Public data intelligence for AI agents — CVE vulnerabilities, compliance records, patents, contracts, and domains.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 27 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The DataNexus MCP MCP server exposes 55 tools, focused primarily on web, network, and developer capabilities. Its published description reads: "Public data intelligence for AI agents — CVE vulnerabilities, compliance records, patents, contracts, and domains". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates DataNexus MCP F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check DataNexus MCP's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add DataNexus MCP to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://datanexusmcp.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Report a data quality issue or agent intent gap for a DataNexus tool response. tool_id: e.g. "T10" or "security_fetch_cve_detail". query_hash: From the query_hash field of the response. signal: incorr
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: report_feedback
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "feedback_type"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: report_feedback
A tool description tries to alter the model’s use of another tool.
e.g. "T10" or "security_fetch_cve_detail". query_hash: From the query_hash field of theRecommendationDescriptions must describe only their own tool.
tool: validate_tool_output
A tool description tries to alter the model’s use of another tool.
ta quality. Use report_feedback instead to manually report an issue you have alRecommendationDescriptions must describe only their own tool.
tool: search_datanexus_tools
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="searchRecommendationDescriptions must describe only their own tool.
tool: search_datanexus_tools
The text tells the model WHEN to call this tool relative to others ("always call first", "before any other tool", "chain to X tool") — a toxic-flow injection that hijacks the agent’s orchestration rather than describing the tool.
ects. Call this before any other DataNexus tool to reduce context load from 40000 to 800 tokensRecommendationTool metadata must describe only the tool, never sequence the agent’s calls.
tool: nonprofit_fetch_nonprofit_by_ein
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="nonproRecommendationDescriptions must describe only their own tool.
tool: nonprofit_search_nonprofits_by_name
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="nonproRecommendationDescriptions must describe only their own tool.
tool: nonprofit_fetch_charity_uk
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="nonproRecommendationDescriptions must describe only their own tool.
tool: security_fetch_package_vulnerabilities
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_dependency_graph
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_cve_detail
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_audit_sbom_vulnerabilities
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_package_licence
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_cisa_kev
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_cve_epss
A tool description tries to alter the model’s use of another tool.
nitor. Use with security_fetch_cve_detail to prioritize patching — EPSS measures urgency,RecommendationDescriptions must describe only their own tool.
tool: compliance_fetch_npi_provider
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
provider name, credential type, speciality taxonomy, practice address, anRecommendationRemove side-channel parameters; constrain tool inputs.
tool: compliance_fetch_npi_provider
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="compliRecommendationDescriptions must describe only their own tool.
tool: compliance_search_npi_by_name
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="compliRecommendationDescriptions must describe only their own tool.
tool: compliance_fetch_finra_broker
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="compliRecommendationDescriptions must describe only their own tool.
tool: compliance_check_sam_exclusion
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="compliRecommendationDescriptions must describe only their own tool.
tool: domain_fetch_domain_rdap
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="domainRecommendationDescriptions must describe only their own tool.
tool: domain_fetch_ssl_certificate_chain
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="domainRecommendationDescriptions must describe only their own tool.
tool: domain_fetch_dns_records
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="domainRecommendationDescriptions must describe only their own tool.
tool: domain_fetch_domain_history
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="domainRecommendationDescriptions must describe only their own tool.
tool: domain_fetch_subdomains
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="domainRecommendationDescriptions must describe only their own tool.
tool: domain_fetch_reverse_ip
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="domainRecommendationDescriptions must describe only their own tool.
tool: legal_fetch_patent_by_number
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="legal_RecommendationDescriptions must describe only their own tool.
tool: legal_search_patents_by_keyword
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="legal_RecommendationDescriptions must describe only their own tool.
tool: legal_fetch_patent_citations
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="legal_RecommendationDescriptions must describe only their own tool.
tool: legal_fetch_inventor_portfolio
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="legal_RecommendationDescriptions must describe only their own tool.
tool: govcon_search_contract_awards
A tool description tries to alter the model’s use of another tool.
ward dates. Use govcon_fetch_vendor_contract_history for all contracts by a specific vendor. Use govRecommendationDescriptions must describe only their own tool.
tool: govcon_fetch_vendor_contract_history
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="govconRecommendationDescriptions must describe only their own tool.
tool: govcon_fetch_open_solicitations
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="govconRecommendationDescriptions must describe only their own tool.
tool: regulatory_search_open_rulemakings
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="regulaRecommendationDescriptions must describe only their own tool.
tool: regulatory_fetch_docket_details
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="regulaRecommendationDescriptions must describe only their own tool.
tool: regulatory_fetch_federal_register_notices
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="regulaRecommendationDescriptions must describe only their own tool.
tool: security_fetch_package_maintainer_history
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_package_risk_brief
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_detect_typosquatting
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: nonprofit_fetch_nonprofit_full_profile
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="nonproRecommendationDescriptions must describe only their own tool.
tool: security_fetch_cve_watch
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_audit_sbom_continuous
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_licence_analysis
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_audit_licence_compatibility
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_cve_risk_summary
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: nonprofit_search_nonprofits_by_category
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="nonproRecommendationDescriptions must describe only their own tool.
tool: nonprofit_fetch_nonprofit_financial_trends
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="nonproRecommendationDescriptions must describe only their own tool.
tool: security_audit_sbom_license_policy
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: security_fetch_cve_watch_status
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="securiRecommendationDescriptions must describe only their own tool.
tool: frontend_security_detect_typosquatting
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="fronteRecommendationDescriptions must describe only their own tool.
tool: frontend_security_audit_manifest
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="fronteRecommendationDescriptions must describe only their own tool.
tool: frontend_security_audit_ci_pipeline
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="fronteRecommendationDescriptions must describe only their own tool.
tool: frontend_security_fetch_package_risk_brief
A tool description tries to alter the model’s use of another tool.
er's need, call report_feedback with feedback_type="agent_gap", tool_id="fronteRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
c data sources. Token-efficient. Verified sources. T04: US/UK nonprofRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
Use search_datanexus_tools first to find the right tool for your task. DatRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: search_datanexus_tools
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nonprofit_fetch_nonprofit_by_ein
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nonprofit_search_nonprofits_by_name
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nonprofit_fetch_charity_uk
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_package_vulnerabilities
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_dependency_graph
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_cve_detail
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_audit_sbom_vulnerabilities
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_package_licence
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_cisa_kev
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_cve_epss
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: compliance_fetch_npi_provider
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: compliance_search_npi_by_name
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: compliance_fetch_finra_broker
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: compliance_check_sam_exclusion
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_fetch_domain_rdap
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_fetch_domain_rdap
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
example.com not https://example.com. Required. Returns registrar, registration date,RecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: domain_fetch_ssl_certificate_chain
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_fetch_dns_records
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_fetch_domain_history
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_fetch_subdomains
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_check_email_security
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: domain_fetch_reverse_ip
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: legal_fetch_patent_by_number
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: legal_search_patents_by_keyword
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: legal_fetch_patent_citations
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: legal_fetch_inventor_portfolio
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: govcon_search_contract_awards
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: govcon_fetch_vendor_contract_history
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: govcon_fetch_open_solicitations
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: regulatory_search_open_rulemakings
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: regulatory_fetch_docket_details
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: regulatory_fetch_federal_register_notices
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_package_maintainer_history
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_package_risk_brief
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_detect_typosquatting
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nonprofit_fetch_nonprofit_full_profile
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_cve_watch
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: security_audit_sbom_continuous
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_licence_analysis
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_audit_licence_compatibility
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_cve_risk_summary
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nonprofit_search_nonprofits_by_category
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: nonprofit_fetch_nonprofit_financial_trends
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: apikeys_rotate_api_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: apikeys_revoke_api_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: security_audit_sbom_license_policy
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: security_fetch_cve_watch_status
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: frontend_security_detect_typosquatting
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: frontend_security_audit_manifest
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: frontend_security_audit_ci_pipeline
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: frontend_security_fetch_package_risk_brief
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Check MCPize subscription status for a DataNexus tool. tool_id: DataNexus tool identifier e.g. "T10". Pass the tool the user is asking about. Returns: status ("free" | "subscription_required" | "not_c
Validate a DataNexus tool response for data quality issues using two-layer validation: deterministic rules first, then AI review for ambiguous cases. Read-only. Never blocks. tool_id: DataNexus tool i
Find the right DataNexus tool by describing your task in plain English. Read-only. No side effects. Call this before any other DataNexus tool to reduce context load from 40000 to 800 tokens. query: Pl
Fetch IRS 990 filing data for any US nonprofit by EIN. Read-only. No side effects. Idempotent. US only. ein: 9-digit Employer ID with or without dash, e.g. 46-5734087 or 465734087. Required. Returns n
Search US nonprofits by name with optional state filter. Read-only. No side effects. Idempotent. US only. Returns up to 25 matches. name: Full or partial organisation name. Required. state: Two-letter
Fetch UK registered charity details by charity number or organisation name. Read-only. No side effects. Idempotent. UK only. charity_number_or_name: UK registered charity number (7 digits, e.g. 123456
Fetch all known CVEs for an open source package version or a batch of packages. Read-only. No side effects. Idempotent. Single-package mode: package (e.g. requests), version (e.g. 2.28.0), ecosystem (
Fetch the full dependency tree for a package version including transitive dependencies. Read-only. No side effects. Idempotent. Hard 8-second timeout — large dependency trees may return partial result
Fetch full detail for a specific CVE by ID. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format CVE-YYYY-NNNNN e.g. CVE-2021-44228. Required. Returns description, CVSS base score,
Audit a Software Bill of Materials for known vulnerabilities across all listed packages. Read-only. No side effects. Idempotent. sbom_json: CycloneDX or SPDX SBOM as a JSON string. Required. Large SBO
Fetch the SPDX licence identifier for an open source package version. Read-only. No side effects. Idempotent. package: Package name e.g. flask. Required. version: Exact version string e.g. 2.3.0. Requ
Check whether a CVE is in the CISA Known Exploited Vulnerabilities (KEV) catalog. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format CVE-YYYY-NNNNN e.g. CVE-2021-44228. Required.
