HoneyLabs by honeylabs.net

MCP server · indexed, not reviewed

Hostedvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.

What the official MCP registry says

Facts

MCP registry
net.honeylabs/mcp · 1.1.0
Endpoint
https://mcp.honeylabs.net/mcp
GitHub stars
2
Registry entry
updated 28 Aug 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under honeylabs.net, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 10 · about 3,154 tokens of context · checked 26 minutes ago

ToolWhat it doesHint
search_events_toolReturn individual raw honeypot events with all fields. Use when the user wants to see actual records: 'show me events from this IP', 'what hit port 443 last week', 'events from Russia yesterday'. Filters: source_ip,…
top_attackers_toolRanked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top attacking countries', 'most targeted ports', 'most common user agents', 'top ASNs by attack volume', 'top IPs from China', 'top attackers…
ioc_lookup_toolLook up any IP address, CIDR network, set of networks, or domain in the honeypot dataset. Use this FIRST whenever the user asks: 'is this IP malicious?', 'is this a known scanner?', 'have you seen this IP?', 'what does…
cve_lookup_toolWho is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577 being exploited in the wild?', 'who is scanning for this CVE?', 'show me actors probing CVE-2023-1389'. Returns severity, KEV…
payload_search_toolLiteral substring search over captured request text: URL path, request body, request headers and event summary. Use for: 'find attacks targeting /wp-admin', 'find requests with this user agent string', 'what payloads…
attack_timeline_toolAttack volume over time, bucketed by hour or day. Use for: 'show attack trends this week', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'attack volume from China over 30 days'. bucket: 'hour' or…
asn_enrich_toolFull honeypot profile for an ASN (autonomous system / hosting provider). Use for: 'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks from this hosting provider', 'attribute this IP to its…
fingerprint_search_toolSearch honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks: 'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?', 'how common is this HASSH?', 'find all scanners with this…
fingerprint_similar_toolRequest shapes within a few headers of an Akin HTTP fingerprint, with what those clients ask for and call themselves, plus the family the token belongs to. Use when one odd request shape turns up in your own web, WAF or…
fingerprint_population_toolThe population behind a single client fingerprint: how many source IPs carry it, across how many networks (ASNs) and countries, the ports they hit, the top networks and a sample of the IPs, plus a read on its shape:…

What https://mcp.honeylabs.net/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 21 warnings · 1 note

  • warnTC07ioc_lookup_toolthe description is about 532 tokens
  • warnTC11asn_enrich_toolnone of its 3 parameters has a description
  • warnTC11attack_timeline_toolnone of its 6 parameters has a description
  • warnTC11cve_lookup_toolnone of its 3 parameters has a description
  • warnTC11fingerprint_population_toolnone of its 2 parameters has a description
  • warnTC11fingerprint_search_toolnone of its 5 parameters has a description
  • warnTC11fingerprint_similar_toolnone of its 3 parameters has a description
  • warnTC11ioc_lookup_toolnone of its 2 parameters has a description
  • warnTC11payload_search_toolnone of its 4 parameters has a description
  • warnTC11search_events_toolnone of its 17 parameters has a description
  • warnTC11top_attackers_toolnone of its 7 parameters has a description
  • warnTC16asn_enrich_toolno readOnlyHint or destructiveHint
  • warnTC16attack_timeline_toolno readOnlyHint or destructiveHint
  • warnTC16cve_lookup_toolno readOnlyHint or destructiveHint
  • warnTC16fingerprint_population_toolno readOnlyHint or destructiveHint
  • warnTC16fingerprint_search_toolno readOnlyHint or destructiveHint
  • warnTC16fingerprint_similar_toolno readOnlyHint or destructiveHint
  • warnTC16ioc_lookup_toolno readOnlyHint or destructiveHint
  • warnTC16payload_search_toolno readOnlyHint or destructiveHint
  • warnTC16search_events_toolno readOnlyHint or destructiveHint
  • warnTC16top_attackers_toolno readOnlyHint or destructiveHint
  • noteTC24server10 of 10 tools have no outputSchema

The checks from /check and anchor check, run each day on the list above: about 3,154 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.