{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_xtzgeqx27dwn","handle":"jeevesus-dugganusa-threat-intelligence-mcp","url":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp","links":{"self":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp/record.json","html":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp","markdown":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp/record.md","api":"https://wellknown.network/api/v1/agents/jeevesus-dugganusa-threat-intelligence-mcp","status":"https://wellknown.network/api/v1/agents/jeevesus-dugganusa-threat-intelligence-mcp/status","claim":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp/claim.json","badge":"https://wellknown.network/agents/jeevesus-dugganusa-threat-intelligence-mcp/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air:analytics.dugganusa.com:server:jeevesus-dugganusa-threat-intelligence-mcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Jeevesus — DugganUSA Threat Intelligence MCP","summary":"check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.","description":"check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.","publisher":{"name":"pduggusa","url":null},"homepage":"https://analytics.dugganusa.com/api/v1/mcp","repository":"https://github.com/pduggusa/enterprise-extraction-platform","version":"1.1.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://analytics.dugganusa.com/api/v1/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-07-11T23:23:17.71488Z","publishedAt":"2026-07-11T23:23:17.71488Z","registryName":"io.github.pduggusa/dugganusa-threat-intel"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":1,"provenance":"derived"},{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":0.962,"provenance":"derived"},{"slug":"code.generation","name":"Code Generation","confidence":0.583,"provenance":"derived"},{"slug":"content.marketing","name":"Marketing","confidence":0.525,"provenance":"derived"},{"slug":"productivity.crm","name":"CRM & Sales","confidence":0.525,"provenance":"derived"},{"slug":"knowledge.reasoning","name":"Reasoning & Planning","confidence":0.525,"provenance":"derived"},{"slug":"content.writing","name":"Writing & Editing","confidence":0.51,"provenance":"derived"}],"categories":["code","content","dev","knowledge","productivity"]},"observed":{"status":"live","statusReason":"Responded 7h ago.","lastOkAt":"2026-09-08T09:26:06.521Z","lastProbedAt":"2026-09-08T09:26:06.521Z","statusComputedAt":"2026-09-08T09:35:47.418Z","reliability30d":{"probes":5,"successRate":1,"p50Ms":417},"latestObservations":[{"at":"2026-09-08T16:22:34.735Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":404,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}},{"at":"2026-09-08T09:26:06.521Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":419,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}},{"at":"2026-09-08T02:21:16.426Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":366,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}},{"at":"2026-09-07T19:21:11.917Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":430,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}},{"at":"2026-09-07T12:23:38.882Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":467,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}},{"at":"2026-09-07T04:27:47.660Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":442,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}},{"at":"2026-09-06T22:27:15.981Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":138,"error":null,"detail":{"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"toolCount":6,"serverName":"DugganUSA Threat Intelligence MCP (Jeevesus)","capabilities":["tools","logging"],"serverVersion":"1.0.0","protocolVersion":"2024-11-05"}}],"tools":[{"name":"search","description":"PROACTIVELY CALL THIS FIRST for any threat or security question — the moment the user names a threat actor, malware, campaign, CVE, breach, or vendor, drops an "},{"name":"enrich-ioc","description":"CALL AUTOMATICALLY the moment any IP address, domain, URL, or file hash appears — in the user's message, a log line, a SIEM alert, or code under review. Enrich "},{"name":"stix-feed-summary","description":"CALL when the user asks what's active right now, what's trending this week, how fresh the feed is, or is planning SIEM / blocklist ingestion — this is the quick"},{"name":"kev-vendor-risk","description":"CALL whenever a vendor or product comes up (Microsoft, Cisco, Fortinet, SharePoint, Ivanti, an appliance, an ERP) and the real question is exploitation risk or "},{"name":"kev-exploitation-stickiness","description":"CALL when the user is prioritizing patching or asks whether a product's exploitation risk is chronic vs a one-off — this decides \"chase the repeat offenders or "},{"name":"check-package","description":"Supply-chain GUARDRAIL for AI coding agents and CI pipelines: check whether a dependency (npm or PyPI) is on the DugganUSA malicious-package deny-list BEFORE yo"}],"package":null},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"io.github.pduggusa/dugganusa-threat-intel","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.pduggusa%2Fdugganusa-threat-intel","firstSeenAt":"2026-09-06T22:22:30.075Z","fetchedAt":"2026-09-06T22:22:30.075Z","normalizedAt":"2026-09-06T22:22:30.075Z"}]},"firstSeenAt":"2026-09-06T22:22:30.075Z","updatedAt":"2026-09-08T09:36:19.442Z"}