Skip to main content

KeyboardCrumbs MCP Server

mcp-name: com.keyboardcrumbs/mcp

Live threat intelligence tools for Claude Desktop. Free, no API key required.

Tools

Tool Description
check_ip Threat intel for any IP — risk score, geo, ASN, C2 associations, staging clusters
check_cve CVE lookup — CVSS, EPSS, KEV status, exploit availability, patch urgency
check_domain Domain intel — DNS records, WHOIS, malware associations, subdomains
check_hash Malware hash lookup via VirusTotal (68+ engines) + CIRCL (6.3B files)
active_threats Live snapshot — KEV count, active C2s, ransomware victims, data freshness
predict_kev KEV Oracle — top CVEs predicted to be added to CISA KEV before it happens
check_staging GhostWatch — detect pre-attack infrastructure staging for an IP or domain
check_ransomware Ransomware group lookup and victim tracking

Install

Option 1 — uvx (no install needed)

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "keyboardcrumbs": {
      "command": "uvx",
      "args": ["--from", "git+https://github.com/keyboardcrumbs/mcp", "keyboardcrumbs-mcp"]
    }
  }
}

Option 2 — Clone and run locally

git clone https://github.com/keyboardcrumbs/mcp
cd mcp
uv venv && source .venv/bin/activate
uv add "mcp[cli]" httpx

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "keyboardcrumbs": {
      "command": "uv",
      "args": ["--directory", "/path/to/mcp", "run", "server.py"]
    }
  }
}

Restart Claude Desktop.

Example Usage

Once installed, just ask Claude:

  • "Is 45.141.26.73 malicious?"
  • "Should I patch CVE-2024-3400 immediately?"
  • "What CVEs are about to be added to CISA KEV?"
  • "Is this domain staging for an attack?"
  • "What's the current threat landscape?"

Claude will call the live KeyboardCrumbs API and return real-time threat intelligence.

Data Sources

URLhaus · Feodo Tracker · AlienVault OTX · CISA KEV · NVD · EPSS · ExploitDB · VirusTotal · CIRCL · SANS ISC DShield · Shodan · RIPE · crt.sh · Ransomware.live

Data updates every 15 minutes. No API key. No signup. No rate limits for normal use.

Links

Release files for keyboardcrumbs-mcp 1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keyboardcrumbs-mcp 1.0.1
File Size Uploaded
keyboardcrumbs_mcp-1.0.1.tar.gz 6.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keyboardcrumbs-mcp 1.0.1
File Interpreter ABI Platform
keyboardcrumbs_mcp-1.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 14.3 kB

Release files / keyboardcrumbs_mcp-1.0.1.tar.gz

Download URL keyboardcrumbs_mcp-1.0.1.tar.gz
Size 6.8 kB
Tags Source
SHA-256 checksum
How to use checksums
c5599bb1e3fd30e88969a4f556f29a1458f65bab3e44ff65b29c7a5814f5d9d2
BLAKE2b-256 checksum
How to use checksums
e629715407ce184a96b92b9a3801913dc4a34360c42968030a8eaa05586e0d88
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / keyboardcrumbs_mcp-1.0.1-py3-none-any.whl

Download URL keyboardcrumbs_mcp-1.0.1-py3-none-any.whl
Size 7.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
31af440ae05045f37867a98b7632d062bfc59e34fd50a59122f817712784c184
BLAKE2b-256 checksum
How to use checksums
fcbaf86e8547bb757d744c763889d87741d011eda83b7cf0371ddbf8bfa23787
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page