DataNexus MCP by datanexusmcp.com

MCP server · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Public data intelligence for AI agents — CVE, compliance, patents, contracts, domains.

What the official MCP registry says

Facts

MCP registry
com.datanexusmcp/mcp-server · 2.4.14
Endpoint
https://datanexusmcp.com/mcp
Packages
npm @datanexusmcp/mcp-server stdio
npm / week
105
Registry entry
updated 30 Jul 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under datanexusmcp.com, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 55 · about 19,453 tokens of context · checked 4 hours ago

ToolWhat it doesHint
report_feedbackReport FeedbackReport a data quality issue or agent intent gap for a DataNexus tool response. tool_id: e.g. "T10" or "security_fetch_cve_detail". query_hash: From the query_hash field of the response. signal: incorrect_data |…read-only
report_mcpize_linkReport Mcpize LinkCheck MCPize subscription status for a DataNexus tool. tool_id: DataNexus tool identifier e.g. "T10". Pass the tool the user is asking about. Returns: status ("free" | "subscription_required" | "not_configured"),…read-only
validate_tool_outputValidate Tool OutputValidate a DataNexus tool response for data quality issues using two-layer validation: deterministic rules first, then AI review for ambiguous cases. Read-only. Never blocks. tool_id: DataNexus tool identifier e.g. T04,…read-only
search_datanexus_toolsSearch Datanexus ToolsFind the right DataNexus tool by describing your task in plain English. Read-only. No side effects. Call this before any other DataNexus tool to reduce context load from 40000 to 800 tokens. query: Plain English…read-only
nonprofit_fetch_nonprofit_by_einNonprofit Fetch Nonprofit By EinFetch IRS 990 filing data for any US nonprofit by EIN. Read-only. No side effects. Idempotent. US only. ein: 9-digit Employer ID with or without dash, e.g. 46-5734087 or 465734087. Required. Returns name, revenue,…read-only
nonprofit_search_nonprofits_by_nameNonprofit Search Nonprofits By NameSearch US nonprofits by name with optional state filter. Read-only. No side effects. Idempotent. US only. Returns up to 25 matches. name: Full or partial organisation name. Required. state: Two-letter US state code e.g.…read-only
nonprofit_fetch_charity_ukNonprofit Fetch Charity UkFetch UK registered charity details by charity number or organisation name. Read-only. No side effects. Idempotent. UK only. charity_number_or_name: UK registered charity number (7 digits, e.g. 1234567) or full/partial…read-only
security_fetch_package_vulnerabilitiesSecurity Fetch Package VulnerabilitiesFetch all known CVEs for an open source package version or a batch of packages. Read-only. No side effects. Idempotent. Single-package mode: package (e.g. requests), version (e.g. 2.28.0), ecosystem…read-only
security_fetch_dependency_graphSecurity Fetch Dependency GraphFetch the full dependency tree for a package version including transitive dependencies. Read-only. No side effects. Idempotent. Hard 8-second timeout — large dependency trees may return partial results. package: Package…read-only
security_fetch_cve_detailSecurity Fetch Cve DetailFetch full detail for a specific CVE by ID. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format CVE-YYYY-NNNNN e.g. CVE-2021-44228. Required. Returns description, CVSS base score, affected products,…read-only
security_audit_sbom_vulnerabilitiesSecurity Audit Sbom VulnerabilitiesAudit a Software Bill of Materials for known vulnerabilities across all listed packages. Read-only. No side effects. Idempotent. sbom_json: CycloneDX or SPDX SBOM as a JSON string. Required. Large SBOMs (100+ packages)…read-only
security_fetch_package_licenceSecurity Fetch Package LicenceFetch the SPDX licence identifier for an open source package version. Read-only. No side effects. Idempotent. package: Package name e.g. flask. Required. version: Exact version string e.g. 2.3.0. Required. ecosystem:…read-only
security_fetch_cisa_kevSecurity Fetch Cisa KevCheck whether a CVE is in the CISA Known Exploited Vulnerabilities (KEV) catalog. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format CVE-YYYY-NNNNN e.g. CVE-2021-44228. Required. Returns in_kev…read-only
