# ContrastAPI (slim) > ContrastAPI, an MCP server by contrastcyber.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. 55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key. - Full: https://www.anchorterminal.com/tools/contrastcyber-api.md (~3,600 tokens) · this version ~3,530 tokens · JSON https://www.anchorterminal.com/tools/contrastcyber-api.json · canonical https://www.anchorterminal.com/tools/contrastcyber-api - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 # ContrastAPI > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by contrastcyber.com (https://api.contrastcyber.com) - Category: Email delivery APIs (https://www.anchorterminal.com/categories/email.md) - Listed because: It's published in the registry under contrastcyber.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: 55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk\_score. No key. ## Facts - MCP registry: `com.contrastcyber/api` 1.36.2 - Endpoint: https://api.contrastcyber.com/mcp/ (streamable HTTP) - Source: https://github.com/UPinar/contrastapi - Website: https://api.contrastcyber.com - GitHub stars: 33 - Registry entry updated: 2026-08-24 ## Tools - Tools it lists (55, about 177,970 tokens of context, `tools/list` without credentials over MCP 2026-07-28, checked 2026-10-04 22:22 UTC): - `domain_report` (read-only): Query DNS, WHOIS, SSL, subdomains, and threat intel for a domain in one call. By default dns.txt is filtered to security-relevant entries (SPF, DMARC, DKIM,… - `audit_domain` (read-only): Perform comprehensive domain audit: combines domain_report + live HTTP security headers + technology fingerprinting. By default report.dns.txt is filtered to… - `contrast_scan` (read-only): Active website security scan: runs the ContrastScan C engine (11 modules — HTTP security headers, SSL/TLS, DNS, redirect chain, information disclosure, cookie… - `tech_stack_cve_audit` (read-only): Composite tech-stack + CVE audit (MCP-only, no REST endpoint). Detects technologies on the target domain, queries CVE database for known vulnerabilities per… - `threat_report` (read-only): Query comprehensive threat profile for an IP: Shodan host data, AbuseIPDB reputation, ASN/geolocation, and open ports. Use for IP investigation and SOC alert… - `dns_lookup` (read-only): Query all DNS record types (A, AAAA, MX, NS, TXT, CNAME, SOA) for a domain. Use for mail routing inspection, nameserver verification, or SPF/DMARC checks; for… - `whois_lookup` (read-only): Retrieve WHOIS registration data: registrar, creation/expiry dates, nameservers, status. Use to verify domain ownership, age, expiration; for full audit use… - `ssl_check` (read-only): (not repeated here: it reads like a rating or a usage claim) - `subdomain_enum` (read-only): Discover subdomains using passive methods: Certificate Transparency logs + DNS brute-force (no active probing). Use to map organization's attack surface;… - `tech_fingerprint` (read-only): Detect website technology stack: CMS, frameworks, CDN, analytics tools, web servers, languages (via HTTP headers + HTML analysis). Use for passive… - `threat_intel` (read-only): Check domain against abuse.ch URLhaus for known malware-distribution URLs (single source — for multi-feed correlation use ioc_lookup which adds ThreatFox and,… - `wayback_lookup` (read-only): Retrieve Wayback Machine snapshots for a domain: first capture, latest, total count, snapshot list. Use to investigate domain history and age; for full audit… - `scan_headers` (read-only): Perform live HTTP GET and analyze security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy. Use to audit live… - `email_mx` (read-only): Analyze email security: MX records, SPF policy, DMARC policy, DKIM probe across common+date-based selectors, mail provider, grade. Use to verify email-auth… - `email_security_posture` (read-only): Analyze domain email authentication posture: SPF, DMARC, DKIM with numeric score and findings. Dual-use: red-team (spoofing feasibility) + blue-team (posture… - `email_disposable` (read-only): Check if email address uses a known disposable/temporary provider (Guerrilla Mail, Temp Mail, Mailinator, etc.). Use for input validation to detect throwaway… - `email_verify` (read-only): One-call email validation combining syntax + MX records + disposable check + role-address detection (admin@/info@/...) + free-provider classification… - `robots_txt` (read-only): Fetch + parse the target domain's robots.txt — sitemaps, per-User-agent