mcp server
data-breach-detector
Read-only breach intel, full history 2007-today: reports THAT an org was breached, never the data.
Description as published by the maintainer. Source
- version 0.3.1
- active
active — Most recent push to the repository was 2026-08-06.
What this server can do
7 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
assess_threat(text)- Classify a piece of security text you supply — an advisory, alert or forum post — into a threat level, matched categories, financial-target flags, a confidence score and a recommended action. Pure local analysis: it collects nothing, stores nothing and reaches no network; the text never leaves the server. Use it to triage findings surfaced by breach_news or from your own monitoring. Required: text.
breach_history(limit, order, query, offset, sector, year_to, data_type, year_from, min_accounts)- Search the FULL historical breach archive — every incident this server knows about, back to 2007: HaveIBeenPwned's verified breach directory, the 2020-2025 ransomwatch leak-site archive (~16k victims), the RansomLook live tracker and SEC 8-K Item 1.05 filings. Filter by keyword, year range, sector, exposed data type or minimum scale; order by date or size. Returns disclosure metadata only, never breach contents. Use this for questions like 'what were the biggest breaches of 2013' or 'which airlines have ever been hit by ransomware'.
breach_news(limit, offset, sector, source, since_days)- Read recent breach and ransomware DISCLOSURES from public threat-intel feeds (HaveIBeenPwned, the RansomLook live leak-site tracker and SEC 8-K Item 1.05 filings), newest first. Every row is metadata only — entity, date, scale, exposed data TYPES, threat level and source — never the leaked data, and a redaction pass strips anything credential-shaped before it is returned. Use sector to narrow to an industry keyword; for one specific organization use check_exposure; for all-time history use breach_history.
breach_stats(limit, sector, group_by)- Aggregate the full breach archive into analyst-grade statistics: incidents and accounts exposed per year, per source, per exposed data type, per threat level, or per ransomware actor — plus the five largest incidents ever recorded. Use it to answer 'how has breach volume trended since 2015', 'which ransomware groups have the most victims' or 'how often are passwords part of a breach'. Aggregate counts only; no leaked records.
breach_timeline(limit, entity, offset)- Build the incident-by-incident CHRONOLOGY of one organization across every source and all history, with judgment on top: first and latest incident, incidents per year, whether the organization is a repeat victim, worst threat level and total accounts ever exposed. Those summary fields cover EVERY incident on record. The timeline list carries a window of them, oldest first within the window, defaulting to the most recent limit incidents and paging backwards with offset, so an organization with a long history shows its current state first rather than only its ancient one. Repeat victimhood is a forward-looking risk signal: organizations named more than once have demonstrably not closed the gap. Metadata only; never the leaked data. For a yes/no presence check use check_exposure. Required: entity.
check_exposure(limit, query, offset, since_days)- Answer whether a domain, company or brand appears in public breach or ransomware DISCLOSURES across ALL history (2007 → today): yes/no with mention count, worst threat level, total accounts exposed across matches, the exposed data TYPES, and the matching disclosure metadata — never the exposed records themselves. This is a triage signal built from disclosure feeds, not proof of compromise; confirm through authorized channels before acting. For the incident-by-incident chronology of one entity, use breach_timeline; for a recent-news sweep, use breach_news. mentions, the aggregates and the data types always cover every match; matches carries one page of them, sized by limit and walked with offset. Required: query.
feed_sources- List the public disclosure feeds this server aggregates, how many disclosures are cached per source, each source's newest item and an honest staleness flag, plus cache ages. Takes no arguments. Also states the scope plainly: public feeds only — no .onion access, no arbitrary fetching or crawling, no credential or PII output. Check this first if another tool's answer looks thin: a stale live feed is a finding, not background noise.
