cywaremcp
One-click install for Cursor, VS Code, Claude, and 20+ other MCP clients, powered by API Commons MCP Install — visit install.apicommons.org for more information.
Documentation
Documentation link · transport
Tools
logged-in-user-details— Get details of the currently logged in Intel Exchange user.get-ctix-user-list— List Intel Exchange users.get-ctix-user-group-list— List Intel Exchange user groups.cql-ctix-grammar-rules— Return the Cyware Query Language (CQL) grammar rules used to build searches.get-cql-query-search-result— Run a CQL query against threat data and return the results.get-threat-data-object-details— Get the details of a threat data object.get-threat-data-object-relations— Get the relations of a threat data object.get-available-relation-type— Get the available threat data relationship types.threat-data-list-bulk-action-add-tag— Bulk add tags to threat data objects.threat-data-list-bulk-mark-indicator-allowed— Bulk mark indicators as allowed.threat-data-list-bulk-unmark-indicator-allowed— Bulk remove indicators from the allowed list.threat-data-list-bulk-manual-review— Bulk add threat data objects for manual review.threat-data-list-bulk-mark-false-positive— Bulk mark indicators as false positive.threat-data-list-bulk-unmark-false-positive— Bulk unmark indicators previously marked false positive.threat-data-list-bulk-update-analyst-tlp— Bulk update the analyst TLP of threat data objects.threat-data-list-bulk-update-analyst-score— Bulk update the analyst score of threat data objects.threat-data-list-bulk-deprecate— Bulk deprecate indicators.threat-data-list-bulk-undeprecate— Bulk undeprecate indicators.threat-data-list-bulk-add-watchlist— Bulk add threat data objects to the watchlist.threat-data-list-bulk-remove-watchlist— Bulk remove threat data objects from the watchlist.threat-data-list-bulk-add-relation— Bulk add a relation to threat data objects.create-tag-in-ctix— Create a new tag in Intel Exchange.get-ctix-tags-list— List the available Intel Exchange tags.get-enrichment-tools-list— List all configured enrichment tools.get-enrichment-tool-details— Get the details of an enrichment tool.get-enrichment-tool-action-configs— Get the action configuration of an enrichment tool.enrichment-tool-supported-for-threat-data-object— List the enrichment tools that support a given threat data object type.enrich-threat-data-object— Enrich a threat data object using a configured enrichment tool.quick-add-intel-create— Create intel in Intel Exchange through Quick Add Intel.get-co-playbooks-list— List the playbooks created in Orchestrate.get-co-playbook-details— Get the details of an Orchestrate playbook.execute-playbook-in-co— Run an Orchestrate playbook.get-co-apps-list— List the apps present in Orchestrate.get-co-app-details— Get the details of a specific Orchestrate app.get-co-actions-of-app— List the actions supported by an Orchestrate app.get-co-app-action-details— Get the details of an Orchestrate app action.get-instances-of-co-app— List the instances configured for an Orchestrate app.execute-action-of-co-app— Run an action of an Orchestrate app.convert-date-string-to-epoch— Utility - convert a dd-mm-yyyy-hh-min-sec date string to epoch.get-epoch-with-delta-from-now— Utility - return an epoch timestamp offset from now.
About MCP
The Model Context Protocol (MCP) is an open protocol Anthropic introduced for connecting LLM-based agents to external tools and data sources. Providers publish MCP servers that expose their API surface as structured, discoverable tools — an MCP-compatible client (Claude Desktop, Cursor, Cline, Continue, etc.) can connect to the server and call its tools without any per-provider integration code.
Browse every MCP server on the APIs.io network or compare with the broader Agent Skill surfaces of the same providers.
Work with this as data
Every MCP server here is available over the APIs.io API and to AI agents over MCP.