ThreatCluster
Rank #26,210io.github.Jam0k/threatcluster
Live threat intel for agents: incidents, actors, CVEs with KEV/EPSS, ransomware leak-site victims.
ThreatCluster is a Model Context Protocol (MCP) server published by Jam0k. It ranks #26,210 of 137,492 servers tracked on MCP Toplist, and its repository has 1 GitHub stars. ThreatCluster is listed across 2 registries — Official MCP and Glama, with 1 tracked version. It was first listed on Sep 26, 2026 and most recently updated on Sep 26, 2026.
Ranks ahead of 111,282 of 137,492 servers on MCP Toplist.
Use ThreatCluster
Requires user-supplied configuration before first use — typically an API key, token or connection string set via environment variables.
claude mcp add --transport http threatcluster https://threatcluster.io/mcpThis endpoint requires authentication — see the server’s docs for credentials.
claude mcp add threatcluster -e "THREATCLUSTER_API_KEY=<your THREATCLUSTER_API_KEY>" -e "THREATCLUSTER_API_BASE=<your THREATCLUSTER_API_BASE>" -- npx -y threatcluster-mcpReplace each placeholder with your own value before saving.
[mcp_servers.threatcluster]
url = "https://threatcluster.io/mcp"Add to ~/.codex/config.toml. This endpoint requires authentication — see the server’s docs for credentials.
[mcp_servers.threatcluster]
command = "npx"
args = ["-y", "threatcluster-mcp"]
[mcp_servers.threatcluster.env]
THREATCLUSTER_API_KEY = "<your THREATCLUSTER_API_KEY>"
THREATCLUSTER_API_BASE = "<your THREATCLUSTER_API_BASE>"Add to ~/.codex/config.toml. Replace each placeholder with your own value before saving.
https://threatcluster.io/mcpSettings → Connectors → “Add custom connector”, then paste this URL. This endpoint requires authentication — see the server’s docs for credentials.
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<your THREATCLUSTER_API_KEY>",
"THREATCLUSTER_API_BASE": "<your THREATCLUSTER_API_BASE>"
}
}
}
}Add to claude_desktop_config.json (Settings → Developer → Edit Config). Replace each placeholder with your own value before saving.
{
"mcpServers": {
"threatcluster": {
"url": "https://threatcluster.io/mcp"
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project). This endpoint requires authentication — see the server’s docs for credentials.
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<your THREATCLUSTER_API_KEY>",
"THREATCLUSTER_API_BASE": "<your THREATCLUSTER_API_BASE>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project). Replace each placeholder with your own value before saving.
{
"servers": {
"threatcluster": {
"type": "http",
"url": "https://threatcluster.io/mcp"
}
}
}Save as .vscode/mcp.json in your workspace. This endpoint requires authentication — see the server’s docs for credentials.
{
"servers": {
"threatcluster": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<your THREATCLUSTER_API_KEY>",
"THREATCLUSTER_API_BASE": "<your THREATCLUSTER_API_BASE>"
}
}
}
}Save as .vscode/mcp.json in your workspace. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"threatcluster": {
"serverUrl": "https://threatcluster.io/mcp"
}
}
}Add to ~/.codeium/windsurf/mcp_config.json. This endpoint requires authentication — see the server’s docs for credentials.
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<your THREATCLUSTER_API_KEY>",
"THREATCLUSTER_API_BASE": "<your THREATCLUSTER_API_BASE>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"threatcluster": {
"url": "https://threatcluster.io/mcp"
}
}
}This endpoint requires authentication — see the server’s docs for credentials.
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<your THREATCLUSTER_API_KEY>",
"THREATCLUSTER_API_BASE": "<your THREATCLUSTER_API_BASE>"
}
}
}
}Replace each placeholder with your own value before saving.
Show your rank
Maintain this server? Add the live rank badge to your README — it updates automatically as the leaderboard changes.
[](https://mcptoplist.com/server/io.github.Jam0k%2Fthreatcluster)<a href="https://mcptoplist.com/server/io.github.Jam0k%2Fthreatcluster"><img src="https://mcptoplist.com/badge/io.github.Jam0k%2Fthreatcluster.svg" alt="MCP Toplist: Top 25% of 137,492" /></a>Variants: append ?metric=score or ?metric=stars to the image URL.
Listed on 2 registries
Jam0k
Available versions (1)
| Version | Published |
|---|---|
| 0.2.3 | Sep 26, 2026 |
Frequently asked questions
- Who maintains ThreatCluster?
- ThreatCluster is maintained by Jam0k, which publishes 1 MCP server (1 total version) tracked on MCP Toplist.
- Is ThreatCluster listed on the Official MCP Registry?
- Yes — ThreatCluster is listed on the Official MCP Registry, alongside Glama.
- How many versions does ThreatCluster have?
- MCP Toplist tracks 1 version of ThreatCluster, most recently published on Sep 26, 2026.
- Where can I find the source code for ThreatCluster?
- The source code for ThreatCluster is hosted at github.com/Jam0k/Threat-Intelligence-MCP.
Do you run this server?
Community projects list the MCP servers behind real agents and apps. Publish yours and this page will link to it.