Skip to main content

MCP server for RelayShield — breach detection, SIM swap, domain lookalikes, OAuth watchlist, infostealer detection, URL/file scanning, MCP registry risk, and prompt-injection breach detection. Subscription (RapidAPI) and pay-as-you-go (x402 USDC on Base) access modes.

Project description

relayshield-mcp

mcp-name: io.github.nzdsf2-gif/relayshield-mcp

RelayShield security intelligence as an MCP server — plug breach detection, SIM swap detection, domain lookalike monitoring, OAuth supply chain watchlist, and URL/file scanning directly into Claude and any MCP-compatible AI agent.

Tools

Tool What it does PAYG price
check_breach Email breach lookup — 13 billion+ records via HIBP $0.10 USDC
check_sim_swap SIM swap / eSIM detection via live carrier data $0.25 USDC
check_domain_lookalikes Typosquat and lookalike domain detection with cert transparency $0.50 USDC
check_oauth_watchlist OAuth-app breach + stolen-token exposure via HIBP + stealer-log corpus $0.30 USDC
check_infostealer Infostealer malware log lookup via Hudson Rock Cavalier $0.15 USDC
scan_wallet EVM wallet on-chain risk check via GoPlus Security $0.10 USDC
scan_url URL malware/phishing scan across 70+ engines (async) $0.05 USDC
scan_file Binary malware scan across 70+ AV engines (async) $0.10 USDC
check_scan_result Poll for verdict after scan_url / scan_file free
check_mcp_registry_risk Typosquat/IOC/registration-age check for MCP servers $0.35 USDC
check_prompt_injection_breach Breach exposure sourced from AI-agent prompt-injection attacks $0.35 USDC
check_supply_chain Up to 10 vendor domains checked for breach/infostealer exposure $0.10 USDC
check_session_risk Active/reusable stolen session (cookie/token) exposure check $0.30 USDC
check_nhi_exposure Non-human-identity credential exposure — API keys, service tokens, PATs $0.40 USDC
check_secret_scan Secrets exposed in public GitHub repositories $0.35 USDC

check_oauth_watchlist, check_supply_chain, check_session_risk, check_nhi_exposure, and check_secret_scan cover related ground — connected-app, session, and machine-credential exposure for an identity or its supply chain — and are a natural set to use together when vetting an agent's current authority, not just a login.

Access modes

Subscription — API key from api.relayshield.net/developers. All 15 tools available. Free tier: 100 calls/month. Paid tiers from $29/month.

Pay-as-you-go — No API key needed. Pay per check in USDC on Base (x402 protocol). Set RELAYSHIELD_X_PAYMENT with your payment proof. All 15 tools available ($0.05–$0.50/check, check_scan_result free). Call a tool with no payment set to receive pricing and payment instructions.

Discovery — Set neither key nor payment. Tool calls return payment requirements and a subscription link.

Install

pip install relayshield-mcp

Or run without installing:

uvx relayshield-mcp

Configure Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

Subscription (RelayShield API key):

{
  "mcpServers": {
    "relayshield": {
      "command": "relayshield-mcp",
      "env": {
        "RELAYSHIELD_API_URL": "https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod",
        "RELAYSHIELD_API_KEY": "your-relayshield-api-key-here"
      }
    }
  }
}

Pay-as-you-go (x402 USDC on Base):

{
  "mcpServers": {
    "relayshield": {
      "command": "relayshield-mcp",
      "env": {
        "RELAYSHIELD_API_URL": "https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod",
        "RELAYSHIELD_X_PAYMENT": "your-x402-payment-proof-here"
      }
    }
  }
}

Quit and relaunch Claude Desktop after editing.

Configure Claude Code (CLI)

claude mcp add relayshield \
  --command relayshield-mcp \
  --env RELAYSHIELD_API_URL=https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod \
  --env RELAYSHIELD_API_KEY=your-relayshield-api-key-here

Usage examples

Once configured, ask Claude:

Check whether user@example.com has been breached.
Has there been a SIM swap on +14155551234?
Check acme.com for lookalike domains.
Are any OAuth apps connected to user@example.com in a recent breach?
Scan this URL for malware: https://suspicious-link.example.com

For URL and file scans, Claude automatically polls check_scan_result every 5 seconds until the verdict is ready.

Environment variables

Variable Description
RELAYSHIELD_API_URL API Gateway base URL (required)
RELAYSHIELD_API_KEY RelayShield subscription key (subscription mode) — get one at api.relayshield.net/developers
RELAYSHIELD_X_PAYMENT x402 payment proof — USDC on Base (pay-as-you-go mode)

Set RELAYSHIELD_API_KEY or RELAYSHIELD_X_PAYMENT — not both. API key takes priority if both are set.

Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

relayshield_mcp-0.2.8.tar.gz (10.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

relayshield_mcp-0.2.8-py3-none-any.whl (10.9 kB view details)

Uploaded Python 3

File details

Details for the file relayshield_mcp-0.2.8.tar.gz.

File metadata

  • Download URL: relayshield_mcp-0.2.8.tar.gz
  • Upload date:
  • Size: 10.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for relayshield_mcp-0.2.8.tar.gz
Algorithm Hash digest
SHA256 981318a17096c8fa39dc38644aaef761f0b11f289fb74b6e929eea41ca58ee97
MD5 11946aa9c35525d7e3258fbcb70bf81f
BLAKE2b-256 3c9eacb3270ad2394f8d6e877b67b79e89b4f1dd00a987614fd7c2da125aae36

See more details on using hashes here.

Provenance

The following attestation bundles were made for relayshield_mcp-0.2.8.tar.gz:

Publisher: publish.yml on relayshield/relayshield-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file relayshield_mcp-0.2.8-py3-none-any.whl.

File metadata

File hashes

Hashes for relayshield_mcp-0.2.8-py3-none-any.whl
Algorithm Hash digest
SHA256 dbd27ea7401c18163386c0ed49f1d2c8e806dc9cf0317a8d355347bc1b182f7d
MD5 1e83bd063c36fae0f66f8cdaf1a99808
BLAKE2b-256 45b891ea45dc73b31f7325fd1f51b775bf9c2bdeae28a1655272ae48ed1b4593

See more details on using hashes here.

Provenance

The following attestation bundles were made for relayshield_mcp-0.2.8-py3-none-any.whl:

Publisher: publish.yml on relayshield/relayshield-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page