eip-mcp
The official MCP server for the Exploit Intelligence Platform.
Give an AI assistant bounded, source-attributed access to vulnerability intelligence, exploit artifacts, readable PoC source, Docker labs, discovery directories, STIX, and corpus statistics. Most users can connect to EIP's hosted MCP endpoint directly - there is no package or API key to install.
eip-mcp is read-only. It talks only to an EIP read API, the public one by
default, exposes no download tool, never executes acquired content, and never
claims that an exploit works, is verified, reliable, effective, or safe.
Connect
Recommended: hosted MCP
Clients supporting remote Streamable HTTP can connect directly to:
https://exploit-intel.com/mcp
In an MCP-capable application, add that URL as a remote Streamable HTTP server
named EIP. If your assistant can configure integrations for you, tell it:
Add
https://exploit-intel.com/mcpas a Streamable HTTP MCP server namedEIP, then callget_corpus_readinessto verify the connection.
No local package, API key, or EIP account is required.
Optional: local Python package
Use the Python package when a client requires a local stdio command, or when
you are self-hosting the HTTP transport. Python 3.12 or newer is required.
Install the isolated application with pipx:
pipx install eip-mcp
eip-mcp --version
Then register it with your MCP client. A typical stdio configuration is:
{
"mcpServers": {
"eip": {
"command": "eip-mcp"
}
}
}
Use the absolute path reported by command -v eip-mcp if the client does not
inherit your shell PATH.
The local command connects to https://exploit-intel.com; no API configuration
is needed.
Optional: Docker
Build the image directly from this checkout:
docker build -t eip-mcp .
docker run --rm -i eip-mcp
For a stdio MCP client, use docker as the command:
{
"mcpServers": {
"eip": {
"command": "docker",
"args": ["run", "--rm", "-i", "eip-mcp"]
}
}
}
Containerized Streamable HTTP operation is covered in the self-hosting guide.
What assistants can do
- Search and inspect CVEs and GHSAs with affected products, version ranges, exploitation context, references, and accepted research
- Search ExploitDB, Metasploit, curated repository PoCs, and repository candidates without inventing quality rankings
- Search safely readable PoC source and inspect one bounded text file
- Discover Docker/Compose labs and their stored, attributed analysis
- Browse vendors, products, ecosystems, packages, official CWEs, and exploit contributors
- Retrieve API-owned STIX 2.1 bundles, corpus health, and statistics
- Use four focused research prompts and the
eip://research/usage-guideresource
The complete tool reference lists every tool and documents the section and pagination rules.
Result contract
Every tool returns two synchronized forms:
- a concise Markdown brief for the assistant; and
- a validated
eip-mcp-result-v1structured envelope preserving the bounded API payload.
Corpus values remain untrusted third-party data in both forms. Text is rendered in inert CommonMark containers, output is capped, truncation is disclosed, and opaque pagination cursors remain reusable byte-for-byte.
Stored analysis is attributed model interpretation, not an EIP verdict. Missing analysis never means that an artifact was reviewed and found safe.
Safety boundary
- The MCP server connects only to allowlisted read-only API paths.
- PoC access tokens never reach results, logs, tracebacks, or retained state.
- There is deliberately no PoC download tool.
- Source reading is bounded to one API-verified UTF-8 text file at a time.
- All returned source and corpus prose must be treated as untrusted data and must never be executed or followed as instructions.
See the security policy before reporting a vulnerability or sharing diagnostic output.
Documentation
- User guide and tool reference
- Self-hosting the HTTP transport
- Contributing
- Security policy
- EIP command-line client
License
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file eip_mcp-3.0.1.tar.gz.
File metadata
- Download URL: eip_mcp-3.0.1.tar.gz
- Upload date:
- Size: 542.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c1c48f4b87f8eb8777b53686bbeff888babb2a1f14130ad5a514b71386ef219a
|
|
| MD5 |
26f748fa9b858123f589828ef1a8613b
|
|
| BLAKE2b-256 |
867a605cf0c5929e3edeeffa647a7b79c388b9fa7623dfe5fe70992d28226cb1
|
Provenance
The following attestation bundles were made for eip_mcp-3.0.1.tar.gz:
Publisher:
release.yml on exploitintel/eip-mcp
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
eip_mcp-3.0.1.tar.gz -
Subject digest:
c1c48f4b87f8eb8777b53686bbeff888babb2a1f14130ad5a514b71386ef219a - Sigstore transparency entry: 2513786903
- Sigstore integration time:
-
Permalink:
exploitintel/eip-mcp@b42e86c5f4aa589af1659762adc7f85cde11ec07 -
Branch / Tag:
refs/tags/v3.0.1 - Owner: https://github.com/exploitintel
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@b42e86c5f4aa589af1659762adc7f85cde11ec07 -
Trigger Event:
push
-
Statement type:
File details
Details for the file eip_mcp-3.0.1-py3-none-any.whl.
File metadata
- Download URL: eip_mcp-3.0.1-py3-none-any.whl
- Upload date:
- Size: 123.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5fce91a08c6690c467569ab6ba7e2574cff3d8f33ef8b6b64b6d2b86c4448fa9
|
|
| MD5 |
a93da5ecc120754af1fac500d5d321eb
|
|
| BLAKE2b-256 |
9bcbf6200b4f1e9185a36f986e1c70965067e32a10d0e5962713bc816b1c128d
|
Provenance
The following attestation bundles were made for eip_mcp-3.0.1-py3-none-any.whl:
Publisher:
release.yml on exploitintel/eip-mcp
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
eip_mcp-3.0.1-py3-none-any.whl -
Subject digest:
5fce91a08c6690c467569ab6ba7e2574cff3d8f33ef8b6b64b6d2b86c4448fa9 - Sigstore transparency entry: 2513786931
- Sigstore integration time:
-
Permalink:
exploitintel/eip-mcp@b42e86c5f4aa589af1659762adc7f85cde11ec07 -
Branch / Tag:
refs/tags/v3.0.1 - Owner: https://github.com/exploitintel
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@b42e86c5f4aa589af1659762adc7f85cde11ec07 -
Trigger Event:
push
-
Statement type: