
isMalicious threat intelligence for AI agents
com.ismaliciousv0.5.0更新於 Oct 1, 2026
Reputation of IPs, domains, URLs, hashes, emails and phones; CVE lookups; prompt-injection scans
安裝
在 SourceWeft 中
- 開啟 儀表板中的 isMalicious threat intelligence for AI agents,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
@ismalicious/mcp-server
A zero-dependency Model Context Protocol server that gives an AI agent isMalicious threat intelligence: reputation verdicts for IP addresses, domains, URLs, file hashes, email addresses and phone numbers, the CVE catalog, and the isinjected gate that scans untrusted content for prompt injection before the agent acts on it.
Install
Keys: https://ismalicious.com/app/account. Free keys exist. Without the two
variables the server still starts, offering only bootstrap_key, which mints a
free key from an email address and uses it for the session (see below).
Registry name: com.ismalicious/mcp-server
(https://registry.modelcontextprotocol.io/v0/servers?search=ismalicious).
Tools
The default search API reads a bare keyword as its .com (paypal →
paypal.com) and returns at most 500 listed lookalikes. limit only reduces
that sample. Only listed domains are returned and a name buried in a longer
hostname is not matched, so an empty answer does not prove that no lookalike
exists.
The MCP result labels total_hits_scope as upstream_sample. Legacy or custom
API responses without completeness metadata produce truncated: null.
Scans and requests are two meters: https://ismalicious.com/api-docs.
Indicator types
check_indicator and check_indicators type each indicator before any
request, the way the API does:
Every value is NFKC-normalised first, so full-width forms from CJK text
(090−1234−5678, user@evil.com, evil.com) read as their ASCII
selves, and an ideographic full stop (。) separates labels. Numbers are read
as typeset before the phone rule applies, and that form is what is sent:
no-break and thin spaces become spaces, typographic dashes and the minus sign
become -, (+33) 6 … becomes +33 6 …, +44 (0)20 … loses the national
(0), 030/1234567 its slash, tel: links their ;ext=… parameters, and a
trailing extension (x123, ext. 123) is dropped. A contact link is read as
the address or number it holds, with or without //: mailto:, tel:,
sms: (and its ?body=…), callto:, and sip: when its user part is a
number. So is a spreadsheet export's =+1…, ="+1…" or '+1….
Input that is none of these is refused before any request (invalid_params;
in a batch, a row with an error, not sent and not charged), never sent as a
domain: an @ the email rule rejects ("john doe"@example.com,
user@localhost, [email protected]/), digits and separators the phone rule
rejects (12345), a number written with its keypad letters
(+1-800-FLOWERS), a URL whose host is not a dotted domain or an IP
(https://intranet/), and anything else that is not a hostname (localhost,
*.evil.com, spaces, quotes or brackets). Sent as a domain, each came back
"not listed", which read as clean / allow.
Defanged input is refanged first, and the refanged value is what is sent:
hxxp(s) in any case, [.] (.) {.} [dot], [:], [@] [at], [/],
surrounding brackets or quotes, a contact scheme, a display name around an
address, trailing sentence punctuation. The result carries input when it differs from indicator by
more than letter case.
SHA-512, SHA-384, TLSH, ssdeep and other hexadecimal strings of 32 characters
or more are refused before any request (invalid_params; in a batch, a row
with an error, not sent and not charged): the API indexes MD5, SHA-1 and
SHA-256 only.
An email address or a phone number is never clean. The API's email and
phone sources are a few feeds, so not being in them is unknown /
unverified, not evidence of safety. Its verdict comes from the address or
number's own listings and, for an email address, the sender domain. A listing
makes it malicious when its source's confidence is 70 or more, or when two
independent publishers at 60 or more agree; one list below that (the
consumer-complaint number feeds and the one address blacklist sit at 55) makes
it suspicious, because such lists name a displayed caller ID or From address,
often forged. For an email address, a
malicious domain that is not a shared mail provider makes the address
malicious; a domain with threat listings, a disposable domain or a domain
whose null MX says it accepts no mail makes it suspicious. Everything is read
from the API's dataset and cached DNS: mx is false only for a null MX,
and null when no DNS answer is cached or the cached one lists no MX. An API server
that predates email and phone support answers them as domains; the result is
then unknown / unverified with a note, never clean / allow.
check_indicator example
blocklist counts threat listings only. Listings whose threatClass is
infrastructure, policy or allowlist — a cloud provider's published
ranges, a Tor exit list, an ad-blocking list — say what the entity is or what
a customer may choose to block, not that it attacked anyone, so they never
reach the verdict. They are reported under infrastructure, which is absent
when there are none:
attributes is one or more of tor-exit, vpn, proxy, doh-resolver,
dns-resolver, sinkhole, cloud, cdn, crawler, scanner,
monitoring, disposable-email, dynamic-dns, url-shortener, bogon,
saas, allowlist; new ones may appear. An indicator cited by a honeypot
feed and sitting in a cloud range keeps its honeypot verdict.
Email address and phone number examples
check_indicator with { "indicator": "06 12 34 56 78", "country": "FR" }:
resolvedWith is e164 (written with + or 00), country (resolved with
country), nanp-guess (10 digits read as North American) or digits (no
country could be told; e164 is then null).