security_fetch_cve_epssSecurity Fetch Cve EpssEPSS exploit probability score for a CVE — predicts likelihood of exploitation in the next 30 days. cve_id: CVE identifier e.g. "CVE-2021-44228". Returns: epss (float 0.0–1.0) and percentile (float 0.0–100.0).…read-only
compliance_fetch_npi_providerCompliance Fetch Npi ProviderFetch NPI registration details for a US healthcare provider by NPI number. Read-only. No side effects. Idempotent. US only. npi_number: 10-digit NPI number e.g. 1003000126. Required. Do not include dashes or spaces.…read-only
compliance_search_npi_by_nameCompliance Search Npi By NameSearch the NPPES NPI Registry by provider name with optional state and speciality filters. Read-only. No side effects. Idempotent. US only. Returns up to 10 matches. name: Full or partial provider name. Required. state:…read-only
compliance_fetch_finra_brokerCompliance Fetch Finra BrokerFetch FINRA BrokerCheck registration for a US broker or investment adviser by CRD number. Read-only. No side effects. Idempotent. US only. crd_number: Central Registration Depository number as a string of digits e.g.…read-only
compliance_check_sam_exclusionCompliance Check Sam ExclusionCheck whether an entity is on the US federal exclusions list (debarred from government contracts). Read-only. No side effects. Idempotent. US only. name_or_ein: Entity name or 9-digit EIN with or without dash e.g. Acme…read-only
domain_fetch_domain_rdapDomain Fetch Domain RdapFetch domain registration details via IANA RDAP (the modern structured replacement for WHOIS). Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. example.com not https://example.com.…read-only
domain_fetch_ssl_certificate_chainDomain Fetch Ssl Certificate ChainFetch SSL certificate history for a domain from Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. github.com. Required. Does not support IP addresses or…read-only
domain_fetch_dns_recordsDomain Fetch Dns RecordsFetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. cloudflare.com. Required. record_types: List of DNS record types to…read-only
domain_fetch_domain_historyDomain Fetch Domain HistoryFetch historical SSL certificate issuance for a domain from Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. example.com. Required. Returns all past…read-only
domain_fetch_subdomainsDomain Fetch SubdomainsEnumerate subdomains for a domain via Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. anthropic.com. Required. Returns deduplicated list of known…read-only
domain_check_email_securityDomain Check Email SecurityCheck SPF, DMARC, and DKIM email authentication for a domain. domain: Domain without protocol e.g. "google.com". Returns: overall_grade (A–F), spf_score, dmarc_score, dkim_score (each 0–10), spf_record, dmarc_record,…read-only
domain_fetch_reverse_ipDomain Fetch Reverse IpFind domains co-hosted on the same IP address (reverse IP lookup). Read-only. No side effects. Idempotent. domain_or_ip: Domain name (e.g. shared.dreamhost.com) or IPv4 address (e.g. 1.2.3.4). Required. If a domain is…read-only
legal_fetch_patent_by_numberLegal Fetch Patent By NumberFetch full patent details by patent number and jurisdiction. Read-only. No side effects. Idempotent. patent_number: Patent number in EPODOC format e.g. EP1000000 for European, CN120586032 for Chinese, JP2020123456 for…read-only
legal_search_patents_by_keywordLegal Search Patents By KeywordSearch patents by keyword across EPO, USPTO, or WIPO. Read-only. No side effects. Idempotent. Returns up to 10 matches. keywords: Search terms describing the invention e.g. neural network image classification. Required.…read-only
legal_fetch_patent_citationsLegal Fetch Patent CitationsFetch forward and backward citation chains for a specific patent. Read-only. No side effects. Idempotent. patent_number: Patent number in EPODOC format e.g. EP1000000 for European, CN120586032 for Chinese, JP2020123456…read-only
legal_fetch_inventor_portfolioLegal Fetch Inventor PortfolioFetch the patent portfolio for a named inventor with optional assignee filter. Read-only. No side effects. Idempotent. inventor_name: Inventor surname or full name e.g. Smith or John Smith. Required. Fuzzy match —…read-only
govcon_search_contract_awardsGovcon Search Contract AwardsSearch government contract awards by keyword, agency, and date range. keyword: Contract scope e.g. "cybersecurity software". agency: Awarding agency e.g. "Department of Defense". Optional. date_from: Earliest award date…read-only
govcon_fetch_vendor_contract_historyGovcon Fetch Vendor Contract HistoryFetch the complete federal contract award history for a specific vendor. Read-only. No side effects. Idempotent. vendor_name: Company or organisation name e.g. Booz Allen Hamilton. Required. Fuzzy match used.…read-only
govcon_fetch_open_solicitationsGovcon Fetch Open SolicitationsFetch currently open government contract solicitations matching a keyword. Read-only. No side effects. Idempotent. keyword: Description of goods or services sought e.g. cloud computing services. Required. Encode special…read-only
regulatory_search_open_rulemakingsRegulatory Search Open RulemakingsSearch open rulemakings and public comment periods on Regulations.gov and the Federal Register. Read-only. No side effects. Idempotent. US federal only. keyword: Topic keywords e.g. artificial intelligence, data…read-only
regulatory_fetch_docket_detailsRegulatory Fetch Docket DetailsFetch full details for a specific regulatory docket by ID. Read-only. No side effects. Idempotent. US federal only. docket_id: Docket identifier in agency format e.g. EPA-HQ-OAR-2021-0317 or FTC-2024-0041. Required.…read-only
regulatory_fetch_federal_register_noticesRegulatory Fetch Federal Register NoticesFetch recent Federal Register notices and rules for a specific agency. Read-only. No side effects. Idempotent. US federal only. agency: Agency name or abbreviation e.g. SEC, Food and Drug Administration, EPA. Required.…read-only
security_fetch_package_maintainer_historySecurity Fetch Package Maintainer HistoryAnalyse ownership and release history for an npm or PyPI package to detect supply-chain risk. Uses PyPI JSON API and npm registry — data refreshed on each call, 1-hour cache. Returns maintainer_count, recent_changes,…read-only
security_fetch_package_risk_briefSecurity Fetch Package Risk BriefSingle SHIP/CAUTION/BLOCK verdict for any package. Combines CVEs, licence, maintainer health, and transitive count in one call. Uses OSV.dev, deps.dev, PyPI, and npm registry — data refreshed on each call. Returns…read-only
security_detect_typosquattingSecurity Detect TyposquattingDetect typosquatting attacks against a package name. Compares using Damerau-Levenshtein distance ≤ 2 against top-10,000 packages. Returns similar_packages with anomaly scores, and a SUSPICIOUS or CLEAN verdict. Uses…read-only
nonprofit_fetch_nonprofit_full_profileNonprofit Fetch Nonprofit Full ProfileComplete nonprofit due diligence in one call. Revenue trends, executive pay, risk flags, and a health score from IRS 990 data. Uses ProPublica Nonprofit Explorer API with IRS e-File fallback. Data refreshed on each…read-only
security_fetch_cve_watchSecurity Fetch Cve WatchPersistent CVE watchlist. Create once, check anytime for new events since your last visit — patch releases, KEV listings, PoC publications, exploitation detected. Uses Redis for persistence, NVD + CISA KEV + EPSS for…writes
security_audit_sbom_continuousSecurity Audit Sbom ContinuousPersistent SBOM watch. Register once, check anytime for new CVEs affecting your dependency snapshot. Silent permanent watch — CycloneDX and SPDX supported. Uses OSV.dev for vulnerability lookup, Redis for persistence…writes
security_fetch_licence_analysisSecurity Fetch Licence AnalysisUnderstand any software licence in plain English. Returns obligations, permissions, limitations, risk level, and OSI/FSF status for any SPDX licence identifier. Static bundle covers top-50 common licences (no network…read-only
security_audit_licence_compatibilitySecurity Audit Licence CompatibilityAudit the licence compatibility of your entire dependency list. Input package names (with ecosystem) or SPDX IDs; get a COMPATIBLE/CONFLICT verdict with specific conflicting pairs and recommended action. Uses static…read-only
security_fetch_cve_risk_summarySecurity Fetch Cve Risk SummaryInstant CVE risk verdict. Combines CVSS severity, CISA KEV exploitation status, and EPSS probability in one parallel call. Returns CRITICAL_EXPLOIT, HIGH_RISK, MODERATE, LOW, or UNKNOWN verdict with patch availability…read-only
nonprofit_search_nonprofits_by_categoryNonprofit Search Nonprofits By CategorySearch US nonprofits by mission category and state. Returns up to 25 results with revenue, assets, and health scores (0–100). Category maps to NTEE codes: education, healthcare, arts, environment, human_services,…read-only
nonprofit_fetch_nonprofit_financial_trendsNonprofit Fetch Nonprofit Financial Trends5-year financial trend for any US nonprofit. Revenue growth, expense ratios, reserve trajectory, and health score history from IRS Form 990 data via ProPublica. Returns trend_direction…read-only
apikeys_generate_api_keyApikeys Generate Api KeyGenerate a DataNexus API key for the given email address. Anonymous callers get 10 free lookups/week; a registered free key unlocks 100/week. Store the returned key — it is shown only once. Pass it as the X-Api-Key…writes
apikeys_rotate_api_keyApikeys Rotate Api Key⚠️ DESTRUCTIVE — requires human confirmation before use in automated pipelines. Revoke the current API key and issue a replacement. Returns the new key once — store it immediately. Pass keys as the X-DataNexus-Key…writes
apikeys_revoke_api_keyApikeys Revoke Api Key⚠️ DESTRUCTIVE — requires human confirmation before use in automated pipelines. Permanently revoke a DataNexus API key. The key will stop working immediately. This action cannot be undone — generate a new key if access…writes
security_audit_sbom_license_policySecurity Audit Sbom License PolicyAudit a CycloneDX or SPDX SBOM against an SPDX licence policy and return a PASS/WARN/BLOCK verdict. sbom: Full SBOM as a JSON string — CycloneDX or SPDX format. Required. 500 KB max. policy: Optional dict with…read-only
security_fetch_cve_watch_statusSecurity Fetch Cve Watch StatusCheck all specified CVE watches for new events since your last poll. Returns only watches with new events, making it efficient to run on a schedule. watch_ids: List of watch IDs to check — same IDs used when creating…read-only
frontend_security_detect_typosquattingFrontend Security Detect TyposquattingTyposquatting detection optimised for the top 500 frontend packages (React, Vite, Axios, Lodash, etc.). Fewer false positives than a full npm scan. For backend packages, use security_detect_typosquatting instead.…read-only
frontend_security_audit_manifestFrontend Security Audit ManifestAudit a frontend package.json for security risks — returns a single SHIP/CAUTION/BLOCK verdict with licence risks and abandonment signals. Different from security_fetch_package_vulnerabilities which audits a single…read-only
frontend_security_audit_ci_pipelineFrontend Security Audit Ci PipelineScan GitHub Actions, Vercel, or Netlify CI configs for exposed secrets, missing lockfile enforcement, and unpinned dependencies. Paste your config content — no filesystem access required. config: Raw YAML/TOML content…read-only
frontend_security_fetch_package_risk_briefFrontend Security Fetch Package Risk BriefSHIP/CAUTION/BLOCK risk brief for an npm package with frontend-specific context. Wraps security_fetch_package_risk_brief restricted to npm, and adds weekly_downloads and is_ui_component signals. package_name: npm…read-only

What https://datanexusmcp.com/mcp answered to tools/list, asked without credentials over MCP 2026-07-28. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 3 warnings · 4 notes

  • warnTC12domain_fetch_dns_recordsno type for record_types[]
  • warnTC12security_fetch_cve_watch_statusno type for watch_ids[]
  • warnTC23server55 tools, about 18,990 tokens of definitions
  • noteTC03frontend_security_fetch_package_risk_briefthe name is 42 characters
  • noteTC03nonprofit_fetch_nonprofit_financial_trendsthe name is 42 characters
  • noteTC03regulatory_fetch_federal_register_noticesthe name is 41 characters
  • noteTC03security_fetch_package_maintainer_historythe name is 41 characters

The checks from /check and anchor check, run each day on the list above: about 19,453 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.