MCP 攻击链研究——阶段一(身份≠行为)
v1.1.0
dev.gtfo/mcp-killchain-stage1-weather
安全研究:MCP 注册表只校验身份,不校验工具行为,详情见 gtfo.dev。
“Weather Query” 共 1,050 个结果
v1.1.0
dev.gtfo/mcp-killchain-stage1-weather
安全研究:MCP 注册表只校验身份,不校验工具行为,详情见 gtfo.dev。
v0.1.3
io.github.AIweather-Anurag/ottasia
某部作品在某地哪里能看?覆盖 30 个亚洲与中东流媒体市场,可通过 Claude 查询。
v2.0.0
com.queryomega/omega
从任意 MCP 客户端查询、浏览并自动化 OmegaAI 工作区,支持 OAuth 2.0 的 Streamable HTTP。
v1.0.0
com.exoquery/mcp-server
Kotlin 编译期 SQL 库,提供文档、代码校验与 SQLite 执行工具。
io.smithery.theagenttimes.news
智能体行动前使用的情报层,给出关于智能体经济的、有出处支撑的回答。检索经过验证的 AI 新闻,附引用、置信度与伦理引擎评分;任何关于 AI 智能体工具、MCP 或框架的问题都可替代通用网页搜索。每条结果都带引用、置信度与伦理引擎评分,专为智能体在推荐工具、安装 MCP 服务器或采取行动前核验证据而构建。
io.smithery.jordan-s648.PolymarketScan
Real-time Polymarket analytics for AI agents. Query live prediction market data including whale trades, market odds, trader profiles, and leaderboards. **Available tools:** - `get_whale_trades` — large trades above a size threshold - `get_market_odds` — current prices and implied probability for any market - `get_trader_profile` — PnL, win rate, ROI for any wallet - `get_leaderboard` — top traders ranked by PnL, ROI, or win rate - `get_market_summary` — AI-citable summary paragraph for any market - `search_markets` — full-text search across all active markets - `get_market_movers` — biggest price movements in the last 24 hours - `get_site_stats` — aggregate platform statistics No API key required. Data provided by PolymarketScan (polymarketscan.org).
io.smithery.support-9ef4.Wayforth
面向 AI 智能体的 API 运行时。 一次工具调用,接入任意 API,无需配置。 在 4,974 个经过验证的 API 中检索,按 WayforthRank 排序——唯一基于真实智能体支付信号而非广告的排名算法。通过 18 项托管服务执行调用,完全不需要 API key。具备自愈能力:某个服务失败时额度自动退回。 你的智能体可以: 按意图在 19 个类目中检索 4,974 个 API 执行:推理、翻译、图像生成、语音转文字、网页搜索、金融数据、天气、新闻等 为任意服务自带 API key(BYOK) 通过 x402 按次付费,每次 0.002 USDC 用 WayforthQL 查询:可按档位、价格、协议、延迟过滤 三种支付通道:银行卡 · Base 上的 USDC · x402 免费开始:100 次调用,无需绑卡 uvx wayforth-mcp · wayforth.io
io.smithery.cyanheads.census-mcp-server
通过 MCP 查询美国人口普查局的数据、变量与地理信息。
io.smithery.axel-belfort.dns-lookup
面向 AI 智能体的 DNS 记录查询 API。通过 Cloudflare DNS-over-HTTPS 查询 A、AAAA、MX、TXT、CNAME、NS、SOA 和 SRV 记录。查询快速、可靠且保护隐私。 工具:network_lookup_dns。 适合域名验证、邮件配置排障、基础设施分析或监控 DNS 变更。重要:若要完整的域名情报(WHOIS + DNS + SSL),请使用 domain_lookup_intelligence。 返回:{records[], type, ttl}。无需 API key——在 Base L2 上以 x402 微支付,每次 0.002 美元。
io.smithery.cyanheads.openfda-mcp-server
通过 openFDA 查询药品、食品、器械与召回数据,支持 STDIO 与 Streamable HTTP。
io.smithery.etweisberg.mlb-mcp
通过 MCP 服务器结构化访问美国职业棒球大联盟(MLB)统计。查询并获取详细棒球数据,包括 Statcast、FanGraphs 和 Baseball Reference 的统计。生成可视化,并与兼容 MCP 的客户端顺畅集成,强化棒球分析能力。
io.smithery.hello-oipe.Geppetto-Robot-Directory
查询全球机器人目录——30 个类目、319 个品牌共 812 款机器人。工具:search_robots(按类目、品牌、价格、用途检索)、get_robot 与 get_robot_full(完整规格)、compare_robots(并排差异对比)、get_category,以及 get_job_automation_risk(240 多种职业的机器人替代风险评分——别处拿不到的数据)。全部为公开读取,无需鉴权。
io.smithery.spacepacket.e3d-ai
Blockchain analytics and AI agent platform for Ethereum. Query live token prices, on-chain stories, investment theses, and the E3D autonomous agent system — all backed by real-time indexed data. **Works anonymously** at the free tier (100 req/day). Add an API key from [e3d.ai/api](https://e3d.ai/api) for higher rate limits. **Tools include:** - Token prices, gainers/losers across 30m / 1h / 24h / 7d / 30d - On-chain stories and structured investment theses - Token and wallet identity, counterparty flow analysis - AI agent status, executions, burn history, next actions
io.smithery.a7om.atom-mcp-server
ATOM is the Global Price Benchmark for AI Inference, delivered as a native tool for AI agents. Query live pricing across the inference market through the AIPI (ATOM Inference Price Index) family of benchmarks. Search models, compare cross-vendor pricing, and access market intelligence. Independent and transparent. Free tier included, no API key needed.
