spidersilk-threats-mcp
v1.0.0
Published
SpiderSilk Threats MCP Server - Full-parameter access to the SpiderSilk threats API
Maintainers
Readme
spidersilk-threats-mcp
MCP server for the SpiderSilk Threats API. Provides full-parameter access to the /threats endpoint with features not available in the general resonance-mcp-server package:
- Status filtering — e.g.
status=8for "reported to entity" updated_sinceon threats — not just darkweb_credentialssort_by=updated_at— not restricted to title/created_at/severity- Auto-pagination — fetch all matching threats across pages
- Grouping — group threats by company_name and severity
Quick Start
API_KEY=sk-g-... npx -y spidersilk-threats-mcpConfiguration
| Environment Variable | Required | Default | Description |
|---------------------|----------|---------|-------------|
| API_KEY | Yes | — | SpiderSilk API key |
| BASE_URL | No | https://api.spidersilk.com/client/v1 | API base URL |
| MCP_TRANSPORT | No | stdio | Transport: stdio or http |
| MCP_HOST | No | 0.0.0.0 | HTTP host (when transport=http) |
| MCP_PORT | No | 8000 | HTTP port (when transport=http) |
MCP Tool
Exposes a single tool spidersilk_threats with three operations:
threats — List threats
{
"operation": "threats",
"page": 1,
"limit": 100,
"sort_by": "updated_at",
"sort_type": "desc",
"status": 8,
"updated_since_hours": 24,
"auto_paginate": false,
"max_pages": 10
}threat — Get single threat
{
"operation": "threat",
"uuid": "threat-uuid-here"
}threats_grouped — Group by company and severity
{
"operation": "threats_grouped",
"status": 8,
"updated_since_hours": 1,
"max_pages": 50
}MCPHub Configuration
{
"spidersilk-threats": {
"command": "npx",
"args": ["-y", "spidersilk-threats-mcp"],
"env": {
"API_KEY": "sk-g-..."
}
}
}Requirements
- Node.js >= 18.0.0
- Python 3.10+ (automatically creates venv and installs dependencies on first run)
License
MIT