A hash the dataset knows also carries file (family, file type, MIME type,
name, size, signature, tags, the file's other digests) and lookupStatus; a
citing source reached through another digest of the same file says
via: "alias", one reached through a listed range via: "cidr".
A hash NSRL knows (flags.knownGood) that a threat blocklist also lists comes
back suspicious with recommendedAction: "review", never malicious /
block: NSRL identifies known software, it does not clear it, and the two
sources disagree, which is a call for an analyst. The headline names the
conflict (<sha256> is known software (NSRL), yet 2 sources list it; review before blocking.) and blocklist still lists the citing sources.
check_indicators relays each row's recommendedAction from the API as it
comes; its rows carry no NSRL flag.
check_indicators returns its rows in input order. When the result would pass
48 KB, whole rows are dropped from the end and the result says so with
returned, omitted, truncated: true and a note; malicious still counts
every row, split into maliciousReturned and maliciousOmitted.
search_indicators does the same with indicators past 32 KB.
Errors
Every failure is a result with isError: true and this body:
error is one of rate_limited, unauthorized, forbidden, not_found,
bad_request, upstream_error, timeout, network_error, invalid_params.
quota.kind is burst, monthly, daily, scans or issuance. A 401 says
whether no key is configured or the configured one was refused.
Timeouts and cancellation
Gate tools 15 s, check_indicator 25 s, CVE tools 10 s, search_indicators
20 s, check_indicators 60 s, check_password_exposure 10 s, bootstrap_key
15 s. ISMALICIOUS_TIMEOUT_MS
replaces all of them; ISMALICIOUS_TIMEOUT_<TOOL>_MS (for example
ISMALICIOUS_TIMEOUT_CHECK_INDICATOR_MS=3000) sets one tool's and wins. A
notifications/cancelled from the client aborts the HTTP call; the cancelled
request gets no response.
Latency
What the server itself does to answer sooner:
fastenrichment ischeck_indicator's default: the API answers from cached intelligence without calling a live upstream first. Facets it did not have cached are listed inmeta.pendingand fetched in the background; only then does the headline ask for one re-check after a few seconds, and it says that a facet still pending after it is not coming (the answer stands; each re-check is a billed request). A hash no source has cached may still wait a few seconds on CIRCL before the answer.standardmay call DNS, OTX or CIRCL before answering.fastneeds an API deploy from 2026-09-30 or later: an older server reads it asstandardfor an IP, a domain or a URL, but storesenrichmentLevel: "fast"in the hash document it caches, which is why this release follows that deploy. Email addresses and phone numbers are answered from cached data at every level.- Connection reuse: one keep-alive pool per scheme (16 sockets, idle
sockets kept 30 s), gzip or brotli responses, so a call a few seconds after
the previous one does not pay a new TCP and TLS handshake. After
initialize, when a key is set, one unauthenticatedGET /healthopens the connection before the first tool call (ISMALICIOUS_PREWARM=0to skip). - Result cache: a successful result is replayed to an identical call —
same key, tool and normalised arguments — for 60 s (
check_indicator,check_indicators,check_url), 1 h (get_cve) or 5 min (recent_cves,search_indicators). A result that lists pending facets is never replayed: the re-check it invites goes to the API. A replay costs no request and says so (meta.cached,meta.ageSec, or a top-level_cache).scan_before_use,bootstrap_keyand errors are never cached.ISMALICIOUS_CACHE_TTL_Scaps or (with0) disables it. - Shared calls: identical calls in flight share one request, a result
with pending facets included. A defanged and a plain form of one indicator
are one call; each caller still gets its own
input.
meta.latencyMs on a check_indicator result is the client-measured round
trip; meta.processingMs is the API's own time.
Calling the API host directly
By default the server calls https://ismalicious.com/api, which forwards to
the API. Setting ISMALICIOUS_API_BASE=https://api.ismalicious.com calls the
API host directly and skips that hop. bootstrap_key still goes to
https://ismalicious.com/api (its route exists only there; see
ISMALICIOUS_WEB_BASE). One billing difference: on the API host
search_indicators is charged one request of the monthly quota, where the
default base only counts it against the burst rate limit.
Resource
ismalicious://quota (application/json): the scan meter from
GET /gate/quota and the request-quota headers seen on the last billed call
of this session.
Environment
Development
The version is declared once in src/version.ts; CHANGELOG.md lists what changed.
This repository mirrors packages/mcp-server from the isMalicious monorepo, where
releases to npm and the MCP registry are cut. Issues and pull requests are welcome here.
The Dockerfile is the build Glama runs to list the server. It sets a
placeholder key pair so tools/list shows every tool; pass a real pair with
docker run -i -e ISMALICIOUS_API_KEY=… -e ISMALICIOUS_API_SECRET=…, or empty
values for bootstrap mode.
來源:README.md,提交 2892ea7
工具
0版本歷史
5- v0.5.0最新Oct 1, 2026
- v0.4.0Sep 30, 2026
- v0.3.1Sep 30, 2026
- v0.3.0Sep 25, 2026
- v0.2.0Sep 16, 2026