EPSS exploit probability score for a CVE — predicts likelihood of exploitation in the next 30 days. cve_id: CVE identifier e.g. "CVE-2021-44228". Returns: epss (float 0.0–1.0) and percentile (float 0.
Fetch NPI registration details for a US healthcare provider by NPI number. Read-only. No side effects. Idempotent. US only. npi_number: 10-digit NPI number e.g. 1003000126. Required. Do not include da
Search the NPPES NPI Registry by provider name with optional state and speciality filters. Read-only. No side effects. Idempotent. US only. Returns up to 10 matches. name: Full or partial provider nam
Fetch FINRA BrokerCheck registration for a US broker or investment adviser by CRD number. Read-only. No side effects. Idempotent. US only. crd_number: Central Registration Depository number as a strin
Check whether an entity is on the US federal exclusions list (debarred from government contracts). Read-only. No side effects. Idempotent. US only. name_or_ein: Entity name or 9-digit EIN with or with
Fetch domain registration details via IANA RDAP (the modern structured replacement for WHOIS). Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. example.com not https:/
Fetch SSL certificate history for a domain from Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. github.com. Required. Does not support
Fetch current DNS records for a domain via Cloudflare DNS over HTTPS. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. cloudflare.com. Required. record_types: List of
Fetch historical SSL certificate issuance for a domain from Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. example.com. Required. Retu
Enumerate subdomains for a domain via Certificate Transparency logs. Read-only. No side effects. Idempotent. domain: Domain name without protocol e.g. anthropic.com. Required. Returns deduplicated lis
Check SPF, DMARC, and DKIM email authentication for a domain. domain: Domain without protocol e.g. "google.com". Returns: overall_grade (A–F), spf_score, dmarc_score, dkim_score (each 0–10), spf_recor
Find domains co-hosted on the same IP address (reverse IP lookup). Read-only. No side effects. Idempotent. domain_or_ip: Domain name (e.g. shared.dreamhost.com) or IPv4 address (e.g. 1.2.3.4). Require
Fetch full patent details by patent number and jurisdiction. Read-only. No side effects. Idempotent. patent_number: Patent number in EPODOC format e.g. EP1000000 for European, CN120586032 for Chinese,
Search patents by keyword across EPO, USPTO, or WIPO. Read-only. No side effects. Idempotent. Returns up to 10 matches. keywords: Search terms describing the invention e.g. neural network image classi
Fetch forward and backward citation chains for a specific patent. Read-only. No side effects. Idempotent. patent_number: Patent number in EPODOC format e.g. EP1000000 for European, CN120586032 for Chi
Fetch the patent portfolio for a named inventor with optional assignee filter. Read-only. No side effects. Idempotent. inventor_name: Inventor surname or full name e.g. Smith or John Smith. Required.
