# DataNexus MCP (slim) > DataNexus MCP, an MCP server by datanexusmcp.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Public data intelligence for AI agents — CVE, compliance, patents, contracts, domains. - Full: https://www.anchorterminal.com/tools/datanexusmcp-mcp-server.md (~3,500 tokens) · this version ~3,430 tokens · JSON https://www.anchorterminal.com/tools/datanexusmcp-mcp-server.json · canonical https://www.anchorterminal.com/tools/datanexusmcp-mcp-server - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 # DataNexus MCP > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by datanexusmcp.com (https://datanexusmcp.com) - Listed because: It's published in the registry under datanexusmcp.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Public data intelligence for AI agents — CVE, compliance, patents, contracts, domains. ## Facts - MCP registry: `com.datanexusmcp/mcp-server` 2.4.14 - Endpoint: https://datanexusmcp.com/mcp (streamable HTTP) - Package: npm `@datanexusmcp/mcp-server` (stdio) - npm downloads a week: 105 - Registry entry updated: 2026-07-30 ## Tools - Tools it lists (55, about 19,453 tokens of context, `tools/list` without credentials over MCP 2026-07-28, checked 2026-10-04 22:22 UTC): - `report_feedback` (read-only): Report a data quality issue or agent intent gap for a DataNexus tool response. tool_id: e.g. "T10" or "security_fetch_cve_detail". query_hash: From the… - `report_mcpize_link` (read-only): Check MCPize subscription status for a DataNexus tool. tool_id: DataNexus tool identifier e.g. "T10". Pass the tool the user is asking about. Returns: status… - `validate_tool_output` (read-only): Validate a DataNexus tool response for data quality issues using two-layer validation: deterministic rules first, then AI review for ambiguous cases.… - `search_datanexus_tools` (read-only): Find the right DataNexus tool by describing your task in plain English. Read-only. No side effects. Call this before any other DataNexus tool to reduce context… - `nonprofit_fetch_nonprofit_by_ein` (read-only): Fetch IRS 990 filing data for any US nonprofit by EIN. Read-only. No side effects. Idempotent. US only. ein: 9-digit Employer ID with or without dash, e.g.… - `nonprofit_search_nonprofits_by_name` (read-only): Search US nonprofits by name with optional state filter. Read-only. No side effects. Idempotent. US only. Returns up to 25 matches. name: Full or partial… - `nonprofit_fetch_charity_uk` (read-only): Fetch UK registered charity details by charity number or organisation name. Read-only. No side effects. Idempotent. UK only. charity_number_or_name: UK… - `security_fetch_package_vulnerabilities` (read-only): Fetch all known CVEs for an open source package version or a batch of packages. Read-only. No side effects. Idempotent. Single-package mode: package (e.g.… - `security_fetch_dependency_graph` (read-only): Fetch the full dependency tree for a package version including transitive dependencies. Read-only. No side effects. Idempotent. Hard 8-second timeout — large… - `security_fetch_cve_detail` (read-only): Fetch full detail for a specific CVE by ID. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format CVE-YYYY-NNNNN e.g. CVE-2021-44228.… - `security_audit_sbom_vulnerabilities` (read-only): Audit a Software Bill of Materials for known vulnerabilities across all listed packages. Read-only. No side effects. Idempotent. sbom_json: CycloneDX or SPDX… - `security_fetch_package_licence` (read-only): Fetch the SPDX licence identifier for an open source package version. Read-only. No side effects. Idempotent. package: Package name e.g. flask. Required.… - `security_fetch_cisa_kev` (read-only): Check whether a CVE is in the CISA Known Exploited Vulnerabilities (KEV) catalog. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format… - `security_fetch_cve_epss` (read-only): EPSS exploit probability score for a CVE — predicts likelihood of exploitation in the next 30 days. cve_id: CVE identifier e.g. "CVE-2021-44228". Returns: epss… - `compliance_fetch_npi_provider` (read-only): Fetch NPI registration details for a US healthcare provider by NPI number. Read-only. No side effects. Idempotent. US only. npi_number: 10-digit NPI number… - `compliance_search_npi_by_name` (read-only): Search the NPPES NPI Registry by provider name with optional state and speciality filters. Read-only. No side effects. Idempotent. US only. Returns up to 10… - `compliance_fetch_finra_broker` (read-only): Fetch FINRA BrokerCheck registration for a US broker or investment adviser by CRD number. Read-only. No side effects. Idempotent. US only. crd_number: Central… - `compliance_check_sam_exclusion` (read-only): Check whether an entity is on the US federal exclusions list (debarred from government contracts). Read-only. No side effects. Idempotent. US only.