allow/disallow rules, crawl-delay, Host directive. Use BEFORE crawling/scraping a… - `redirect_chain` (read-only): Walk an HTTP redirect chain hop-by-hop, returning per-hop {url, status_code, location, latency_ms}. Use to deobfuscate URL shorteners (bit.ly / t.co /… - `brand_assets` (read-only): Scrape a domain's homepage `` for public brand assets — favicon, og:image, theme-color, og:site_name, JSON-LD `Organization.logo`. Use to enrich CRM… - `seo_audit` (read-only): One-shot SEO audit of a domain's homepage with a 0-100 composite score + a `missing_signals` list of concrete fixes. Use BEFORE pitching SEO work to a… - `geo_audit` (read-only): Deterministic GEO / AI-visibility readiness audit of a domain's homepage with a 0-100 score + a `missing_signals` fix list. Answers "can AI assistants… - `phone_lookup` (read-only): Validate and analyze phone number: country, region, carrier, line type (mobile/landline/VoIP), timezone, formatted versions. Use to verify phone legitimacy and… - `ip_lookup` (read-only): Query comprehensive IP intelligence: reverse DNS, ASN + holder name + country inline (RIPE Stat, Phase 1), open ports, hostnames, vulnerabilities (Shodan… - `asn_lookup` (read-only): Look up Autonomous System Number (ASN) for a domain or IP: AS number, organization, IPv4/IPv6 prefixes. Use to identify network operator and IP range… - `cve_lookup` (read-only): Retrieve detailed CVE data by ID: description, CVSS v3.1 + vector, CVSS v2 (always emitted), EPSS score + percentile, CISA KEV status (expanded: due_date,… - `calculate_risk_score` (read-only): Composite CVE risk score (0-100) — fuses CVSS, EPSS, KEV, and PoC into a single agent-ready triage signal. Formula: CVSS*0.20 + EPSS*0.35 + KEV*0.30 + PoC*0.15… - `get_cvss_details` (read-only): Parse a CVSS v3.x vector string into a per-metric breakdown plus a recomputed base score. Returns the canonicalized vector, version (3.0 or 3.1), base_score,… - `cve_search` (read-only): Search CVE database with filters: product/vendor, severity, published date range, EPSS score, CWE, CVSS range, CISA KEV status. Default response is SLIM… - `cve_leading` (read-only): List CVEs indexed from MITRE/GHSA BEFORE NVD publication (early-warning, freshest data). By default each result is slim (no description, no cvss_breakdown, no… - `exploit_lookup` (read-only): Search public exploits/PoC for a specific CVE across three sources: (1) GitHub Advisory Database (sources.github.advisories[]), (2) Shodan CVEDB references… - `bulk_cve_lookup` (read-only): Batch query multiple CVEs (up to 50 per call, same for Free and Pro): retrieve full CVE details for all in 1 request instead of N. By default each CVE's… - `kev_detail` (read-only): Look up CISA KEV (Known Exploited Vulnerabilities) full record for a CVE. Returns federal patch deadline (due_date), CISA-specified required_action… - `cwe_lookup` (read-only): Look up MITRE CWE (Common Weakness Enumeration) catalog record from research view 1000. Default response is SLIM (first 3 mitigations, first 3 examples;… - `atlas_technique_lookup` (read-only): Look up a MITRE ATLAS technique — the AI/ML adversarial attack catalog. ATLAS catalogues TTPs targeting machine learning systems: prompt injection, model… - `bulk_atlas_technique_lookup` (read-only): Bulk ATLAS technique lookup — retrieve full records for up to 50 techniques in a single request instead of N separate atlas_technique_lookup calls. Designed as… - `atlas_technique_search` (read-only): Search the MITRE ATLAS catalog of AI/ML attack techniques by keyword, tactic, or maturity. Default response is SLIM (description truncated to 240 chars per… - `atlas_case_study_lookup` (read-only): Look up a MITRE ATLAS case study — a documented real-world AI/ML attack incident. Each case study links a sequence of ATLAS techniques (techniques_used) to the… - `atlas_case_study_search` (read-only): Search ATLAS case studies (real-world AI/ML attack incidents) by keyword or referenced technique. Default response is SLIM (description truncated to 240 chars… - `d3fend_defense_lookup` (read-only): Look up a MITRE D3FEND defense technique. D3FEND is the canonical defensive counterpart to ATT&CK — each defense is classified into one of 7 tactics… - `d3fend_defense_search` (read-only): Search the MITRE D3FEND catalog of defensive techniques by keyword, tactic, or targeted artifact. Default response is SLIM (drops `uri` from each row — saves… - `d3fend_defense_for_attack` (read-only): Reverse