{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_f39xa5tdpfv5","handle":"pg1-sovereign-threat-intelligence","url":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence","links":{"self":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence/record.json","html":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence","markdown":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence/record.md","api":"https://wellknown.network/api/v1/agents/pg1-sovereign-threat-intelligence","status":"https://wellknown.network/api/v1/agents/pg1-sovereign-threat-intelligence/status","claim":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence/claim.json","badge":"https://wellknown.network/agents/pg1-sovereign-threat-intelligence/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/pg1-sovereign-threat-intelligence/history","tools":"https://wellknown.network/api/v1/agents/pg1-sovereign-threat-intelligence/tools"},"ard":{"identifier":"urn:air:pg1-ai-agent.vercel.app:server:pg1-sovereign-threat-intelligence","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"PG1 Sovereign Threat Intelligence","summary":"Threat intel for AI agents: IOCs, CVEs (EPSS/KEV), wallet sanctions and age, domain and URL checks.","description":"Threat intel for AI agents: IOCs, CVEs (EPSS/KEV), wallet sanctions and age, domain and URL checks.","publisher":{"name":"Project-Gifted1","url":null},"homepage":null,"repository":"https://github.com/Project-Gifted1/pg1-ai-agent","version":"1.16.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://pg1-ai-agent.vercel.app/api/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-10-07T11:51:20.612249Z","publishedAt":"2026-10-07T11:51:20.612249Z","registryName":"io.github.Project-Gifted1/pg1-threat-intel"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":1,"provenance":"derived"},{"slug":"commerce.payments","name":"Payments","confidence":1,"provenance":"derived"},{"slug":"communication.notifications","name":"Notifications","confidence":1,"provenance":"derived"},{"slug":"code.security-review","name":"Security Review","confidence":0.807,"provenance":"derived"}],"categories":["code","commerce","communication","dev"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 6h ago.","lastOkAt":"2026-10-10T04:32:42.541Z","lastProbedAt":"2026-10-10T04:32:42.541Z","statusComputedAt":"2026-10-10T04:33:38.902Z","reliability30d":{"probes":70,"successRate":1,"p50Ms":113,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":70,"ok":70,"authBoundaryOk":0,"serviceOk":70,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-10T04:32:42.541Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":48,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"toolCount":16,"toolsHash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.17.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T22:28:18.757Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":47,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"toolCount":16,"toolsHash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.17.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T16:31:55.455Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":48,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"toolCount":16,"toolsHash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.17.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T09:26:31.015Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":79,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"toolCount":16,"toolsHash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.17.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T02:26:02.423Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":77,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"toolCount":16,"toolsHash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.17.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T19:23:24.137Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":46,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"toolCount":16,"toolsHash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.17.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T12:26:20.519Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":112,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "}],"toolCount":15,"toolsHash":"7087d47cab256c5f781211e567f223b6038a03b04385ea9926d3331f85caf479","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.16.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T06:22:58.017Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":74,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "}],"toolCount":15,"toolsHash":"7087d47cab256c5f781211e567f223b6038a03b04385ea9926d3331f85caf479","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.16.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-07T23:24:04.330Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":177,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "}],"toolCount":15,"toolsHash":"7087d47cab256c5f781211e567f223b6038a03b04385ea9926d3331f85caf479","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.16.