ContrastAPI MCP Server
com.contrastcyber/api
55 security tools for AI agents: CVE/KEV lookup, vulnerability assessment, threat intelligence, and OSINT—free, no API key.
What is the ContrastAPI MCP server?
ContrastAPI is an MCP server providing 55 security intelligence tools for AI agents, grounded in authoritative sources like NVD, CISA KEV, FIRST EPSS, and MITRE frameworks. It enables vulnerability lookup, threat assessment, domain/IP investigation, and code-security checks without requiring signup or API keys.
ContrastAPI gives AI agents access to comprehensive security intelligence across CVE/KEV/CWE databases, MITRE ATLAS and D3FEND frameworks, Sigma rules, email security posture (SPF/DMARC), domain and IP investigation, IOC enrichment, and web intelligence. Use it to ground security decisions in authoritative data, assess exploit probability via EPSS scores, and investigate attack surface with live web intelligence.
How to install ContrastAPI
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
CVE lookup— Query NVD for vulnerability details, EPSS exploit probability, and composite risk scoringKEV detail— Check CISA Known Exploited Vulnerabilities catalogCWE lookup— Retrieve Common Weakness Enumeration detailsEPSS scoring— Exploit Prediction Scoring System probability assessmentDomain investigation— Analyze domain security posture and configurationIP investigation— Query IP reputation and threat intelligenceIOC enrichment— Investigate indicators of compromiseCode security checks— Assess code for security vulnerabilitiesSigma rules— Query and apply Sigma detection rulesEmail SPF/DMARC— Verify email authentication and security postureMITRE ATLAS— Browse MITRE ATLAS adversary tactics and techniquesMITRE D3FEND— Access MITRE D3FEND defensive countermeasuresWeb intelligence tools— robots.txt, redirect chains, email verification, brand assets, SEO audit, geo audit
Use cases
- Look up CVE details with EPSS exploit probability and risk scores to prioritize patching
- Check if a vulnerability is in CISA's Known Exploited Vulnerabilities catalog for immediate threat assessment
- Investigate domain and IP reputation to assess attack surface and threat landscape
- Verify email authentication (SPF/DMARC) to evaluate email security posture
- Enrich indicators of compromise (IOCs) with threat intelligence from authoritative sources
ContrastAPI MCP server FAQ
ContrastAPI is a free MCP server with 55 security tools that give AI agents access to vulnerability databases (CVE/KEV/CWE), MITRE frameworks, Sigma rules, and threat intelligence—all grounded in authoritative sources like NVD and CISA.
Yes, ContrastAPI is completely free. No signup, no API key required. All 55 tools are available immediately.
Download the `.mcpb` file from the latest GitHub release and double-click it, or go to Claude Desktop Settings → Extensions → Install Extension. Alternatively, use the JSON config with `mcp-remote` for any MCP client.
None. ContrastAPI requires no API key, signup, or authentication. It works out of the box.
Yes. You can look up CVE/KEV/CWE details, retrieve EPSS exploit-probability scores, and calculate composite risk scores to prioritize vulnerabilities.
ContrastAPI pulls from authoritative sources including NVD, CISA KEV, FIRST EPSS, MITRE ATLAS, MITRE D3FEND, and live web intelligence APIs.
README (reference)
Source of truth, from the repository.
ContrastAPI — 55 Security Tools + 7 MCP Resources for AI Agents
<p align="center"> <img src="app/static/banner.png" alt="ContrastAPI Banner" width="100%"> </p>Security intelligence, built for AI agents. Give your agent grounded answers about vulnerabilities, threats, and attack surface — backed by authoritative sources (NVD, CISA KEV, FIRST EPSS, MITRE ATLAS & D3FEND), never guesswork. CVE/KEV/CWE lookup with EPSS exploit-probability and composite risk scoring, domain & IP investigation, IOC enrichment, code-security checks, and live web intelligence. 55 tools, 7 Resources, and 3 Prompts — free, no API key, no signup.
中文 · Live: api.contrastcyber.com
Documentation
- API Documentation — REST reference: 60+ endpoints, authentication, rate limits, token costs, and response envelope.
- MCP Documentation — MCP tool-selection guide, 7 Resources, 3 Prompts, and copy-paste agent prompts.
Setup (MCP)
Any MCP client
{
"mcpServers": {
"contrastapi": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://api.contrastcyber.com/mcp/"]
}
}
}
Restart your agent. Other clients (Python SDK, Node SDK, cURL, VS Code): mcp-setup · quickstart
Claude Desktop — one-click extension
Grab the .mcpb file from the latest release and double-click it (or Claude Desktop → Settings → Extensions → Install Extension…). No signup, no API key — all 55 tools ready immediately.
SDKs
pip install contrastapi # Python 3.10+ — sync + async, typed responses, shortcut helpers
npm install contrastapi # Node 14+ — concrete TypeScript types, 14 namespaces
Both SDKs cover every HTTP endpoint and MCP tool — CVE/KEV/CWE, ATLAS, D3FEND, Sigma rules, email security posture, domain, IP, IOC, code security, and web intelligence — with wire-exact response shapes and a typed exception hierarchy that mirrors the API error envelope. They also expose MCP Resources for browsing the ATLAS, D3FEND, and CWE catalogs (see docs/MCP_Documentation.md) and a conditional triage Prompt (see docs/MCP_Documentation.md#contrast-triage). Web-intelligence tools — robots_txt, redirect_chain, email_verify, brand_assets, seo_audit, geo_audit — ship with an explicit ethical floor: per-target throttling, robots.txt respected, no SMTP probing.
Links
OpenAPI: openapi.json
<details> <summary>Also available on</summary>Smithery · npm · VS Code Marketplace · Awesome OSINT MCP · RapidAPI
</details> <details> <summary>Multi-agent verdict metadata</summary>Responses include a verdict block — deterministic, falsifiable_fields, data_age_seconds, sources_queried / sources_unavailable, completeness — so a verifier agent can independently re-derive specific fields from the upstream authority (NVD, RDAP, CT logs, URLhaus). Probe GET /v1/capabilities for "verdict_metadata": true.
CVE responses also embed next_calls: list[PivotHint] — {tool, input, reason} triples that suggest the next MCP tool to call (e.g. kev_detail when kev.in_kev=true, cwe_lookup when cwe_id is set). Agents chain workflows without manual prompting.
MIT
Related MCP servers
Extract structured data from a web page, read it as markdown, verify values against the source.
Consulta y opera gastos compartidos, deudas, presupuestos e ingresos de tu grupo.
List, schedule, and retrieve evidence for ControlDrill incident-response tabletop exercises.
Check which file formats convert to which, and get links that open the converter.

com.convexvalue/cvserver
Live US options chains with Greeks and IV, a screener, SQL, and FMP fundamentals.
Conveyancing Fees Australia: the site's own MCP server — enquiry (enquiry = a human handoff, not...
View repository →