Agent Tools
Back to MCP servers
● healthy

Real-time threat intelligence for AI agents — 900K+ IOCs including prompt-injection payloads and malicious AI-skill (MCP tool) indicators. Free, no API key. Check IPs, domains, URLs, hashes, CVEs, **prompt-injection payloads**, and **malicious AI-skill / MCP-tool definitions** against the live Nullcone network. Hosted over streamablecHTTP — nothing to install. ## Connect claude mcp add --transport http nullcone https://nullcone.ai/mcp Or point any MCP client at `https://nullcone.ai/mcp`. ## What you get - `lookup_ioc` — check any indicator against the feed - `recent_threats` — current threat picture - `submit_ioc` / `submit_batch` — contribute indicators - `check_prompt` — sub-millisecond prompt-injection lookup - `validate_skill` / `scan_skill_content` — vet MCP tools and AI skills before loading - `poll_since` — incremental sync, no persistent connection - 30+ tools total, plus resources (`threat://recent`, `threat://stats`) and analysis prompts No signup required. Reads and submissions are open; destructive tools are disabled on the public endpoint.

Transport
streamable-http
Auth
smithery_api_key
Cost

How to connect

MCP endpoint (streamable-http)
https://server.smithery.ai/maco144/nullcone/mcp
JSON-RPC initialize probe
curl -X POST https://server.smithery.ai/maco144/nullcone/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{}}'
Homepage
https://nullcone.ai
Listed at (smithery)
https://nullcone.ai