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-07T16:29:09.249Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":87,"error":null,"detail":{"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "}],"toolCount":15,"toolsHash":"7087d47cab256c5f781211e567f223b6038a03b04385ea9926d3331f85caf479","serverName":"pg1-threat-intel","capabilities":["tools"],"serverVersion":"1.16.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"get_threat_indicators","description":"PG1 Sovereign Threat Intelligence: returns a STIX 2.1 bundle of verified threat indicators (IPs, domains, URLs, file hashes) sourced from OTX and NVD. Payment r"},{"name":"get_cve_details","description":"PG1 Sovereign Threat Intelligence: enriched CVE lookup combining NVD (description, CVSS score/vector), FIRST.org EPSS (exploit-probability score and percentile)"},{"name":"get_ioc_context","description":"PG1 Sovereign Threat Intelligence: looks up a single specific indicator value (IP, domain, URL, or hash) — the recommended pre-action safety check for AI agents"},{"name":"get_cve_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple CVE identifiers in a single call, each enriched with NVD description/CVSS, FIRST.org EPSS score, and CISA K"},{"name":"get_ioc_batch","description":"PG1 Sovereign Threat Intelligence: looks up multiple indicators (IPs, domains, URLs, hashes) in a single call — a batched pre-action safety check for AI agents."},{"name":"get_threat_actor_profile","description":"PG1 Sovereign Threat Intelligence: returns a dossier for a known threat actor / APT group — aliases, description, associated MITRE ATT&CK techniques, and associ"},{"name":"get_cve_by_product","description":"PG1 Sovereign Threat Intelligence: returns CVEs affecting a given vendor/product (optionally a specific version), enriched with CVSS, EPSS, and CISA KEV status,"},{"name":"get_usage_status","description":"PG1 Sovereign Threat Intelligence: returns your remaining free-tier calls for today and current Gumroad license status. No payment required — this tool is alway"},{"name":"subscribe_alerts","description":"PG1 Sovereign Threat Intelligence: registers a standing filter (indicator type, min EPSS, or KEV-only). Matching new indicators are POSTed to the given webhook "},{"name":"submit_indicator","description":"PG1 Sovereign Threat Intelligence: submit an observed indicator for validation and possible inclusion in future query results. Requires a valid Gumroad license "},{"name":"check_wallet_sanctions","description":"PG1 Sovereign Threat Intelligence: checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily fro"},{"name":"check_domain_age","description":"PG1 Sovereign Threat Intelligence: looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor), resolved through the IANA bootstrap re"},{"name":"check_hostname_reputation","description":"PG1 Sovereign Threat Intelligence: checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist and a lookalike/typosquat detector, syn"},{"name":"check_wallet_age","description":"PG1 Sovereign Threat Intelligence: reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or ou"},{"name":"check_ip_abuse","description":"PG1 Sovereign Threat Intelligence: looks up one public IPv4 or IPv6 address in AbuseIPDB using YOUR OWN AbuseIPDB API key (free or paid), and returns its abuse "},{"name":"check_package","description":"PG1 Sovereign Threat Intelligence: a pre-install check for one npm or PyPI package - check before you install. No payment required - this tool is always free, a"}],"package":null,"toolSurface":{"id":"ts_pb6c6k9jrpev","endpointId":"ep_vtg5tcz7sjp2","hash":"2c97356b212523e428aff0fc44f20e4f801c8713b14c51732e53d857dda0a0fd","toolCount":16,"serverName":"pg1-threat-intel","serverVersion":"1.17.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-10-08T19:23:24.139Z","lastSeenAt":"2026-10-10T04:32:42.554Z","observations":6,"toolNames":["get_threat_indicators","get_cve_details","get_ioc_context","get_cve_batch","get_ioc_batch","get_threat_actor_profile","get_cve_by_product","get_usage_status","subscribe_alerts","submit_indicator","check_wallet_sanctions","check_domain_age","check_hostname_reputation","check_wallet_age","check_ip_abuse","check_package"],"distinctSurfaces":15},"endpointFacts":[{"id":"ep_vtg5tcz7sjp2","url":"https://pg1-ai-agent.vercel.app/api/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-09T02:26:02.445Z","auth":{"observedAt":"2026-10-09T02:26:02.475Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-10-09T02:26:02.495Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"*.vercel.app","issuer":{"commonName":"WR1","organization":"Google Trust Services"},"validFrom":"2026-08-29T19:48:09.000Z","validTo":"2026-11-27T19:48:08.000Z","daysToExpiry":48,"sanCount":1,"fingerprint256":"8F:46:C4:A0:A2:89:BF:DE:40:60:D0:69:86:F2:AF:76:1E:E6:2D:66:8D:DE:97:2E:6B:EF:46:87:EE:4F:60:93"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"io.github.Project-Gifted1/pg1-threat-intel","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.Project-Gifted1%2Fpg1-threat-intel","firstSeenAt":"2026-09-21T04:18:22.033Z","fetchedAt":"2026-10-10T00:19:38.979Z","normalizedAt":"2026-10-10T00:19:38.979Z"}]},"firstSeenAt":"2026-09-21T04:18:22.033Z","updatedAt":"2026-10-10T04:34:45.789Z"}