Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Added "check_package" (15 tools before, 16 now)
PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, and no AI model is involved. SIBLING DIFFERENTIATION: Use before installing or recommending a software package (npm or PyPI) only. Do NOT use for domains (use check_domain_age / check_hostname_reputation), CVE ids (use get_cve_details) or products by vendor name (use get_cve_by_product). BEHAVIOR: Returns { ecosystem, name, version_checked, exists, version_exists, first_published, age_days, latest_version, latest_published, reported_mal…
Added "check_ip_abuse" (14 tools before, 15 now)
PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse confidence score and report counts with attribution to AbuseIPDB. BRING YOUR OWN KEY: send the key in the X-AbuseIPDB-Key HTTP request header on /api/mcp or /api/a2a - never as a tool argument. PG1 has no AbuseIPDB key of its own; without the header the call returns an MCP tool error (isError: true, code abuseipdb_key_required) and AbuseIPDB is not contacted. No PG1 payment required - lookups count against your own AbuseIPDB quota. SIB…
Changed the definition of "get_ioc_batch", "get_ioc_context" and "get_threat_indicators"
⟨26 unchanged words⟩ returns the same aggregated provenance as get_ioc_context fromThreatFox, URLhaus, andOTX. SIBLING DIFFERENTIATION: Use for checking several indicators ⟨110 unchanged words⟩
⟨28 unchanged words⟩ or connecting to something. Returns aggregated provenance fromThreatFox, URLhaus, andOTX — reporting sources, observation count, aggregated ⟨151 unchanged words⟩
Changed the definition of "check_wallet_age"
⟨71 unchanged words⟩ :"object"},"type":"array"},"delegate_address":{"description":"The lowercased delegate contract address when delegated is true, otherwise null.","type":["string","null"]},"delegated":{"description":"true when the address currently has an EIP-7702 delegation on this chain (its code is exactly 0xef0100 followed by a 20-byte delegate address), false when it does not, null when the code check did not complete. Checked live on every call, never cached. is_contract is unchanged and is still true for a delegated address.","type":["boolean","null"]},"first_direction":{"enum":["in","out" ⟨154 unchanged words⟩
Added "check_wallet_age"; changed the definition of "check_domain_age", "check_hostname_reputation" and "check_wallet_sanctions" (13 tools before, 14 now)
⟨15 unchanged words⟩ backward compatibility.","type":"boolean"},"checks":{"description":"Which underlying sources were checked for this result and whether each one completed.","items":{"properties":{"checked_at":{"type":"string"},"data_as_of":{"type":["string","null"]},"result":{"enum":["ok","timeout","error","skipped"],"type":"string"},"source":{"description":"Generic label for the data source checked, never a vendor name.","type":"string"}},"required":["source","result","checked_at","data_as_of"],"type":"object"},"type":"array"},"domain":{"type":"string"},"expiration_date" ⟨41 unchanged words⟩ "type":["string","null"]},"reasons":{"description":"Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.","items":{"properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"type":"object"},"type":"array"},"registrar":{"type":["string","null"]},"registration_date":{"type":["string","null"]},"request_id":{"description":"UUID for this request, also sent as the X-Request-Id response header.","type":"string"},"source":{"type":["string","null"]},"status":{"description":"\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.","enum":["flagged","no_flags","unknown"],"type":"string"},"test_fixture":{"description":"true only when the input was a documented integration test fixture and this response is canned; absent on real results.","type":"boolean"
Changed the definition of "get_cve_batch", "get_cve_by_product", "get_cve_details" and 4 more
⟨29 unchanged words⟩ get_cve_details, batched. Payment required: $0.01 via x402, sent in params._meta['x402/payment'] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY ⟨63 unchanged words⟩
⟨28 unchanged words⟩ NVD keyword search. Payment required: $0.01 via x402,
Added "check_hostname_reputation" (12 tools before, 13 now)
PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, synced daily by the sovereign-threat-pipeline. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for phishing/lookalike-domain screening of a hostname only. Do NOT use for domain registration age (use check_domain_age), general threat-feed indicator lookups (use get_ioc_context), or wallet sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { hostname, verdict, sources, lookalike_of, list_synced_…
Added "check_domain_age" and "check_wallet_sanctions" (10 tools before, 12 now)
PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap registry for the correct per-TLD RDAP server. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for domain registration/age checks only. Do NOT use for reputation/threat-feed lookups (use get_ioc_context) or sanctions screening (use check_wallet_sanctions). BEHAVIOR: Returns { found: true, available: true, registration_date, age_days, expiration_date, registrar, newly_registered, source } when available, or { f…
PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet/address sanctions screening only. Do NOT use for IP/domain/hash/URL threat lookups (use get_ioc_context) or CVE data (use get_cve_details). BEHAVIOR: Returns { listed: true|false, matches, source, list_last_synced }. A listed:false result means the address is not on the OFAC SDN list as of the reported sync time — it is informati…
Changed the definition of "get_cve_batch", "get_cve_by_product", "get_cve_details" and 4 more
⟨30 unchanged words⟩ , batched. Payment required: $0.01 via x402 (X-PAYMENT or payment-signaturePAYMENT-SIGNATURE header) or a valid Gumroad license key ⟨64 unchanged words⟩
⟨29 unchanged words⟩ keyword search. Payment required: $0.01 via x402 (X-PAYMENT or payment-signaturePAYMENT-SIGNATURE header) or a valid Gumroad license key ⟨57 unchanged words⟩
Changed the definition of "get_threat_indicators"
⟨81 unchanged words⟩ Allowed enum-style values: 'IPv4', 'domain', 'URL', 'FileHash-MD5', 'FileHash-SHA1', or'hash'.'FileHash-SHA256'.","type":["string","null"]} ⟨2 unchanged words⟩
Changed the definition of "get_cve_batch", "get_cve_by_product", "get_cve_details" and 4 more
⟨30 unchanged words⟩ batched. Payment required: $0.01 via x402 (X-PAYMENT or payment-signature header) or a valid Gumroad license key ( ⟨64 unchanged words⟩
⟨30 unchanged words⟩ search. Payment required: $0.01 via x402 (X-PAYMENT or payment-signature header) or a valid Gumroad license key ( ⟨57 unchanged words⟩
Added "get_cve_by_product", "get_usage_status", "submit_indicator" and 1 more; changed the definition of "get_cve_batch", "get_cve_details", "get_ioc_context" and 1 more (6 tools before, 10 now)
⟨71 unchanged words⟩ a single CVE (use get_cve_details, lower overhead) or for discovering CVEs by vendor/product (use get_cve_by_product). BEHAVIOR: Accepts up to 20 ids per ⟨14 unchanged words⟩
Only numbers and dates differ: this server embeds live figures in the definition, so the text moves without the contract changing.
⟨75 unchanged words⟩ search or threat-actor dossier profiling. BEHAVIOR: Returns401402 on payment failure, 404 if CVE is not found.
Added "get_cve_batch", "get_ioc_batch" and "get_threat_actor_profile"; changed the definition of "get_cve_details", "get_ioc_context" and "get_threat_indicators" (3 tools before, 6 now)
⟨18 unchanged words⟩ and the CISA Known Exploited Vulnerabilities catalog (whether this CVE is being actively exploitedactiveinwildtheexploitationwildstatus). Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for specific CVE lookups. Do NOT use for IP/domain/hash enrichment (use get_ioc_context) or bulk feed ingestion (use get_threat_indicators). USAGE EXCLUSIONS: Does not support wildcard search or threat-actor dossier profiling. BEHAVIOR: Returns 401 on payment failure, 404 if CVE is not found.
Certificate recorded, valid to 2026-11-27
Authorization not required
Added "get_cve_details" and "get_ioc_context"; changed the definition of "get_threat_indicators" (1 tools before, 3 now)
⟨8 unchanged words⟩ 500, max 1000).","type":"stringinteger"},"min_score":{"description":"Minimum confidence score (0-100).","type":"stringinteger"},"since":{"description":"ISO timestamp; ⟨23 unchanged words⟩
PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile), and the CISA Known Exploited Vulnerabilities catalog (whether this CVE is being actively exploited in the wild). Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header).
Unknown → Live
First tool surface recorded: 1 tool (server version 1.1.0)
https://pg1-ai-agent.vercel.app/api/mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 19 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨14 unchanged words⟩ domains, URLs, file hashes) sourced fromThreatFox, URLhaus,OTX and NVD. Payment required: $0.01 via x402 ⟨104 unchanged words⟩
⟨4 unchanged words⟩ ,"checked_at":{"type":"string"},"checks":{"description":"Which underlying sources were checked for this result and whether each one completed.","items":{"properties":{"checked_at":{"type":"string"},"data_as_of":{"type":["string","null"]},"result":{"enum":["ok","timeout","error","skipped"],"type":"string"},"source":{"description":"Generic label for the data source checked, never a vendor name.","type":"string"}},"required":["source","result","checked_at","data_as_of"],"type":"object"},"type":"array"},"hostname":{"description":"The hostname after normalization ⟨29 unchanged words⟩ "type":["string","null"]},"reasons":{"description":"Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.","items":{"properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"type":"object"},"type":"array"},"request_id":{"description":"UUID for this request, also sent as the X-Request-Id response header.","type":"string"},"sources":{"items":{"properties":{"match_type ⟨15 unchanged words⟩ ,"type":"object"},"type":"array"},"status":{"description":"\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.","enum":["flagged","no_flags","unknown"],"type":"string"},"test_fixture":{"description":"true only when the input was a documented integration test fixture and this response is canned; absent on real results.","type":"boolean"},"verdict":{"description":"Never \ ⟨22 unchanged words⟩
⟨19 unchanged words⟩ against sanctioned_wallets.","type":"string"},"checks":{"description":"Which underlying sources were checked for this result and whether each one completed.","items":{"properties":{"checked_at":{"type":"string"},"data_as_of":{"type":["string","null"]},"result":{"enum":["ok","timeout","error","skipped"],"type":"string"},"source":{"description":"Generic label for the data source checked, never a vendor name.","type":"string"}},"required":["source","result","checked_at","data_as_of"],"type":"object"},"type":"array"},"disclaimer":{"type":"string"},"list_last_synced" ⟨31 unchanged words⟩ ,"message":{"type":"string"},"reasons":{"description":"Machine-readable reason codes for anything flagged in this result. Empty when nothing was flagged.","items":{"properties":{"code":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"type":"object"},"type":"array"},"request_id":{"description":"UUID for this request, also sent as the X-Request-Id response header.","type":"string"},"source":{"type":"string"},"status":{"description":"\"unknown\" whenever a source needed for this answer timed out, errored, or was skipped - never \"no_flags\" in that case.","enum":["flagged","no_flags","unknown"],"type":"string"},"test_fixture":{"description":"true only when the input was a documented integration test fixture and this response is canned; absent on real results.","type":"boolean"}},"required":["address","address_normalized" ⟨6 unchanged words⟩
PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or out), plus whether the address is a contract. No payment required — this tool is always free. SIBLING DIFFERENTIATION: Use for wallet age/history only. Do NOT use for sanctions screening (use check_wallet_sanctions), domain age (use check_domain_age), or hostname/phishing reputation (use check_hostname_reputation). BEHAVIOR: Returns { address, chain, found, first_seen, age_days, first_seen_block, first_direction, is_contract, note, sourc…
⟨27 unchanged words⟩ exploitation status). Payment required: $0.01 via x402, sent in params._meta["x402/payment"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY ⟨30 unchanged words⟩ wildcard search or threat-actor dossier profiling. BEHAVIOR:ReturnsIf402paymentonispaymentmissingfailureor fails, returns a normal tool result with isError: true, the x402 v2 PaymentRequired object in structuredContent and the same JSON in content[0].text; on success the settlement receipt is in result._meta["x402/payment-response"]. Returns 404 if CVE is not found.
⟨29 unchanged words⟩ aggregated provenance as get_ioc_context from ThreatFox, URLhaus,AbuseIPDB,and OTX. SIBLING DIFFERENTIATION: Use for checking several ⟨84 unchanged words⟩ is found, the normal payment gate (x402 via params._meta['x402/payment'], with the PAYMENT-SIGNATURE header also accepted, or a Gumroad X-API-KEY license) applies to the full batch result.
⟨31 unchanged words⟩ something. Returns aggregated provenance from ThreatFox, URLhaus,AbuseIPDB,and OTX — reporting sources, observation count, ⟨100 unchanged words⟩ payment or free-tier quota is consumed. Payment (x402 viax402params._meta['x402/payment'], with the PAYMENT-SIGNATURE header also accepted, or a Gumroad X-API-KEY license) is only required when a real record is found. If payment is required but missing or fails, the result has isError: true with the x402 v2 PaymentRequired object in structuredContent.
⟨27 unchanged words⟩ MITRE ATT&CK Enterprise. Payment required: $0.01 via x402, sent in params._meta['x402/payment'] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY ⟨54 unchanged words⟩
⟨16 unchanged words⟩ file hashes) sourced from ThreatFox, URLhaus,AbuseIPDB,OTX and NVD. Payment required: $0.01 via x402, sent in params._meta["x402/payment"] (the PAYMENT-SIGNATURE header is also accepted), or a valid Gumroad license key (X-API-KEY ⟨41 unchanged words⟩ via the limit parameter (max 1000).ReturnsIf402payment is missing or fails, returns a normal tool result with isError: true, the x402 v2 PaymentRequired object in structuredContent and the same JSON in content[0].text; onpaymentsuccessfailure.the settlement receipt is in result._meta["x402/payment-response"].
