Contrastapi — Security Intelligence

by UPinar

361 downloads
Not rated
GitHub

About

Security intelligence API for AI models. CVE lookup with EPSS/KEV enrichment, domain reconnaissance (DNS, WHOIS, SSL, subdomains, WAF detection), and code security checks (secrets, injection, headers). No API key required.

Details

Author
UPinar
Downloads
361
Categories
Other, Search, Knowledge Base, Developer Tools, Security, API

- Search 340,000+ vulnerabilities with EPSS exploit probability and CISA KEV status
- Full domain reconnaissance: DNS, WHOIS, SSL, subdomains, and WAF detection
- Secret detection for hardcoded API keys, tokens, and passwords (14 patterns)
- Injection detection for SQL, command, and path traversal patterns
- HTTP security header validation against best practices
- Dependency checking of packages against the CVE database

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Contrastapi — Security Intelligence
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Add the server to your MCP client configuration. No API key is required. The free tier allows up to 100 requests per hour.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "contrastapi \u2014 security intelligence": {
            "contrastapi": {
                "url": "https://mcp.contrastcyber.com/mcp"
            }
        }
    }
}

McpServers

{
    "contrastapi": {
        "url": "https://mcp.contrastcyber.com/mcp"
    }
}

ContrastAPI — 55 Security Tools + 7 MCP Resources for AI Agents

Security intelligence, built for AI agents.Give your agent grounded answers about vulnerabilities, threats, and attack surface — backed by authoritative sources (NVD, CISA KEV, FIRST EPSS, MITRE ATLAS & D3FEND), never guesswork. CVE/KEV/CWE lookup with EPSS exploit-probability and composite risk scoring, domain & IP investigation, IOC enrichment, code-security checks, and live web intelligence.55 tools, 7 Resources, and 3 Prompts — free, no API key, no signup.

- API Documentation— REST reference: 60+ endpoints, authentication, rate limits, token costs, and response envelope.
-
MCP Documentation— MCP tool-selection guide, 7 Resources, 3 Prompts, and copy-paste agent prompts.

{ "mcpServers": { "contrastapi": { "command": "npx", "args": ["-y", "mcp-remote", "https://api.contrastcyber.com/mcp/"] } } }

Restart your agent. Other clients (Python SDK, Node SDK, cURL, VS Code):mcp-setup·quickstart

Grab the.mcpbfile from thelatest releaseand double-click it (or Claude Desktop →Settings → Extensions → Install Extension…). No signup, no API key — all 55 tools ready immediately.

pip install contrastapi # Python 3.10+ — sync + async, typed responses, shortcut helpers npm install contrastapi # Node 14+ — concrete TypeScript types, 14 namespaces

Both SDKs cover every HTTP endpoint and MCP tool — CVE/KEV/CWE, ATLAS, D3FEND, Sigma rules, email security posture, domain, IP, IOC, code security, and web intelligence — with wire-exact response shapes and a typed exception hierarchy that mirrors the API error envelope. They also expose MCP Resources for browsing the ATLAS, D3FEND, and CWE catalogs (seedocs/MCP_Documentation.md) and a conditional triage Prompt (seedocs/MCP_Documentation.md#contrast-triage). Web-intelligence tools —robots_txt,redirect_chain,email_verify,brand_assets,seo_audit,geo_audit— ship with an explicit ethical floor: per-target throttling, robots.txt respected, no SMTP probing.

Smithery·npm·VS Code Marketplace·Awesome OSINT MCP·RapidAPI

Responses include averdictblock —deterministic,falsifiable_fields,data_age_seconds,sources_queried/sources_unavailable,completeness— so a verifier agent can independently re-derive specific fields from the upstream authority (NVD, RDAP, CT logs, URLhaus). ProbeGET /v1/capabilitiesfor"verdict_metadata": true.

CVE responses also embednext_calls: list[PivotHint]{tool, input, reason}triples that suggest the next MCP tool to call (e.g.kev_detailwhenkev.in_kev=true,cwe_lookupwhencwe_idis set). Agents chain workflows without manual prompting.

Semantic search through Dickens' classic tale. Find passages by meaning, theme, or concept - not just keywords.

MCP server for the AI Dev Jobs board - 8,400+ open AI/ML engineering roles at 489 companies. Search by role, location, salary, experience level. Live MCP endpoint aidevboard.com/mcp with 4 tools.

API for AI agents to search, license, and download b-roll video clips and voiceovers. Pay-per-request, no human interaction required.

Keyless remote MCP connector to search flights, hotels, and experiences at all-in prices (every mandatory tax and fee included) and book on breckenwander.com.

EU legal research for AI agents: semantic + full-text search over ~48,000 EUR-Lex acts including consolidated versions, daily drift monitoring, answers with verifiable CELEX citations. German, English, French. Remote MCP server at https://conformi.eu/api/mcp — free tier, no key required for article and timeline tools.

Corpus search and linguistic analysis for AI Agents

Destiny Codex turns the Destiny 2 Manifest (gibberish hash-reference JSON) into clean, AI-readable text. CLI + MCP server with 9 tools: search, filter, get, relationships, graph traversal, item comparison. Works for 100% of the manifest - all 83 definition tables supported generically.

Server that connects Claude/Cursor to the FatSecret Platform API. Search foods, track your diet, manage recipes, and monitor weight directly from your AI assistant.

Open-source Node.js FHIR MCP server with SMART Backend Services, metadata-aware search/CRUD tools, compact responses, FHIRPath filtering, safe pagination, audit events, and terminology lookup.

Geospatial data for AI agents via OpenStreetMap — geocoding, reverse geocoding, POI search, routing, and area statistics. No API key required.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.