lookup: given an ATT&CK T-code, return D3FEND defenses that mitigate it. This is the bridge from offensive intelligence (ATT&CK / ATLAS / CVE) to… - `d3fend_attack_coverage` (read-only): Batch coverage breakdown: given a list of ATT&CK T-codes, return distinct defense counts per D3FEND tactic + identify which techniques have NO D3FEND mapping… - `sigma_rule_lookup` (read-only): Look up a single Sigma detection rule by UUID from the SigmaHQ corpus (~3,200 rules, refreshed daily at 02:00 UTC). Returns the full rule with title,… - `bulk_sigma_rule_lookup` (read-only): Bulk Sigma rule lookup — retrieve full records for up to 50 rule UUIDs in a single request instead of N separate sigma_rule_lookup calls. Designed for triage… - `ioc_lookup` (read-only): Enrich Indicator of Compromise (IP/domain/URL/hash) by auto-detecting type and querying abuse.ch feeds. Per-type source coverage: hash → ThreatFox only (Feodo… - `hash_lookup` (read-only): Query MalwareBazaar for file hash (MD5/SHA1/SHA256): malware family, file type, size, tags, first/last seen, download count. Use to check if file hash is known… - `password_check` (read-only): Check if SHA-1 hash appears in Have I Been Pwned (HIBP) breach dataset using k-anonymity (5-char prefix only, full hash never leaves tool). Use for password… - `phishing_check` (read-only): Query URLhaus for a specific URL and its host. is_malicious is True only when there is ACTIVE evidence — exact URL match with url_status='online' (or unknown)… - `bulk_ioc_lookup` (read-only): Batch query multiple IOCs (IP/domain/URL/hash, up to 50 per call, same for Free and Pro) in 1 request: auto-detects type + queries abuse.ch feeds… - `check_secrets` (read-only): Scan source code (or snippet) for hardcoded secrets — cloud provider keys, API tokens, connection strings, private keys, passwords. Supports Python,… - `check_injection` (read-only): Scan source code for injection vulnerabilities: SQL injection, command injection, path traversal via unsafe string concatenation/unsanitized input. Supports… - `check_dependencies` (read-only): Audit project dependencies (npm/PyPI/Maven/RubyGems/etc.) against CVE database: find known vulnerabilities in your package list. Bulk query up to 50 packages… - `username_lookup` (read-only): Search for username across 15+ social/dev platforms (GitHub, Reddit, X/Twitter, LinkedIn, Instagram, TikTok, Discord, YouTube, Keybase, HackerOne, etc.). Use… - `check_headers` (read-only): Validate HTTP security headers you provide (JSON): CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy against best… - How its tools read to an agent (0 errors, 59 warnings, 1 note, about 177,970 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC07 cve_lookup: the description is about 536 tokens - warn TC13 check_dependencies: packages[] (object with no properties) - warn TC14 cwe_lookup: allowed values are in the description, not an enum: cwe_id - warn TC22 asn_lookup: the definition is about 2,174 tokens - warn TC22 atlas_case_study_lookup: the definition is about 2,263 tokens - warn TC22 atlas_case_study_search: the definition is about 2,598 tokens - warn TC22 atlas_technique_lookup: the definition is about 2,811 tokens - warn TC22 atlas_technique_search: the definition is about 2,894 tokens - warn TC22 audit_domain: the definition is about 9,235 tokens - warn TC22 brand_assets: the definition is about 2,793 tokens - warn TC22 bulk_atlas_technique_lookup: the definition is about 3,571 tokens - warn TC22 bulk_cve_lookup: the definition is about 6,267 tokens - warn TC22 bulk_ioc_lookup: the definition is about 2,841 tokens - warn TC22 bulk_sigma_rule_lookup: the definition is about 3,511 tokens - warn TC22 calculate_risk_score: the definition is about 2,522 tokens - warn TC22 check_dependencies: the definition is about 2,680 tokens - warn TC22 check_headers: the definition is about 3,087 tokens - warn TC22 check_injection: the definition is about 2,495 tokens - warn TC22 check_secrets: the definition is about 2,476 tokens - warn TC22 contrast_scan: the definition is about 2,929 tokens - warn TC22 cve_leading: the definition is about 4,180 tokens - warn TC22 cve_lookup: the definition is about 5,930 tokens - warn TC22 cve_search: the definition is about 5,368 tokens - warn TC22 cwe_lookup: the definition is about 3,228 tokens - JSON: https://www.anchorterminal.com/api/v1/tools/contrastcyber-api.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming