ContrastAPI by contrastcyber.com
MCP server · Email delivery APIs · indexed, not reviewed
Hostedvendor's own
Not reviewed
No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Facts
- MCP registry
com.contrastcyber/api· 1.36.2- Endpoint
https://api.contrastcyber.com/mcp/- Website
- api.contrastcyber.com
- GitHub stars
- 33
- Registry entry
- updated 24 Aug 2026
From the official MCP registry, the package registries and our own checks. JSON · Markdown
Why it's listed
- It's published in the registry under contrastcyber.com, a namespace the registry only gives to whoever proves they control that domain.
Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.
Tools it lists 55 · about 177,970 tokens of context · checked 14 minutes ago
| Tool | What it does | Hint |
|---|---|---|
domain_reportDomain Report | Query DNS, WHOIS, SSL, subdomains, and threat intel for a domain in one call. By default dns.txt is filtered to security-relevant entries (SPF, DMARC, DKIM, MTA-STS, TLS-RPT) and dns.total_txt_records reports the honest… | read-only |
audit_domainAudit Domain | Perform comprehensive domain audit: combines domain_report + live HTTP security headers + technology fingerprinting. By default report.dns.txt is filtered to security-relevant entries (SPF, DMARC, DKIM, MTA-STS,… | read-only |
contrast_scanContrast Scan | Active website security scan: runs the ContrastScan C engine (11 modules — HTTP security headers, SSL/TLS, DNS, redirect chain, information disclosure, cookie flags, DNSSEC, HTTP methods, CORS, HTML hygiene, deep CSP… | read-only |
tech_stack_cve_auditTech Stack CVE Audit | Composite tech-stack + CVE audit (MCP-only, no REST endpoint). Detects technologies on the target domain, queries CVE database for known vulnerabilities per product, enriches top-10 CVE candidates with CISA KEV federal… | read-only |
threat_reportThreat Report | Query comprehensive threat profile for an IP: Shodan host data, AbuseIPDB reputation, ASN/geolocation, and open ports. Use for IP investigation and SOC alert triage; for domain data use domain_report. Note: nested asn… | read-only |
dns_lookupDNS Lookup | Query all DNS record types (A, AAAA, MX, NS, TXT, CNAME, SOA) for a domain. Use for mail routing inspection, nameserver verification, or SPF/DMARC checks; for full overview use domain_report. TXT records are returned… | read-only |
whois_lookupWHOIS Lookup | Retrieve WHOIS registration data: registrar, creation/expiry dates, nameservers, status. Use to verify domain ownership, age, expiration; for full audit use domain_report. Free: 30/hr, Pro: 500/hr. Returns {domain,… | read-only |
ssl_check | (not repeated here: it reads like a rating or a usage claim) | read-only |
subdomain_enumSubdomain Enum | Discover subdomains using passive methods: Certificate Transparency logs + DNS brute-force (no active probing). Use to map organization's attack surface; non-intrusive. Response carries next_calls — capped at 5… | read-only |
tech_fingerprintTech Fingerprint | Detect website technology stack: CMS, frameworks, CDN, analytics tools, web servers, languages (via HTTP headers + HTML analysis). Use for passive reconnaissance; for full audit use audit_domain. Free: 30/hr, Pro:… | read-only |
threat_intelThreat Intel | Check domain against abuse.ch URLhaus for known malware-distribution URLs (single source — for multi-feed correlation use ioc_lookup which adds ThreatFox and, for IPs, Feodo Tracker). Use for fast domain-level threat… | read-only |
wayback_lookupWayback Lookup | Retrieve Wayback Machine snapshots for a domain: first capture, latest, total count, snapshot list. Use to investigate domain history and age; for full audit use domain_report. Free: 30/hr, Pro: 500/hr. status='ok'… | read-only |
scan_headersScan Headers | Perform live HTTP GET and analyze security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy. Use to audit live website headers; use check_headers to validate headers you… | read-only |
email_mxEmail MX | Analyze email security: MX records, SPF policy, DMARC policy, DKIM probe across common+date-based selectors, mail provider, grade. Use to verify email-auth setup and phishing risk; for full audit use domain_report.… | read-only |
email_security_postureEmail Security Posture | Analyze domain email authentication posture: SPF, DMARC, DKIM with numeric score and findings. Dual-use: red-team (spoofing feasibility) + blue-team (posture audit). Score 0-100, grades A+-F. DKIM probing tests common… | read-only |
email_disposableEmail Disposable | Check if email address uses a known disposable/temporary provider (Guerrilla Mail, Temp Mail, Mailinator, etc.). Use for input validation to detect throwaway signups; for domain reputation use threat_intel. Companion… | read-only |
email_verifyEmail Verify | One-call email validation combining syntax + MX records + disposable check + role-address detection (admin@/info@/...) + free-provider classification (gmail/outlook/yahoo/...). Use BEFORE adding an email to a contact… | read-only |
robots_txtRobots.txt | Fetch + parse the target domain's robots.txt — sitemaps, per-User-agent allow/disallow rules, crawl-delay, Host directive. Use BEFORE crawling/scraping a target site (seo_audit, brand_assets, redirect_chain) to honour… | read-only |
redirect_chainRedirect Chain | Walk an HTTP redirect chain hop-by-hop, returning per-hop {url, status_code, location, latency_ms}. Use to deobfuscate URL shorteners (bit.ly / t.co / lnkd.in), audit suspicious links from phishing investigations, or… | read-only |
brand_assetsBrand Assets | Scrape a domain's homepage `<head>` for public brand assets — favicon, og:image, theme-color, og:site_name, JSON-LD `Organization.logo`. Use to enrich CRM records, build company-card UIs, or correlate a lead's site to… | read-only |
seo_auditSEO Audit | One-shot SEO audit of a domain's homepage with a 0-100 composite score + a `missing_signals` list of concrete fixes. Use BEFORE pitching SEO work to a prospect, when triaging a lead's marketing maturity, or as a… | read-only |
geo_auditGeo Audit | Deterministic GEO / AI-visibility readiness audit of a domain's homepage with a 0-100 score + a `missing_signals` fix list. Answers "can AI assistants (ChatGPT, Claude, Perplexity, Google AI) discover, crawl, and… | read-only |
phone_lookupPhone Lookup | Validate and analyze phone number: country, region, carrier, line type (mobile/landline/VoIP), timezone, formatted versions. Use to verify phone legitimacy and detect fraud risks. Requires E.164 format (+1234567890).… | read-only |
ip_lookupIP Lookup | Query comprehensive IP intelligence: reverse DNS, ASN + holder name + country inline (RIPE Stat, Phase 1), open ports, hostnames, vulnerabilities (Shodan InternetDB enriched with severity + cvss_v3 from local cve.db —… | read-only |
asn_lookupASN Lookup | Look up Autonomous System Number (ASN) for a domain or IP: AS number, organization, IPv4/IPv6 prefixes. Use to identify network operator and IP range ownership. Default returns first 50 prefixes per family — set… | read-only |
cve_lookupCVE Lookup | Retrieve detailed CVE data by ID: description, CVSS v3.1 + vector, CVSS v2 (always emitted), EPSS score + percentile, CISA KEV status (expanded: due_date, required_action, ransomware flag, vendor_project, product,… | read-only |
calculate_risk_scoreCalculate Risk Score | Composite CVE risk score (0-100) — fuses CVSS, EPSS, KEV, and PoC into a single agent-ready triage signal. Formula: CVSS*0.20 + EPSS*0.35 + KEV*0.30 + PoC*0.15 (each component rescaled to 0-100 before weighting).… | read-only |
get_cvss_detailsGet CVSS Details | Parse a CVSS v3.x vector string into a per-metric breakdown plus a recomputed base score. Returns the canonicalized vector, version (3.0 or 3.1), base_score, base_severity (NONE/LOW/MEDIUM/HIGH/CRITICAL), and the eight… | read-only |
cve_searchCVE Search | Search CVE database with filters: product/vendor, severity, published date range, EPSS score, CWE, CVSS range, CISA KEV status. Default response is SLIM per-result (cve_id, summary, severity, cvss_v3, cwe_id, epss, kev,… | read-only |
cve_leadingCVE Leading | List CVEs indexed from MITRE/GHSA BEFORE NVD publication (early-warning, freshest data). By default each result is slim (no description, no cvss_breakdown, no affected_products list, no references) — pass include='full'… | read-only |
exploit_lookupExploit Lookup | Search public exploits/PoC for a specific CVE across three sources: (1) GitHub Advisory Database (sources.github.advisories[]), (2) Shodan CVEDB references (sources.shodan_refs.results[] — packetstorm/seclists/vendor… | read-only |
bulk_cve_lookupBulk CVE Lookup | Batch query multiple CVEs (up to 50 per call, same for Free and Pro): retrieve full CVE details for all in 1 request instead of N. By default each CVE's affected_products is truncated to the first 20 entries… | read-only |
kev_detailKEV Detail | Look up CISA KEV (Known Exploited Vulnerabilities) full record for a CVE. Returns federal patch deadline (due_date), CISA-specified required_action remediation, known ransomware association, vendor/product, the… | read-only |
cwe_lookupCWE Lookup | Look up MITRE CWE (Common Weakness Enumeration) catalog record from research view 1000. Default response is SLIM (first 3 mitigations, first 3 examples; extended_description is null) — pass include='full' for the… | read-only |
atlas_technique_lookupATLAS Technique Lookup | Look up a MITRE ATLAS technique — the AI/ML adversarial attack catalog. ATLAS catalogues TTPs targeting machine learning systems: prompt injection, model evasion, training data poisoning, model theft, etc. Roughly 80%… | read-only |
bulk_atlas_technique_lookupBulk ATLAS Technique Lookup | Bulk ATLAS technique lookup — retrieve full records for up to 50 techniques in a single request instead of N separate atlas_technique_lookup calls. Designed as the natural follow-up to atlas_case_study_lookup, whose… | read-only |
atlas_technique_searchATLAS Technique Search | Search the MITRE ATLAS catalog of AI/ML attack techniques by keyword, tactic, or maturity. Default response is SLIM (description truncated to 240 chars per row); pass include='full' for the verbose record. Pass… | read-only |
atlas_case_study_lookupATLAS Case Study Lookup | Look up a MITRE ATLAS case study — a documented real-world AI/ML attack incident. Each case study links a sequence of ATLAS techniques (techniques_used) to the incident. Default response is SLIM (description truncated… | read-only |
atlas_case_study_searchATLAS Case Study Search | Search ATLAS case studies (real-world AI/ML attack incidents) by keyword or referenced technique. Default response is SLIM (description truncated to 240 chars per row); pass include='full' for the verbose summary.… | read-only |
d3fend_defense_lookupD3FEND Defense Lookup | Look up a MITRE D3FEND defense technique. D3FEND is the canonical defensive counterpart to ATT&CK — each defense is classified into one of 7 tactics (Model/Harden/Detect/Isolate/Deceive/Evict/Restore) and may target a… | read-only |
d3fend_defense_searchD3FEND Defense Search | Search the MITRE D3FEND catalog of defensive techniques by keyword, tactic, or targeted artifact. Default response is SLIM (drops `uri` from each row — saves ~60 chars/row, ~30% on popular drills); pass include='full'… | read-only |
d3fend_defense_for_attackD3FEND Defense for Attack | Reverse lookup: given an ATT&CK T-code, return D3FEND defenses that mitigate it. This is the bridge from offensive intelligence (ATT&CK / ATLAS / CVE) to defensive playbook. Pair with cve_lookup or… | read-only |
d3fend_attack_coverageD3FEND Attack Coverage | Batch coverage breakdown: given a list of ATT&CK T-codes, return distinct defense counts per D3FEND tactic + identify which techniques have NO D3FEND mapping (undefended_techniques). Use to assess the defensive posture… | read-only |
sigma_rule_lookupSigma Rule Lookup | Look up a single Sigma detection rule by UUID from the SigmaHQ corpus (~3,200 rules, refreshed daily at 02:00 UTC). Returns the full rule with title, description, status… | read-only |
bulk_sigma_rule_lookupBulk Sigma Rule Lookup | Bulk Sigma rule lookup — retrieve full records for up to 50 rule UUIDs in a single request instead of N separate sigma_rule_lookup calls. Designed for triage workflows where multiple rule ids are known (e.g., from a… | read-only |
ioc_lookupIOC Lookup | Enrich Indicator of Compromise (IP/domain/URL/hash) by auto-detecting type and querying abuse.ch feeds. Per-type source coverage: hash → ThreatFox only (Feodo and URLhaus do not index hashes); IP → ThreatFox + Feodo… | read-only |