Last successful function declaration observed on . Source: https://breach.seiche.info/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://breach.seiche.info/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 0 | Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. | cumulative, all time | GitHub | |
| Last commit | 2026-08-06 | Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. | point in time | GitHub | |
| Open issues | 1 | Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. | as of fetch | GitHub | |
| Latest published version | 0.3.1 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-08-02 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| License | MIT | Licence GitHub detected in the repository. Detection can be wrong; the LICENSE file is authoritative. | as of fetch | GitHub | |
| First listed in the MCP Registry | 2026-08-02 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | active | The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. | as of fetch | GitHub | |
| mcp tools declared | 7 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | breach.seiche.info | |
| mcp endpoint status | ok | The server listed 7 functions when asked. | as of probe | breach.seiche.info |
Where to get it
Related, by what their authors tagged them
-
ContrastAPI
— last commit 2026-08-04, shares cybersecurity, security, threat-intelligence
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
-
com.threadlinqs/intelthreadlinqs-mcp
— last commit 2026-08-03, shares cybersecurity, security, threat-intelligence
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
-
io.github.aplaceforallmystuff/mcp-threatintel
— last commit 2026-08-05, shares cybersecurity, security, threat-intelligence
Unified threat intel - OTX, AbuseIPDB, GreyNoise, abuse.ch, Feodo Tracker
-
io.github.BurtTheCoder/shodan
— last commit 2026-03-31, shares cybersecurity, security, threat-intelligence
MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries.
-
io.github.BurtTheCoder/virustotal
— last commit 2026-05-24, shares cybersecurity, security, threat-intelligence
MCP server for querying VirusTotal API with comprehensive security analysis tools.
-
Cybersecurity Threat Intelligence MCP
— last commit 2026-07-16, shares cybersecurity, threat-intelligence
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
-
Scry
— archived, last commit 2026-05-25, shares security, threat-intelligence
Free IPv4 lookups against a distributed attacker-observation corpus.
-
Phishunt
— last commit 2026-08-02, shares threat-intelligence
Public phishing feed: suspicious/confirmed phishing URLs detected hourly. No auth, CC0.
-
TweetFeed
— last commit 2026-08-01, shares threat-intelligence
IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter. No auth, CC0.
-
io.github.AynOps/AynOps
— last commit 2026-08-06, shares threat-intelligence
AynOps is a reconnaissance focused MCP Server which gives reconnaissance capabilities to AI Clients
These share tags the maintainers applied themselves, such as cybersecurity, security, threat-intelligence. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
Also from beepboop2025
-
io.github.beepboop2025/groundcheck
— last commit 2026-08-06
Verify claims, resolve FIGI identity, extract claims, and sign x402 delivery receipts over MCP.
-
LiquiLens — the Failure Radar
— repository gone
Bank and lender failure early warning, with the validated record served beside every claim.
-
io.github.beepboop2025/lucent
— last commit 2026-07-19
Pre-sign transaction-safety checks for signing agents (ERC-7730 descriptors).
-
noisefloor — is this number real?
— last commit 2026-08-02
Is this number real, or is it noise? Peek-safe A/B tests, change detection, honest forecasts.
-
Palimpsest — censorship and model-eval observatory
— last commit 2026-08-06
Live internet-censorship signals and tamper-evident, pre-registered, hash-chained AI model evals.
-
io.github.beepboop2025/pdf-suite-mcp
— last commit 2026-07-30
37 tools to read, create, merge, split, watermark, fill, redact & search PDFs. Local, no API key.
-
io.github.beepboop2025/pdf-toolkit-mcp
— last commit 2026-07-30
37 tools to read, create, merge, split, watermark, fill, redact & search PDFs. Local, no API key.
-
Seiche — funding-stress terminal
— last commit 2026-08-06
Funding stress early warning for US money markets from free public data, with an honest backtest.
-
io.github.beepboop2025/umbra-proof
— last commit 2026-08-06
Verify Umbra bridge accountability proofs (signed receipts, checkpoints, Merkle inclusion).
-
Undertow — market liquidity map
— last commit 2026-08-06
Live exit costs by venue, depth concentration, and a sealed calls record that keeps its misses.
How the author describes it
Topics the maintainer set on GitHub: breach-monitoring, cybersecurity, defensive-security, mcp, mcp-server, model-context-protocol, security, threat-intelligence.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json