io.smithery.kennyckk.mcp_hkbus
查询香港九巴与龙运巴士的实时到站信息和完整线路详情。轻松检索公交线路、站点和预计到达时间,改善出行体验。支持英文与繁体中文双语,覆盖更广泛的用户。
io.smithery.blackboxfoundry.livedatalink
已索引的公开记录超过 200 万条,统一在一个 MCP 端点。LiveDataLink 是托管的 Streamable HTTP MCP,提供带来源链接的公开数据,覆盖 60 个领域、共 294 个工具。可查询政府、监管、金融、交通、制裁/KYB、法院、不动产、健康、能源以及跨源证据数据。使用 list_tool_groups 与 groups URL 参数可只暴露所需的工具子集。端点:https://livedatalink.ai/mcp。API key 鉴权使用 Authorization: Bearer YOUR_API_KEY;也提供限额内的匿名评估。免费档:每月 1,000 次查询,无需绑卡。Starter:每月 10 美元 5,000 次查询。Pro:每月 49 美元 50,000 次查询。均为每月硬上限,不自动超额扣费。来源覆盖与数据新鲜度各有差异,部分工具需要上游凭据。结果支持复核,但不保证合规。覆盖证据:https://github.com/blackboxfoundry/livedatalink/blob/main/COVERAGE.md。接入说明:https://github.com/blackboxfoundry/livedatalink/blob/main/CLIENTS.md。
io.smithery.vdineshk.dominion-observatory
Behavioral trust scoring and MCP gateway proxy for 14,820+ MCP servers. Query real attestation data — interaction history, success rates, latency, uptime — before your agent executes sensitive operations. **8 tools** for trust evaluation, server discovery, and health monitoring: - `get-trust-score` — instant trust score (0-100) for any MCP server - `query-server` — full behavioral profile with attestation evidence - `list-servers` — browse the entire 14,820+ server directory - `get-leaderboard` — top-ranked servers by trust score - `check-health` — real-time uptime and latency checks - `get-compliance-report` — MiCA Article 12 compliance attestation receipts - `report-outcome` — report tool call outcomes to improve trust data - `get-baselines` — historical behavioral baselines **MCP Gateway Proxy**: Route agent calls through Observatory for automatic trust verification and compliance attestation. Every proxied call gets a trust check + signed attestation receipt. **Use cases**: Agent-to-agent commerce trus
io.smithery.cyanheads.fema-mcp-server
查询 FEMA 灾害宣告、公共援助拨款、住房救助与 NFIP 理赔。
io.smithery.cyanheads.imf-mcp-server
Query IMF SDMX 3.0 macroeconomic data — 193 dataflows, WEO, BOP, CPI, exchange rates, 190 countries.
io.smithery.node2flow.gemini-file-search-rag
Google 的 Gemini File Search 与 RAG(检索增强生成)MCP 服务器。 ## 特性 - 创建与管理 File Search 存储库 - 上传文档(文本、PDF、base64),支持自定义元数据与分块配置 - 把已有的 Gemini 文件导入存储库 - 跟踪上传/操作状态 - 用 RAG 查询文档,可选择模型并按元数据过滤 ## 12 个工具 **存储库管理**:创建、列出、获取、删除存储库 **上传与导入**:直接上传内容或导入已有文件 **操作**:查看存储库/上传操作状态 **文档**:列出、获取、删除存储库中的文档 **RAG 查询**:用 Gemini 模型查询文档(支持元数据过滤) ## 配置 - GEMINI_API_KEY——在 https://aistudio.google.com/apikey 申请
v0.15.11
io.github.cyanheads/secedgar-mcp-server
通过 MCP 查询 SEC EDGAR 申报文件、XBRL 财务数据与公司信息,支持 STDIO 与 Streamable HTTP。
v0.3.0
io.github.cyanheads/usgs-water-mcp-server
查询约 8,000 个水文站与地下水井的 USGS 实时及历史水文数据。
v0.2.0
io.github.cyanheads/treasury-fiscaldata-mcp-server
通过 MCP 查询美国国债、利率、汇率及财政数据集。
v0.3.2
io.github.cyanheads/fema-mcp-server
查询 FEMA 灾害宣告、公共援助拨款、住房救助与 NFIP 理赔。