Not reviewed
No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Facts
- MCP registry
net.honeylabs/mcp· 1.1.0- Endpoint
https://mcp.honeylabs.net/mcp- Website
- honeylabs.net
- GitHub stars
- 2
- Registry entry
- updated 28 Aug 2026
From the official MCP registry, the package registries and our own checks. JSON · Markdown
Why it's listed
- It's published in the registry under honeylabs.net, a namespace the registry only gives to whoever proves they control that domain.
Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.
Tools it lists 10 · about 3,154 tokens of context · checked 26 minutes ago
| Tool | What it does | Hint |
|---|---|---|
search_events_tool | Return individual raw honeypot events with all fields. Use when the user wants to see actual records: 'show me events from this IP', 'what hit port 443 last week', 'events from Russia yesterday'. Filters: source_ip,… | |
top_attackers_tool | Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top attacking countries', 'most targeted ports', 'most common user agents', 'top ASNs by attack volume', 'top IPs from China', 'top attackers… | |
ioc_lookup_tool | Look up any IP address, CIDR network, set of networks, or domain in the honeypot dataset. Use this FIRST whenever the user asks: 'is this IP malicious?', 'is this a known scanner?', 'have you seen this IP?', 'what does… | |
cve_lookup_tool | Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577 being exploited in the wild?', 'who is scanning for this CVE?', 'show me actors probing CVE-2023-1389'. Returns severity, KEV… | |
payload_search_tool | Literal substring search over captured request text: URL path, request body, request headers and event summary. Use for: 'find attacks targeting /wp-admin', 'find requests with this user agent string', 'what payloads… | |
attack_timeline_tool | Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this week', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'attack volume from China over 30 days'. bucket: 'hour' or… | |
asn_enrich_tool | Full honeypot profile for an ASN (autonomous system / hosting provider). Use for: 'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks from this hosting provider', 'attribute this IP to its… | |
fingerprint_search_tool | Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks: 'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?', 'how common is this HASSH?', 'find all scanners with this… | |
fingerprint_similar_tool | Request shapes within a few headers of an Akin HTTP fingerprint, with what those clients ask for and call themselves, plus the family the token belongs to. Use when one odd request shape turns up in your own web, WAF or… | |
fingerprint_population_tool | The population behind a single client fingerprint: how many source IPs carry it, across how many networks (ASNs) and countries, the ports they hit, the top networks and a sample of the IPs, plus a read on its shape:… |
What https://mcp.honeylabs.net/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.
How its tools read to an agent 0 errors · 21 warnings · 1 note
- warnTC07ioc_lookup_toolthe description is about 532 tokens
- warnTC11asn_enrich_toolnone of its 3 parameters has a description
- warnTC11attack_timeline_toolnone of its 6 parameters has a description
- warnTC11cve_lookup_toolnone of its 3 parameters has a description
- warnTC11fingerprint_population_toolnone of its 2 parameters has a description
- warnTC11fingerprint_search_toolnone of its 5 parameters has a description
- warnTC11fingerprint_similar_toolnone of its 3 parameters has a description
- warnTC11ioc_lookup_toolnone of its 2 parameters has a description
- warnTC11payload_search_toolnone of its 4 parameters has a description
- warnTC11search_events_toolnone of its 17 parameters has a description
- warnTC11top_attackers_toolnone of its 7 parameters has a description
- warnTC16asn_enrich_toolno readOnlyHint or destructiveHint
- warnTC16attack_timeline_toolno readOnlyHint or destructiveHint
- warnTC16cve_lookup_toolno readOnlyHint or destructiveHint
- warnTC16fingerprint_population_toolno readOnlyHint or destructiveHint
- warnTC16fingerprint_search_toolno readOnlyHint or destructiveHint
- warnTC16fingerprint_similar_toolno readOnlyHint or destructiveHint
- warnTC16ioc_lookup_toolno readOnlyHint or destructiveHint
- warnTC16payload_search_toolno readOnlyHint or destructiveHint
- warnTC16search_events_toolno readOnlyHint or destructiveHint
- warnTC16top_attackers_toolno readOnlyHint or destructiveHint
- noteTC24server10 of 10 tools have no outputSchema
The checks from /check and anchor check, run each day on the list above: about 3,154 tokens of definitions. Not part of the score yet. Check your own server.