Loomal

ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)

0 starsRemote-capable

About Threatfox

Threatfox is an MCP (Model Context Protocol) server published by pipeworx-io in the official MCP registry. ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)

Threatfox runs as a hosted remote over streamable-http — MCP clients connect directly to its endpoint, with nothing to install locally.

Development happens in the open at github.com/pipeworx-io/mcp-threatfox.

Use Threatfox with your agent

Claude Code · one command
claude mcp add --transport http threatfox https://gateway.pipeworx.io/threatfox/mcp
Claude Desktop, Cursor & other MCP clients · config
{
  "mcpServers": {
    "threatfox": {
      "url": "https://gateway.pipeworx.io/threatfox/mcp"
    }
  }
}
streamable-httphttps://gateway.pipeworx.io/threatfox/mcp

Frequently asked questions

What is Threatfox?
Threatfox is an MCP (Model Context Protocol) server by pipeworx-io. ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
How do I connect Threatfox to Claude, Cursor, or another MCP client?
Threatfox is a remote MCP server — add its endpoint (https://gateway.pipeworx.io/threatfox/mcp) to your client's MCP configuration (for example with "claude mcp add", or under "mcpServers" in Cursor's mcp.json) and restart the client.
Is Threatfox open source?
Yes — the source code is public at github.com/pipeworx-io/mcp-threatfox.
Can AI agents pay to use Threatfox?
Not yet through Loomal — Threatfox is listed as a free directory entry. If its maintainer verifies ownership, they can set per-call USDC pricing that agents pay over x402, with settlement on Base.

Listing data from the official MCP registry and GitHub, refreshed periodically. Not affiliated with the maintainer unless claimed. Maintain Threatfox? Claim this listing free by verifying GitHub ownership, or contact us.