… - `domain_fetch_domain_rdap` (read-only): Fetch domain registration details via IANA RDAP (the modern structured replacement for WHOIS). Read-only. No side effects. Idempotent. domain: Domain name… - `domain_fetch_ssl_certificate_chain` (read-only): Fetch SSL certificate history for a domain from Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol… - `domain_fetch_dns_records` (read-only): Fetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g.… - `domain_fetch_domain_history` (read-only): Fetch historical SSL certificate issuance for a domain from Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without… - `domain_fetch_subdomains` (read-only): Enumerate subdomains for a domain via Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g.… - `domain_check_email_security` (read-only): Check SPF, DMARC, and DKIM email authentication for a domain. domain: Domain without protocol e.g. "google.com". Returns: overall_grade (A–F), spf_score,… - `domain_fetch_reverse_ip` (read-only): Find domains co-hosted on the same IP address (reverse IP lookup). Read-only. No side effects. Idempotent. domain_or_ip: Domain name (e.g.… - `legal_fetch_patent_by_number` (read-only): Fetch full patent details by patent number and jurisdiction. Read-only. No side effects. Idempotent. patent_number: Patent number in EPODOC format e.g.… - `legal_search_patents_by_keyword` (read-only): Search patents by keyword across EPO, USPTO, or WIPO. Read-only. No side effects. Idempotent. Returns up to 10 matches. keywords: Search terms describing the… - `legal_fetch_patent_citations` (read-only): Fetch forward and backward citation chains for a specific patent. Read-only. No side effects. Idempotent. patent_number: Patent number in EPODOC format e.g.… - `legal_fetch_inventor_portfolio` (read-only): Fetch the patent portfolio for a named inventor with optional assignee filter. Read-only. No side effects. Idempotent. inventor_name: Inventor surname or full… - `govcon_search_contract_awards` (read-only): Search government contract awards by keyword, agency, and date range. keyword: Contract scope e.g. "cybersecurity software". agency: Awarding agency e.g.… - `govcon_fetch_vendor_contract_history` (read-only): Fetch the complete federal contract award history for a specific vendor. Read-only. No side effects. Idempotent. vendor_name: Company or organisation name e.g.… - `govcon_fetch_open_solicitations` (read-only): Fetch currently open government contract solicitations matching a keyword. Read-only. No side effects. Idempotent. keyword: Description of goods or services… - `regulatory_search_open_rulemakings` (read-only): Search open rulemakings and public comment periods on Regulations.gov and the Federal Register. Read-only. No side effects. Idempotent. US federal only.… - `regulatory_fetch_docket_details` (read-only): Fetch full details for a specific regulatory docket by ID. Read-only. No side effects. Idempotent. US federal only. docket_id: Docket identifier in agency… - `regulatory_fetch_federal_register_notices` (read-only): Fetch recent Federal Register notices and rules for a specific agency. Read-only. No side effects. Idempotent. US federal only. agency: Agency name or… - `security_fetch_package_maintainer_history` (read-only): Analyse ownership and release history for an npm or PyPI package to detect supply-chain risk. Uses PyPI JSON API and npm registry — data refreshed on each… - `security_fetch_package_risk_brief` (read-only): Single SHIP/CAUTION/BLOCK verdict for any package. Combines CVEs, licence, maintainer health, and transitive count in one call. Uses OSV.dev, deps.dev, PyPI,… - `security_detect_typosquatting` (read-only): Detect typosquatting attacks against a package name. Compares using Damerau-Levenshtein distance ≤ 2 against top-10,000 packages. Returns similar_packages with… - `nonprofit_fetch_nonprofit_full_profile` (read-only): Complete nonprofit due diligence in one call. Revenue trends, executive pay, risk flags, and a health score from IRS 990 data. Uses ProPublica Nonprofit… - `security_fetch_cve_watch` (writes): Persistent CVE watchlist. Create once, check anytime for new events since your last visit — patch releases, KEV listings, PoC publications, exploitation… - `security_audit_sbom_continuous` (writes): Persistent SBOM watch. Register once, check anytime for new CVEs affecting your dependency snapshot. Silent permanent watch — CycloneDX and SPDX supported.