⟨28 unchanged words⟩ status). Payment required: $0.01 via x402 (X-PAYMENT or payment-signaturePAYMENT-SIGNATURE header) or a valid Gumroad license key ⟨49 unchanged words⟩
⟨129 unchanged words⟩ is found, the normal payment gate (x402X-PAYMENT/payment-signaturePAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) applies ⟨5 unchanged words⟩
⟨148 unchanged words⟩ free-tier quota is consumed. Payment (via x402X-PAYMENT/payment-signaturePAYMENT-SIGNATURE header or a Gumroad X-API-KEY license) is ⟨8 unchanged words⟩
⟨28 unchanged words⟩ ATT&CK Enterprise. Payment required: $0.01 via x402 (X-PAYMENT or payment-signaturePAYMENT-SIGNATURE header) or a valid Gumroad license key ⟨55 unchanged words⟩
⟨24 unchanged words⟩ and NVD. Payment required: $0.01 via x402 (X-PAYMENT or payment-signaturePAYMENT-SIGNATURE header) or a valid Gumroad license key ⟨54 unchanged words⟩
⟨29 unchanged words⟩ . Payment required: $0.01 via x402 (X-PAYMENT or payment-signature header) or a valid Gumroad license key ( ⟨49 unchanged words⟩
⟨9 unchanged words⟩ domains, URLs, hashes) in a single call,each returning the same aggregated provenance as get_ioc_context—reporting sources, observation count,aconfidencebatchedscore,pre-actionmalwaresafetyfamilies,checkandfortags.AIPaymentagents.required:Each$0.01returnsviathex402same(X-PAYMENTaggregatedheader)provenanceorasaget_ioc_contextvalidfromGumroadThreatFox,licenseURLhaus,keyAbuseIPDB,(X-API-KEYandheader).OTX. SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. allIPs extractedURLsfromanaagentlogisfileaboutortoalertvisit). Do NOT use for a single indicator ⟨11 unchanged words⟩ BEHAVIOR: Accepts up to 20 indicators percall;call.unobservedA found:false result for any indicator means nothing bad is recorded in PG1's sources — NOT that it's safe. If NONE of the submitted indicators arereportedfound,per-entrytheratherwholethanbatchfailingis FREE — no payment or free-tier quota consumed. If at least one indicator is found, thewholenormalbatch.payment gate (x402 X-PAYMENT/payment-signature header or a Gumroad X-API-KEY license) applies to the full batch result.
⟨11 unchanged words⟩ (IP, domain, URL, or hash)across—allthetelemetryrecommendedsourcespre-actionandsafetyreturnscheck for AI agents before visiting, downloading, or connecting to something. Returns aggregated provenance from ThreatFox, URLhaus, AbuseIPDB, and OTX — reporting sources, observation count, aggregated confidence score, known malware families, tags, and first/last seen timestamps.Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header).SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of ⟨18 unchanged words⟩ or software vulnerability analysis (use get_cve_details).USAGE EXCLUSIONSBEHAVIOR:DoesReturnsnotaperformnormalactiveresultport-scanningshaped { found: true, indicator_type, provenance } orlive{networkfound:probing.falseBEHAVIOR} — never an error for 'not found'. A found:falseReturnsresult402meansonnothingpaymentbadfailure,is404recordedifin PG1's sources; it does NOT mean the indicator isunobserved.safe, only that it isn't in this dataset. Lookups that return found:false are FREE — no payment or free-tier quota is consumed. Payment (via x402 X-PAYMENT/payment-signature header or a Gumroad X-API-KEY license) is only required when a real record is found.
⟨29 unchanged words⟩ Enterprise. Payment required: $0.01 via x402 (X-PAYMENT or payment-signature header) or a valid Gumroad license key ( ⟨55 unchanged words⟩
⟨25 unchanged words⟩ NVD. Payment required: $0.01 via x402 (X-PAYMENT or payment-signature header) or a valid Gumroad license key ( ⟨54 unchanged words⟩
Only numbers and dates differ: this server embeds live figures in the definition, so the text moves without the contract changing.
⟨95 unchanged words⟩ port-scanning or live network probing. BEHAVIOR: Returns401402 on payment failure, 404 if the indicator is unobserved.
Only numbers and dates differ: this server embeds live figures in the definition, so the text moves without the contract changing.
⟨82 unchanged words⟩ the limit parameter (max 1000). Returns401402 on payment failure.
PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status, sorted by exploitation risk. Sourced from NVD keyword search. Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for discovering CVEs by vendor/product when you do not already have an exact CVE id. Do NOT use for a known CVE id (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Uses NVD keyword search, not strict CPE matching — results may include n…
PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is always free.
PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402. Submissions are staged for review, not immediately added to the live feed.
PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook URL as they're ingested. Requires a valid Gumroad license key (X-API-KEY header) — this tool is NOT available via per-query x402, since it establishes a recurring subscription rather than a single paid call.
{"properties":{"cve_id":{"description":"Mandatory official CVE identifier,string strictly formatted as 'CVE-YYYY-NNNN' (e.g.,'CVE-2021-44228'.'CVE-2021-44228').","type":"string"}},"required": ⟨3 unchanged words⟩
⟨17 unchanged words⟩ all telemetry sources and returns aggregated provenance —whichreporting sourcesreported it,how manyobservationtimescount,anaggregated confidence score, known malware families, tags, ⟨12 unchanged words⟩ a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for point-lookup enrichment of a single indicator. Do NOT use for bulk intelligence downloads (use get_threat_indicators), multiple indicators at once (use get_ioc_batch), or software vulnerability analysis (use get_cve_details). USAGE EXCLUSIONS: Does not perform active port-scanning or live network probing. BEHAVIOR: Returns 401 on payment failure, 404 if the indicator is unobserved.
{"properties":{"value":{"description":"TheMandatory exact indicator string value to look up,e.g.such as anIPIPv4 address (198.51.100.1), fully qualified domain, complete URL, orfileSHA-256hash.hash string.","type":"string"}},"required": ⟨3 unchanged words⟩
⟨34 unchanged words⟩ a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use ONLY for bulk feed synchronizations. Do NOT use for single-item lookups (use get_ioc_context) or CVE analysis (use get_cve_details). USAGE EXCLUSIONS: Does not provide historical query archival beyond the active ingestion window. BEHAVIOR: Pagination is handled via the limit parameter (max 1000). Returns 401 on payment failure.
{"properties":{"limit":{"default":500,"description":"MaxPagination boundary constraint defining the maximum number of indicators to return in a single payload (defaultinteger500,betweenmax1 and 1000, defaulting to 500).","type":["integer","null"]},"min_score":{"description":"Minimum confidenceConfidence score(0-100).threshold integer ranging inclusively from 0 to 100 to filter low-confidence noise.","type":["integer","null"]},"since":{"description":"ISOtimestamp;timestamponlyconstraintreturn(e.g., 2026-09-20T00:00:00Z); strictly filters and returns only indicators last seen after thistime.exact timestamp.","type":["string","null"]},"type":{"description":"FilterIndicatorbycategoryindicator_type,filter.e.g.Allowed enum-style values: 'IPv4', 'domain','URL'.'URL', or 'hash'.","type":["string","null"]}},"type":"object"}
PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA KEV status — same enrichment as get_cve_details, batched. Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for looking up several known CVE ids at once (e.g. from an SBOM or scan report). Do NOT use for a single CVE (use get_cve_details, lower overhead). BEHAVIOR: Accepts up to 20 ids per call; malformed or not-found ids are reported per-entry rather than…
PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call, each returning the same aggregated provenance as get_ioc_context — reporting sources, observation count, confidence score, malware families, and tags. Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for checking several indicators at once (e.g. all IPs extracted from a log file or alert). Do NOT use for a single indicator (use get_ioc_context, lower overhead) or bulk feed synchronization (use get_thre…
PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associated malware/tooling. Sourced from MITRE ATT&CK Enterprise. Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header). SIBLING DIFFERENTIATION: Use for actor/group-level profiling. Do NOT use for single-indicator lookups (use get_ioc_context) or vulnerability data (use get_cve_details / get_cve_batch). USAGE EXCLUSIONS: Coverage is limited to groups tracked in MITRE ATT&CK — not all threat ac…
PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) across all telemetry sources and returns aggregated provenance — which sources reported it, how many times, an aggregated confidence score, known malware families, tags, and first/last seen timestamps. Payment required: $0.01 via x402 (X-PAYMENT header) or a valid Gumroad license key (X-API-KEY header).