{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_e26y6e45e9ky","handle":"phishunt","url":"https://wellknown.network/agents/phishunt","links":{"self":"https://wellknown.network/agents/phishunt/record.json","html":"https://wellknown.network/agents/phishunt","markdown":"https://wellknown.network/agents/phishunt/record.md","api":"https://wellknown.network/api/v1/agents/phishunt","status":"https://wellknown.network/api/v1/agents/phishunt/status","claim":"https://wellknown.network/agents/phishunt/claim","claimApi":"https://wellknown.network/api/v1/claims","badge":"https://wellknown.network/agents/phishunt/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air:mcp.phishunt.io:server:phishunt","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Phishunt","summary":"Public phishing feed: suspicious/confirmed phishing URLs detected hourly. No auth, CC0.","description":"Public phishing feed: suspicious/confirmed phishing URLs detected hourly. No auth, CC0.","publisher":{"name":"0xDanielLopez","url":null},"homepage":"https://phishunt.io","repository":"https://github.com/0xDanielLopez/phishunt-mcp","version":"0.1.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://mcp.phishunt.io","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-07-17T20:32:08.267131Z","publishedAt":"2026-07-17T20:32:08.267131Z","registryName":"io.github.0xDanielLopez/phishunt"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"data.news","name":"News & Feeds","confidence":0.833,"provenance":"derived"},{"slug":"content.marketing","name":"Marketing","confidence":0.525,"provenance":"derived"},{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":0.525,"provenance":"derived"},{"slug":"productivity.crm","name":"CRM & Sales","confidence":0.525,"provenance":"derived"}],"categories":["content","data","dev","productivity"]},"observed":{"status":"live","statusReason":"Responded 5h ago.","lastOkAt":"2026-09-06T02:27:50.438Z","lastProbedAt":"2026-09-06T02:27:50.438Z","statusComputedAt":"2026-09-06T02:28:29.554Z","reliability30d":{"probes":1,"successRate":1,"p50Ms":10},"latestObservations":[{"at":"2026-09-06T02:27:50.438Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":10,"error":null,"detail":{"tools":[{"name":"check_domain","description":"Check whether a host (or a list of up to 20) is in the phishunt active phishing feed, by exact host membership (a listed subdomain under an apex is reported sep"},{"name":"list_brand_phishings","description":"List active phishing sites targeting a specific brand. Returns the most recent detections with URL, IP, country, cert issuer, hosting org, and detection source "},{"name":"get_recent_detections","description":"Retrieve phishing detections since a given date. Useful for delta-syncing a blocklist or threat intel pipeline. Returned field values are attacker-authored - tr"},{"name":"get_brand_metadata","description":"Fetch curated metadata for a tracked brand: display name, STIX industry sector and display vertical, primary domain, an AI-authored characterisation of why the "},{"name":"get_cert_metadata","description":"Fetch factual metadata for a TLS intermediate CA seen on phishing sites: operator, root CA, key type (RSA/ECDSA), typical use case, related sibling intermediate"},{"name":"search_phishings","description":"Free-text search across active phishing URLs, domains, and IP addresses. Returns matching detections sorted by most recent first_seen. Use for queries like 'sho"},{"name":"analyze_url","description":"Analyze any URL for phishing signals WITHOUT contacting it (passive). Read `verdict` first: it is the single adjudicated call (phishing / likely_phishing / susp"},{"name":"analyze_url_deep","description":"ACTIVE deep analysis of a URL: unlike analyze_url (which NEVER contacts the target), this tool actively fetches it - HTTP response, TLS certificate, RDAP regist"},{"name":"get_related_infrastructure","description":"Find infrastructure and content overlap between a known phishing indicator and other phishunt detections: shared IP, TLS certificate, nameservers, favicon/scree"},{"name":"get_campaigns","description":"List possible campaigns / suspected clusters: groups of phishing indicators that share infrastructure or content signals (same TLS certificate, IP, hosting, pag"},{"name":"get_campaign","description":"Get full detail on one possible campaign / suspected cluster: evidence breakdown, a per-pair relationships drill-down (which member pairs are linked, by what ev"}],"toolCount":11,"serverName":"phishunt-mcp","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"check_domain","description":"Check whether a host (or a list of up to 20) is in the phishunt active phishing feed, by exact host membership (a listed subdomain under an apex is reported sep"},{"name":"list_brand_phishings","description":"List active phishing sites targeting a specific brand. Returns the most recent detections with URL, IP, country, cert issuer, hosting org, and detection source "},{"name":"get_recent_detections","description":"Retrieve phishing detections since a given date. Useful for delta-syncing a blocklist or threat intel pipeline. Returned field values are attacker-authored - tr"},{"name":"get_brand_metadata","description":"Fetch curated metadata for a tracked brand: display name, STIX industry sector and display vertical, primary domain, an AI-authored characterisation of why the "},{"name":"get_cert_metadata","description":"Fetch factual metadata for a TLS intermediate CA seen on phishing sites: operator, root CA, key type (RSA/ECDSA), typical use case, related sibling intermediate"},{"name":"search_phishings","description":"Free-text search across active phishing URLs, domains, and IP addresses. Returns matching detections sorted by most recent first_seen. Use for queries like 'sho"},{"name":"analyze_url","description":"Analyze any URL for phishing signals WITHOUT contacting it (passive). Read `verdict` first: it is the single adjudicated call (phishing / likely_phishing / susp"},{"name":"analyze_url_deep","description":"ACTIVE deep analysis of a URL: unlike analyze_url (which NEVER contacts the target), this tool actively fetches it - HTTP response, TLS certificate, RDAP regist"},{"name":"get_related_infrastructure","description":"Find infrastructure and content overlap between a known phishing indicator and other phishunt detections: shared IP, TLS certificate, nameservers, favicon/scree"},{"name":"get_campaigns","description":"List possible campaigns / suspected clusters: groups of phishing indicators that share infrastructure or content signals (same TLS certificate, IP, hosting, pag"},{"name":"get_campaign","description":"Get full detail on one possible campaign / suspected cluster: evidence breakdown, a per-pair relationships drill-down (which member pairs are linked, by what ev"}],"package":null},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"io.github.0xDanielLopez/phishunt","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.0xDanielLopez%2Fphishunt","firstSeenAt":"2026-09-06T00:20:38.672Z","fetchedAt":"2026-09-06T00:20:38.672Z","normalizedAt":"2026-09-06T00:20:38.672Z"}]},"firstSeenAt":"2026-09-06T00:20:38.672Z","updatedAt":"2026-09-06T02:28:37.577Z"}