{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_v83a97q5krzn","handle":"scry","url":"https://wellknown.network/agents/scry","links":{"self":"https://wellknown.network/agents/scry/record.json","html":"https://wellknown.network/agents/scry","markdown":"https://wellknown.network/agents/scry/record.md","api":"https://wellknown.network/api/v1/agents/scry","status":"https://wellknown.network/api/v1/agents/scry/status","claim":"https://wellknown.network/agents/scry/claim","claimApi":"https://wellknown.network/api/v1/claims","badge":"https://wellknown.network/agents/scry/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air:mcp.tunnelmind.ai:server:scry","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Scry","summary":"Free IPv4 lookups against a distributed attacker-observation corpus.","description":"Free IPv4 lookups against a distributed attacker-observation corpus.","publisher":{"name":"ai.tunnelmind","url":null},"homepage":"https://api.tunnelmind.ai","repository":"https://github.com/TunnelMind/scry-mcp","version":"0.5.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://mcp.tunnelmind.ai/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-05-25T01:01:59.607954Z","publishedAt":"2026-05-25T01:01:59.607954Z","registryName":"ai.tunnelmind/scry"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[],"categories":[]},"observed":{"status":"unknown","statusReason":"Not checked yet.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[{"at":"2026-09-05T18:27:34.424Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":67,"error":null,"detail":{"tools":[{"name":"scry_stats","description":"Returns aggregate Scry corpus telemetry: total observation count, distinct\nsource IPs, first/last observation timestamps, last-24h activity, and\nper-protocol br"},{"name":"scry_check","description":"Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last\nobserved, observation count, protocols and ports targeted, ASN, country, categ"},{"name":"scry_check_bulk","description":"Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP."},{"name":"scry_top","description":"Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'"},{"name":"scry_timeseries","description":"Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling."},{"name":"scry_asn","description":"Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol "},{"name":"scry_country","description":"Roll-up of corpus activity by ISO country code. Same shape as scry_asn."},{"name":"scry_tools","description":"List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors."},{"name":"scry_tool","description":"Single tool detail by 16-char hex id from scry_tools."},{"name":"scry_campaigns","description":"Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history."},{"name":"scry_campaign","description":"Single campaign detail by id (format: c[0-9a-f]{15})."},{"name":"scry_recent","description":"Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms."}],"toolCount":12,"serverName":"scry","capabilities":["tools","prompts"],"serverVersion":"0.5.0","protocolVersion":"2025-03-26"}}],"tools":[{"name":"scry_stats","description":"Returns aggregate Scry corpus telemetry: total observation count, distinct\nsource IPs, first/last observation timestamps, last-24h activity, and\nper-protocol br"},{"name":"scry_check","description":"Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last\nobserved, observation count, protocols and ports targeted, ASN, country, categ"},{"name":"scry_check_bulk","description":"Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP."},{"name":"scry_top","description":"Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'"},{"name":"scry_timeseries","description":"Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling."},{"name":"scry_asn","description":"Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol "},{"name":"scry_country","description":"Roll-up of corpus activity by ISO country code. Same shape as scry_asn."},{"name":"scry_tools","description":"List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors."},{"name":"scry_tool","description":"Single tool detail by 16-char hex id from scry_tools."},{"name":"scry_campaigns","description":"Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history."},{"name":"scry_campaign","description":"Single campaign detail by id (format: c[0-9a-f]{15})."},{"name":"scry_recent","description":"Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms."}],"package":null},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"ai.tunnelmind/scry","url":"https://registry.modelcontextprotocol.io/v0/servers/ai.tunnelmind%2Fscry","firstSeenAt":"2026-09-05T15:22:04.040Z","fetchedAt":"2026-09-05T15:22:04.040Z","normalizedAt":"2026-09-05T15:22:04.040Z"}]},"firstSeenAt":"2026-09-05T15:22:04.040Z","updatedAt":"2026-09-05T15:22:07.278Z"}