Koot by Datakoot

com.datakootv1.2.2Updated Oct 9, 2026

One-call briefings for AI agents: dependency risk (KEV/EPSS), SEC companies, domains, US places.

VerifiedStreamable HTTPWeb executableFinanceSecurity & MonitoringLocation & Lifestyle

Overview

AI-generated overview

Koot gives an assistant one-call briefings on software dependency risk, US public companies, domains, and US places.

What it does
Koot bundles several official-data lookups into single calls. brief_stack checks packages for known vulnerabilities, ranks them by real-world exploitation signals, and returns a fix-first list. brief_company returns SEC profiles, recent filings, insider trades, and reported financials for a US public company. brief_domain covers registration, DNS, email security, tech stack, and subdomains, while brief_place reports weather, alerts, earthquakes, and elevation for a US location. Pro tools add watch lists and change-only reports.
When to use it
Use it when you want a quick, consolidated answer instead of chaining many lookups: checking whether a project's dependencies are safe to ship, getting a snapshot of a US public company's filings, profiling a domain, or checking conditions and hazards for a US place.
Requirements
A remote MCP endpoint at no local runtime, API key, or signup for the free tier. Pro features require a paid key sent as an Authorization Bearer header or an X-Datakoot-Key header. Network access to the endpoint is needed.
Before you install
The free tier is limited to 5 briefs a day. Paid options exist: per-brief payment in USDC on Base through a separate x402 endpoint, and a Pro subscription. Pro keys are secrets and should be passed only as the Authorization Bearer or X-Datakoot-Key header. Watch tools store what you ask them to monitor and can send daily alerts to Slack or Discord, so review what you submit.

Installation

In SourceWeft

  1. Open Koot by Datakoot in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "koot-briefings": {
      "type": "http",
      "url": "https://koot.datakoot.com/mcp"
    }
  }
}

README

Koot — by Datakoot

One call that does the work of many lookups. Koot briefs your AI agent on a software stack, a public company, a domain or a US place, and answers in one line, with the details underneath.

https://koot.datakoot.com/mcp

No API key for the free briefs (5 a day). Built on the nine Datakoot official-data servers.

Tools

ToolWhat it doesSources
brief_stack"Is my project safe?" Checks every package for known vulnerabilities, ranks them by real-world exploitation (CISA KEV, FIRST EPSS), flags abandoned packages and npm malware placeholders, and returns a fix-first listOSV.dev, CISA KEV, FIRST EPSS, npm / PyPI / crates.io
brief_companyA US public company in one call: SEC profile, recent filings (8-K material events flagged), insider trades and reported financialsSEC EDGAR
brief_domainA domain in one call: registration and DNS, email security (SPF/DKIM/DMARC), tech stack, subdomains from certificate logsRDAP, DNS, Certificate Transparency
brief_placeA US place in one call: current conditions, forecast, active alerts for the state, nearby earthquakes, elevationNWS, USGS, US Census
koot_watchPro. Tell Koot once what to watch (packages, a pasted package.json, and/or company tickers). Optional daily alerts to Slack or Discord
koot_whats_newPro. "Anything new?" Reports only what changed: newly exploited or likely-exploited issues in your packages, and new SEC filings from your companies
koot_watchesPro. Lists what Koot is watching
koot_unwatchPro. Stop watching some or all items, or turn alerts off

Quick start

claude mcp add --transport http koot https://koot.datakoot.com/mcp

Or point any MCP client at https://koot.datakoot.com/mcp.

Try it in 10 seconds — no key, no signup

bash
curl -s https://koot.datakoot.com/mcp \  -H 'content-type: application/json' \  -H 'accept: application/json, text/event-stream' \  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"brief_stack","arguments":{"packages":["[email protected]","[email protected]"]}}}'

The koot field answers in one line, for example: "⚠️ No confirmed exploitation, but 2 issue(s) have a high exploit probability (EPSS ≥ 10%). Fix first: npm:[email protected]."

Or just ask your agent:

  • "Is my package.json safe to ship?"
  • "Brief me on Tesla's recent SEC filings."
  • "What's the weather risk in Pine Grove, PA today?"

Pricing

  • Free: 5 briefs a day, no key, no signup.
  • Pay per brief: $0.01 in USDC on Base through x402, with no account, at https://x402.datakoot.com/mcp.
  • Pro ($15/mo): unlimited briefs, plus Koot Watch. Send your key as Authorization: Bearer <key> (or X-Datakoot-Key: <key>). Pricing.

Data & attribution

Data comes from official public sources: NIST NVD and CISA KEV (US public domain), FIRST EPSS, OSV.dev (CC-BY 4.0), SEC EDGAR, the National Weather Service, USGS and the US Census Bureau. No API keys. No signup. No data resale.

Part of Datakoot: official-source data for AI agents, one keyless call.

Source: README.md at commit 719104f

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.2.2LatestOct 9, 2026