Search government contract awards by keyword, agency, and date range. keyword: Contract scope e.g. "cybersecurity software". agency: Awarding agency e.g. "Department of Defense". Optional. date_from:
Fetch the complete federal contract award history for a specific vendor. Read-only. No side effects. Idempotent. vendor_name: Company or organisation name e.g. Booz Allen Hamilton. Required. Fuzzy mat
Fetch currently open government contract solicitations matching a keyword. Read-only. No side effects. Idempotent. keyword: Description of goods or services sought e.g. cloud computing services. Requi
Search open rulemakings and public comment periods on Regulations.gov and the Federal Register. Read-only. No side effects. Idempotent. US federal only. keyword: Topic keywords e.g. artificial intelli
Fetch full details for a specific regulatory docket by ID. Read-only. No side effects. Idempotent. US federal only. docket_id: Docket identifier in agency format e.g. EPA-HQ-OAR-2021-0317 or FTC-2024-
Fetch recent Federal Register notices and rules for a specific agency. Read-only. No side effects. Idempotent. US federal only. agency: Agency name or abbreviation e.g. SEC, Food and Drug Administrati
Analyse ownership and release history for an npm or PyPI package to detect supply-chain risk. Uses PyPI JSON API and npm registry — data refreshed on each call, 1-hour cache. Returns maintainer_count,
Single SHIP/CAUTION/BLOCK verdict for any package. Combines CVEs, licence, maintainer health, and transitive count in one call. Uses OSV.dev, deps.dev, PyPI, and npm registry — data refreshed on each
Detect typosquatting attacks against a package name. Compares using Damerau-Levenshtein distance ≤ 2 against top-10,000 packages. Returns similar_packages with anomaly scores, and a SUSPICIOUS or CLEA
Complete nonprofit due diligence in one call. Revenue trends, executive pay, risk flags, and a health score from IRS 990 data. Uses ProPublica Nonprofit Explorer API with IRS e-File fallback. Data ref
Persistent CVE watchlist. Create once, check anytime for new events since your last visit — patch releases, KEV listings, PoC publications, exploitation detected. Uses Redis for persistence, NVD + CIS
Persistent SBOM watch. Register once, check anytime for new CVEs affecting your dependency snapshot. Silent permanent watch — CycloneDX and SPDX supported. Uses OSV.dev for vulnerability lookup, Redis
Understand any software licence in plain English. Returns obligations, permissions, limitations, risk level, and OSI/FSF status for any SPDX licence identifier. Static bundle covers top-50 common lice
Audit the licence compatibility of your entire dependency list. Input package names (with ecosystem) or SPDX IDs; get a COMPATIBLE/CONFLICT verdict with specific conflicting pairs and recommended acti
Instant CVE risk verdict. Combines CVSS severity, CISA KEV exploitation status, and EPSS probability in one parallel call. Returns CRITICAL_EXPLOIT, HIGH_RISK, MODERATE, LOW, or UNKNOWN verdict with p
Search US nonprofits by mission category and state. Returns up to 25 results with revenue, assets, and health scores (0–100). Category maps to NTEE codes: education, healthcare, arts, environment, hum
5-year financial trend for any US nonprofit. Revenue growth, expense ratios, reserve trajectory, and health score history from IRS Form 990 data via ProPublica. Returns trend_direction (GROWING/STABLE
Generate a DataNexus API key for the given email address. Anonymous callers get 10 free lookups/week; a registered free key unlocks 100/week. Store the returned key — it is shown only once. Pass it as
⚠️ DESTRUCTIVE — requires human confirmation before use in automated pipelines. Revoke the current API key and issue a replacement. Returns the new key once — store it immediately. Pass keys as the X-
⚠️ DESTRUCTIVE — requires human confirmation before use in automated pipelines. Permanently revoke a DataNexus API key. The key will stop working immediately. This action cannot be undone — generate a
Audit a CycloneDX or SPDX SBOM against an SPDX licence policy and return a PASS/WARN/BLOCK verdict. sbom: Full SBOM as a JSON string — CycloneDX or SPDX format. Required. 500 KB max. policy: Optional
Check all specified CVE watches for new events since your last poll. Returns only watches with new events, making it efficient to run on a schedule. watch_ids: List of watch IDs to check — same IDs us
Typosquatting detection optimised for the top 500 frontend packages (React, Vite, Axios, Lodash, etc.). Fewer false positives than a full npm scan. For backend packages, use security_detect_typosquatt
Audit a frontend package.json for security risks — returns a single SHIP/CAUTION/BLOCK verdict with licence risks and abandonment signals. Different from security_fetch_package_vulnerabilities which a
Scan GitHub Actions, Vercel, or Netlify CI configs for exposed secrets, missing lockfile enforcement, and unpinned dependencies. Paste your config content — no filesystem access required. config: Raw
SHIP/CAUTION/BLOCK risk brief for an npm package with frontend-specific context. Wraps security_fetch_package_risk_brief restricted to npm, and adds weekly_downloads and is_ui_component signals. packa