, nodeId, label, confidence (0.3-0.9), confidenceLabel (low/medium/high) }. By default only variants that EXIST as nodes are returned - the registered lookalikes worth investigating. Note that "exists" means registered/observed, NOT malicious: pivot each hit through explain_indicator for a threat verdict.

Arguments:
  \- name (string, required) - the domain or brand to mutate, e.g. "google.com". Allowed characters: letters (including Unicode), digits, '.', '-', '_'.
  \- label (string, optional, default HOSTNAME) - node label to check existence against.
  \- includeNonExistent (boolean, optional, default false) - when true, also return generated variants that do NOT exist in the graph (larger, noisier result set).

Performance: typically <150ms. Results are capped at 500 rows.

Input parameters:

- `includeNonExistent` (boolean): Optional. When true, also return generated variants that do not exist in the graph. Default: false.
- `label` (string): Optional node label to check existence against. Default: HOSTNAME.
- `name` (string, required): Domain or brand to generate variants for. Examples: "google.com", "paypal.com". Unicode allowed.

Output parameters:

- `rows` (array)

### `list_recipes` (~358 tokens)

List WhisperGraph Catalog Recipes

List the whisper.security catalog of ready-made recipes - the full set exposed by this server. Two kinds:

\- `direct` recipes (keyless) are a single graph procedure: whisper.assess (threat posture), whisper.identify (vendor/operator), whisper.explain, whisper.variants (typosquats), whisper.origins (CDN de-cloak), whisper.history / whisper.history.whois (WHOIS timeline), whisper.walk, whisper.psl.*, whisper.asSet, whisper.lookupTorRelay, db.schema. These run WITHOUT an API key (rate-limited).
\- `flow` recipes (keyed) are curated multi-step investigations: attack-path, attack-surface, indicator-enrichment, infrastructure-mapping, subdomain-takeover, bgp-hijack-exposure, blast-radius, route-health, typosquat, nameserver-hijack-dns-consistency, map-supply-chain-concentration, discover-ai-agent-infrastructure, build-takedown-evidence-package, indicator, anycast-dns-root-sovereignty. These need a WhisperGraph API key.

Each entry returns { slug, title, purpose, category, mode, access, requiresKey, inputs[], params[], columns[], docsUrl }. Run any of them with run_recipe(recipe=<slug>, ...). Optional filters:
  \- mode ("direct" | "flow")
  \- access ("keyless" | "keyed")

The catalog is generated from the canonical whisper.security catalog, so this list stays in sync with what the platform ships.

Input parameters:

- `access` (string): Filter to keyless (no API key) or keyed (API key required) recipes.
- `mode` (string): Filter to only direct or only flow recipes.

Output parameters:

- `recipes` (array)

### `run_recipe` (~526 tokens)

Run a WhisperGraph Catalog Recipe

Run a named whisper.security catalog recipe by its slug (see list_recipes for the full set). This is the highest-leverage tool for infrastructure & threat questions: instead of hand-writing Cypher, run the curated recipe.

Arguments:
  \- recipe (string, required) - the recipe slug, e.g. "assess", "identify", "indicator-enrichment", "infrastructure-mapping", "attack-path", "subdomain-takeover", "typosquat", "bgp-hijack-exposure".
  \- inputs (object, optional) - the recipe's inputs keyed by name (see the recipe's inputs[] in list_recipes). Examples: {"v":"8.8.8.8"} for assess/identify; {"value":"github.com"} for indicator-enrichment / infrastructure-mapping; {"domain":"paypal.com"} for typosquat; {"country":"BR"} for anycast-dns-root-sovereignty; {"value":"paypal.com","other":"paypa1.com"} for attack-path. Omit to use the recipe's built-in example.
  \- params (object, optional) - flow tuning params, e.g. {"level":"deep"} for attack-surface / infrastructure-mapping / attack-path, {"depth":3} for blast-radius, {"instanceType":"Global"} for anycast-dns-root-sovereignty.

Behaviour:
  \- `direct` recipes run keyless and return { success, recipe, mode:"direct", columns[], rows[], statistics }.
  \- `flow` recipes need an API key (WHISPER_API_KEY over stdio, or the relayed X-API-Key / Authorization header over HTTP) and return { success, recipe, mode:"flow", steps[], totalLatencyMs } where each step carries { id, title, columns, rows }.
  \- On an unknown slug or a keyless call to a keyed flow, returns { success:false, error, suggestion } - never throws.

Prefer run_recipe over hand-written Cypher whenever a recipe fits the question; fall back to the query tool for bespoke traversals.

Input parameters:

- `inputs` (object): The recipe's inputs keyed by name, e.g. {"v":"8.8.8.8"} or {"value":"github.com"}.
- `params` (object): Optional flow tuning params, e.g. {"level":"deep"} or {"depth":3}.
- `recipe` (string, required): Recipe slug from list_recipes, e.g. "assess", "indicator-enrichment", "attack-path".

Output parameters:

- `columns` (array)
- `error` (string)
- `mode` (string)
- `recipe` (string)
- `rows` (array)
- `statistics` (object)
- `steps` (array)
- `success` (boolean)
- `suggestion` (string)
- `totalLatencyMs` (number)

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/whisper-sec-whisper-graph/whisper-security-whisper-graph-mcp#diagnostics

## Score history

- 2026-08-03: 76
- 2026-08-02: 73
- 2026-08-01: 23
- 2026-07-31: 5
- 2026-07-30: 31
- 2026-07-28: 49
- 2026-07-27: 49

## Links

- npm package: https://www.npmjs.com/package/@whisper-security/whisper-graph-mcp
- Socket report: https://socket.dev/npm/package/@whisper-security/whisper-graph-mcp
- Repository: https://github.com/whisper-sec/whisper-graph-mcp
- Website: https://www.whisper.security/docs/ai/mcp/setup
- Changelog RSS feed: https://verifymcp.io/servers/whisper-sec-whisper-graph/whisper-security-whisper-graph-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/whisper-sec-whisper-graph/whisper-security-whisper-graph-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/whisper-sec-whisper-graph/whisper-security-whisper-graph-mcp