hash_lookupHash Lookup | Query MalwareBazaar for file hash (MD5/SHA1/SHA256): malware family, file type, size, tags, first/last seen, download count. Use to check if file hash is known malware; use ioc_lookup for auto-detection of all IOC… | read-only |
password_checkPassword Check | Check if SHA-1 hash appears in Have I Been Pwned (HIBP) breach dataset using k-anonymity (5-char prefix only, full hash never leaves tool). Use for password breach audits; read-only, no data stored. Companion OSINT… | read-only |
phishing_checkPhishing Check | Query URLhaus for a specific URL and its host. is_malicious is True only when there is ACTIVE evidence — exact URL match with url_status='online' (or unknown) OR host has urls_online > 0. URLhaus retains historical… | read-only |
bulk_ioc_lookupBulk IOC Lookup | Batch query multiple IOCs (IP/domain/URL/hash, up to 50 per call, same for Free and Pro) in 1 request: auto-detects type + queries abuse.ch feeds per-indicator. Per-type source coverage matches ioc_lookup: hash →… | read-only |
check_secretsCheck Secrets | Scan source code (or snippet) for hardcoded secrets — cloud provider keys, API tokens, connection strings, private keys, passwords. Supports Python, JavaScript, TypeScript, Java, Go, Ruby, Shell, Bash. Use to detect… | read-only |
check_injectionCheck Injection | Scan source code for injection vulnerabilities: SQL injection, command injection, path traversal via unsafe string concatenation/unsanitized input. Supports Python, JavaScript, TypeScript, Java, Go, Ruby, Shell, Bash.… | read-only |
check_dependenciesCheck Dependencies | Audit project dependencies (npm/PyPI/Maven/RubyGems/etc.) against CVE database: find known vulnerabilities in your package list. Bulk query up to 50 packages per call (same for Free and Pro). Use for dependency security… | read-only |
username_lookupUsername Lookup | Search for username across 15+ social/dev platforms (GitHub, Reddit, X/Twitter, LinkedIn, Instagram, TikTok, Discord, YouTube, Keybase, HackerOne, etc.). Use for OSINT investigations and identity verification. Free:… | read-only |
check_headersCheck Headers | Validate HTTP security headers you provide (JSON): CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy against best practices. Use to test header config before deployment or validate… | read-only |
What https://api.contrastcyber.com/mcp/ answered to tools/list, asked without credentials over MCP 2026-07-28. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.
How its tools read to an agent 0 errors · 59 warnings · 1 note
- warnTC07cve_lookupthe description is about 536 tokens
- warnTC13check_dependenciespackages[] (object with no properties)
- warnTC14cwe_lookupallowed values are in the description, not an enum: cwe_id
- warnTC22asn_lookupthe definition is about 2,174 tokens
- warnTC22atlas_case_study_lookupthe definition is about 2,263 tokens
- warnTC22atlas_case_study_searchthe definition is about 2,598 tokens
- warnTC22atlas_technique_lookupthe definition is about 2,811 tokens
- warnTC22atlas_technique_searchthe definition is about 2,894 tokens
- warnTC22audit_domainthe definition is about 9,235 tokens
- warnTC22brand_assetsthe definition is about 2,793 tokens
- warnTC22bulk_atlas_technique_lookupthe definition is about 3,571 tokens
- warnTC22bulk_cve_lookupthe definition is about 6,267 tokens
- warnTC22bulk_ioc_lookupthe definition is about 2,841 tokens
- warnTC22bulk_sigma_rule_lookupthe definition is about 3,511 tokens
- warnTC22calculate_risk_scorethe definition is about 2,522 tokens
- warnTC22check_dependenciesthe definition is about 2,680 tokens
- warnTC22check_headersthe definition is about 3,087 tokens
- warnTC22check_injectionthe definition is about 2,495 tokens
- warnTC22check_secretsthe definition is about 2,476 tokens
- warnTC22contrast_scanthe definition is about 2,929 tokens
- warnTC22cve_leadingthe definition is about 4,180 tokens
- warnTC22cve_lookupthe definition is about 5,930 tokens
- warnTC22cve_searchthe definition is about 5,368 tokens
- warnTC22cwe_lookupthe definition is about 3,228 tokens
The first 24 of 60; every finding is in the listing's JSON under mcpTools.check.
The checks from /check and anchor check, run each day on the list above: about 177,970 tokens of definitions. Not part of the score yet. Check your own server.