
Nullcone Threat Intelligence
Feed agents real-time IOC and AI-specific threat intelligence—including prompt-injection signals—before you ship agent features to users.
Overview
Nullcone is a Ship-phase MCP server that delivers real-time threat intelligence with 890K+ IOCs for AI agents, including prompt-injection and skill threats.
What is this MCP server?
- Nullcone Threat Intelligence remote MCP at https://nullcone.ai/mcp
- Catalog cites 890K+ IOCs including prompt-injection and AI-skill threats
- streamable-http transport (v0.1.0) with website nullcone.ai
- GitHub source maco144/nullcone-mcp for implementation reference
- Focused on AI agent threat context, not generic enterprise SIEM dashboards
- Publisher cites 890K+ IOCs in the server description
- Remote endpoint https://nullcone.ai/mcp (streamable-http)
- Server manifest version 0.1.0; repository nullcone-mcp on GitHub
What problem does it solve?
Agent builders launch features blind to fast-moving prompt-injection and malicious-skill IOCs because local repos lack a live intel feed.
Who is it for?
Solo builders hardening Claude/Cursor agents and custom skills who want a zero-install remote TI MCP endpoint.
Skip if: Teams needing on-prem-only intel with air-gapped policies or full SOC case management in one tool.
What do I get? / Deliverables
After adding the remote MCP, agents can query Nullcone for relevant IOCs and AI-centric threats during pre-ship security checks.
- Live IOC and AI-threat queries via hosted MCP
- Access to catalog-described 890K+ indicator corpus scope
- Prompt-injection and AI-skill-oriented intelligence context for agents
Recommended MCP Servers
Journey fit
How it compares
AI-focused threat-intel MCP feed, not a code-review skill or dependency audit marketplace.
Common Questions / FAQ
Who is nullcone for?
Indie and solo builders shipping AI agents or skills who need prompt-injection and IOC context inside their MCP toolchain.
When should I use nullcone?
Use it in Ship security passes when validating agent inputs, skill sources, and external payloads against live threat data.
How do I add nullcone to my agent?
Register the remote MCP URL https://nullcone.ai/mcp (streamable-http) in your client; no local package is listed in the server manifest.