Agent Skills

mlab.sh

Threat intelligence: enrich IOCs (IP, domain, URL, hash), search CVEs and actors, scan SBOMs

Install

Install and configure the MCP from https://doc.mlab.sh/docs/mlab.sh/integrations/mcp now. Follow the documentation's installation instructions, ask me for anything you can't complete yourself, and verify its tools load.
README

mlab docs

Search⌘``K

Documentation Overview

Getting Started

Verify Your Infrastructure API Guide

Scans & Lookups

Unified Search Domain intelligence File analysis & content inspection Email (EML) Analysis Crypto Address Lookup MAC Address Lookup Email Lookup Phone Number Lookup Custom Scan

Developer API

API Reference

Integrations

Overview MCP Integration n8n Integration GitHub Action VS Code Extension Browser Extension

Tools

Mitre Coverage Map YARA Rule Builder RedKit · Infrastructure Scanner

Support

Troubleshooting Get in touch Become a Partner

GitHub

MCP Integration

Connect Claude and other AI assistants to mlab.sh through the Model Context Protocol server.

Copy MarkdownOpen

mlab.sh exposes a Model Context Protocol (MCP) server that lets Claude and other AI assistants query threat intelligence, run scans, and manage your account directly from a conversation.

Official support: Claude only. This MCP integration has been tested and is officially supported on Claude (claude.ai web and Claude Desktop). Other MCP-compatible clients may work but are neither tested nor guaranteed - use them at your own discretion and expect no dedicated support for third-party clients.

Endpoint and transports

The MCP server is available at a single URL and supports two transports:

  • Streamable HTTP - POST https://mlab.sh/mcp
  • SSE - GET https://mlab.sh/mcp

Authentication: All requests require a Bearer token in the Authorization header. Tokens start with mcp_ and can be created in Account → Settings → MCP Tokens or via OAuth from any compatible AI client (e.g. Claude.ai).

Claude.ai web connector (recommended)

Claude.ai supports remote MCP connectors via OAuth 2.0. No token to copy - authorization is handled automatically.

Open Claude.ai → Settings → Integrations → Add connector (or the connector icon in the chat input bar).

Enter the MCP server URL:

https://mlab.sh/mcp

Claude.ai will redirect you to mlab.sh to authorize the connection. Click Authorize - done.

Claude Desktop (local)

Claude Desktop uses a stdio bridge (mcp-remote) to connect to remote HTTP servers. Requires Node.js.

Create an MCP token in Account → Settings → MCP Tokens.

Open your Claude Desktop config file:

# macOS
~/Library/Application Support/Claude/claude_desktop_config.json

# Windows
%APPDATA%\Claude\claude_desktop_config.json

Add the following entry (replace mcp_xxx with your token):

{
  "mcpServers": {
    "mlab": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://mlab.sh/mcp",
        "--header",
        "Authorization: Bearer mcp_xxx"
      ]
    }
  }
}

Restart Claude Desktop. The mlab tools will appear in the tool picker.

Available tools

ToolDescriptionParameters
detect_iocAuto-detect IOC type and enrich IPs with geolocation & reputationvalue
scan_ipLook up an IPv4 or IPv6 address, or a CIDR range. Geolocation, ISP, ASN, network type, TOR status, reverse DNS with forward confirmation, and the RDAP allocation with its abuse contactip
start_domain_scanLaunch a domain scan (returns cached results instantly if available)domain
get_domain_scan_resultsPoll scan results - DNS, subdomains, SSL, security.txt, robots.txtdomain
get_scan_historyRecent scan history, optionally filtered by typetype? limit?
get_bookmarksList saved bookmarks (IPs, domains, hashes)limit?
add_bookmarkSave an IOC to bookmarksvalue
remove_bookmarkRemove an IOC from bookmarksvalue
scan_cryptoLook up a blockchain address - labels, sanctions, risk score. 18 chains, all reachable. Pass chain for an EVM address: it cannot be derived, and a wrong guess loses every labeladdress chain?
cve_searchSearch CVEs by keyword, product, vendor or CVE ID. Returns CVSS score, severity, EPSS probability, KEV status and affected productsquery severity? date_start? date_end? limit? page?
cve_detailFull record for a single CVE - CVSS vector breakdown, CWE weaknesses, references, EPSS exploitation probability and CISA KEV datescve_id
search_actorsSearch threat actors by name or alias - optional filters on origin, incident type and targeted sector. MISP Galaxy data onlyquery origin? motivation? sector? limit?
get_actorProfile of a threat actor from MISP Galaxy (description, origin, state sponsor, synonyms, targeted countries & sectors, references) plus its MITRE ATT&CK tools and techniques. Keep the sources block when quotingslug
get_scan_limitsRemaining daily quotas for IP, domain, file and crypto scans-
get_account_infoCurrent user, organization and subscription plan-

Token management

MCP tokens are personal and scoped to your user account: they act as you, with your organization role, and are not affected by API key permissions, which apply to organization API keys only. You can create up to 5 active tokens, or 100 on the Team and Enterprise plans. Tokens can be revoked at any time from Account → Settings.

Tokens issued via OAuth (e.g. from Claude.ai) are also listed there, labeled OAuth: <client name>.

Overview Ways to plug mlab.sh into your stack - AI assistants, automation platforms, CI/CD, your editor and your browser. n8n Integration Automate mlab.sh scanning, CVE intelligence and threat-actor data from your n8n workflows with the official community node package.

On this page

Endpoint and transports Claude.ai web connector (recommended) Claude Desktop (local) Available tools Token management

[{"@context":"https://schema.org","@type":"Organization","name":"mlab","url":"https://mlab.sh","logo":"https://doc.mlab.sh/logo.png"},{"@context":"https://schema.org","@type":"WebSite","name":"mlab documentation","url":"https://doc.mlab.sh","description":"Documentation for the entire mlab stack - core platform, API, dashboard, CLI, SDKs and infrastructure."}]

Search skills and MCP servers

Search across 31,816 skills and MCPs