MCP Service
FlagThis runs a public
Model Context Protocol (MCP) server, so AI assistants and agents can query FlagThis threat intelligence directly instead of scraping pages. It needs no account or API key, and is rate limited (about 60 requests per minute per client).
Streamable HTTP: https://flagthis.com/mcp/
Why use this instead of NVD, CISA KEV or a web search?
- One call, already joined. A CVE lookup returns CVSS, EPSS, CISA KEV status, SSVC, public exploit / PoC and scanner-template availability, CWE and a plain
PATCH_NOW / PATCH_SOON / SCHEDULE / MONITOR call with the reasons. Otherwise your agent has to fetch NVD, KEV and EPSS separately and reconcile them.
- Built for agents. Compact structured JSON instead of scraped pages, so responses are small, there is no HTML to parse, no API key is needed and the answers are cached.
- Data you can't get elsewhere: package safety. Sentinel tracks malicious, typosquatted and brand-impersonating npm and PyPI packages, plus takedowns. It also flags names that don't exist on the registry, which is how LLM-hallucinated "slopsquat" installs happen. Registries and CVE databases don't tell you this before
pip install.
- Honest about gaps. A package we haven't audited is reported as
audited: false, never as safe, and the request is queued so the most-requested packages get evaluated first.
FlagThis doesn't replace the authoritative records: NVD and the CNAs remain the source of truth for CVE text and scoring. It aggregates and triages them for you.
Available tools
| Tool |
What it does |
flagthis_lookup_cve | CVE details plus a triage call: CVSS, EPSS, CISA KEV, SSVC, public exploit / PoC, CWE, and a patch-priority level with reasons |
flagthis_search_recent_cves | The newest published CVEs, newest first (optional minimum CVSS) |
flagthis_search_exploited_cves | CVEs exploited in the wild or added to CISA KEV |
flagthis_check_package | Checks an npm or PyPI package against Sentinel takedowns, brand impersonation and threat score |
flagthis_check_packages | Batch version: check up to 25 npm / PyPI packages (e.g. a whole requirements.txt) in one call |
flagthis_get_daily_brief | Compact daily threat brief (under 2,000 tokens) |
flagthis_get_safe_handling_principles | The FlagThis agent safe-handling principles, citable by number |
flagthis_safe_harbor_evaluate | Evaluates a suspicious instruction and returns a directive such as HALT_TOOL_EXECUTION or PAUSE_AND_AWAIT_OPERATOR. See /agent |
Set up your client
Claude Code
claude mcp add --transport http flagthis https://flagthis.com/mcp/
Claude.ai and Claude Desktop (custom connector)
Open Settings, then Connectors, choose "Add custom connector", and enter https://flagthis.com/mcp/. Leave authentication empty.
Cursor
Add to ~/.cursor/mcp.json (or the project's .cursor/mcp.json):
{
"mcpServers": {
"flagthis": { "url": "https://flagthis.com/mcp/" }
}
}
VS Code (GitHub Copilot)
Add to .vscode/mcp.json:
{
"servers": {
"flagthis": { "type": "http", "url": "https://flagthis.com/mcp/" }
}
}
Windsurf
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"flagthis": { "serverUrl": "https://flagthis.com/mcp/" }
}
}
Gemini CLI
Add to ~/.gemini/settings.json:
{
"mcpServers": {
"flagthis": { "httpUrl": "https://flagthis.com/mcp/" }
}
}
Clients that only speak stdio
{
"mcpServers": {
"flagthis": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://flagthis.com/mcp/"]
}
}
}
Test it with curl
curl -s -X POST https://flagthis.com/mcp/ \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"1"}}}'
Results are AI-assisted intelligence and may be incomplete. Verify anything critical independently. Client configuration formats change between releases; if one of the snippets above stops working, check your client's MCP documentation.