… - `security_fetch_licence_analysis` (read-only): Understand any software licence in plain English. Returns obligations, permissions, limitations, risk level, and OSI/FSF status for any SPDX licence… - `security_audit_licence_compatibility` (read-only): Audit the licence compatibility of your entire dependency list. Input package names (with ecosystem) or SPDX IDs; get a COMPATIBLE/CONFLICT verdict with… - `security_fetch_cve_risk_summary` (read-only): Instant CVE risk verdict. Combines CVSS severity, CISA KEV exploitation status, and EPSS probability in one parallel call. Returns CRITICAL_EXPLOIT, HIGH_RISK,… - `nonprofit_search_nonprofits_by_category` (read-only): Search US nonprofits by mission category and state. Returns up to 25 results with revenue, assets, and health scores (0–100). Category maps to NTEE codes:… - `nonprofit_fetch_nonprofit_financial_trends` (read-only): 5-year financial trend for any US nonprofit. Revenue growth, expense ratios, reserve trajectory, and health score history from IRS Form 990 data via… - `apikeys_generate_api_key` (writes): Generate a DataNexus API key for the given email address. Anonymous callers get 10 free lookups/week; a registered free key unlocks 100/week. Store the… - `apikeys_rotate_api_key` (writes): ⚠️ DESTRUCTIVE — requires human confirmation before use in automated pipelines. Revoke the current API key and issue a replacement. Returns the new key once —… - `apikeys_revoke_api_key` (writes): ⚠️ DESTRUCTIVE — requires human confirmation before use in automated pipelines. Permanently revoke a DataNexus API key. The key will stop working immediately.… - `security_audit_sbom_license_policy` (read-only): Audit a CycloneDX or SPDX SBOM against an SPDX licence policy and return a PASS/WARN/BLOCK verdict. sbom: Full SBOM as a JSON string — CycloneDX or SPDX… - `security_fetch_cve_watch_status` (read-only): Check all specified CVE watches for new events since your last poll. Returns only watches with new events, making it efficient to run on a schedule. watch_ids:… - `frontend_security_detect_typosquatting` (read-only): Typosquatting detection optimised for the top 500 frontend packages (React, Vite, Axios, Lodash, etc.). Fewer false positives than a full npm scan. For backend… - `frontend_security_audit_manifest` (read-only): Audit a frontend package.json for security risks — returns a single SHIP/CAUTION/BLOCK verdict with licence risks and abandonment signals. Different from… - `frontend_security_audit_ci_pipeline` (read-only): Scan GitHub Actions, Vercel, or Netlify CI configs for exposed secrets, missing lockfile enforcement, and unpinned dependencies. Paste your config content — no… - `frontend_security_fetch_package_risk_brief` (read-only): SHIP/CAUTION/BLOCK risk brief for an npm package with frontend-specific context. Wraps security_fetch_package_risk_brief restricted to npm, and adds… - How its tools read to an agent (0 errors, 3 warnings, 4 notes, about 19,453 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC12 domain_fetch_dns_records: no type for record_types[] - warn TC12 security_fetch_cve_watch_status: no type for watch_ids[] - warn TC23 server: 55 tools, about 18,990 tokens of definitions - note TC03 frontend_security_fetch_package_risk_brief: the name is 42 characters - note TC03 nonprofit_fetch_nonprofit_financial_trends: the name is 42 characters - note TC03 regulatory_fetch_federal_register_notices: the name is 41 characters - note TC03 security_fetch_package_maintainer_history: the name is 41 characters - JSON: https://www.anchorterminal.com/api/v1/tools/datanexusmcp-mcp-server.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming