Enterprise DNA
M MCP Servers Developer low

ppcvote/misp-mcp-server

by Various

MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via prompt-defense-audit

P

MCP

ppcvote/misp-mcp-server

Added 7 June 2026

#ai-security #claude #cybersecurity #llm-security #mcp #misp #model-context-protocol #prompt-injection

Overview

A TypeScript-based MCP server that connects to MISP (Malware Information Sharing Platform) for threat intelligence operations. It includes built-in prompt injection defense via the prompt-defense-audit library.

Best for

Best for
Developers building AI agents that need to query MISP threat intelligence with added security against prompt injection

Use cases

  • Query MISP events and attributes from an MCP client
  • Automate threat intelligence workflows with MISP data
  • Integrate MISP into AI agent pipelines with injection protection

Notes

A TypeScript-based MCP server that connects to MISP (Malware Information Sharing Platform) for threat intelligence operations. It includes built-in prompt injection defense via the prompt-defense-audit library.

1 stars on GitHub. Last updated 2026-05-29. Licensed MIT.

Use cases

  • Query MISP events and attributes from an MCP client
  • Automate threat intelligence workflows with MISP data
  • Integrate MISP into AI agent pipelines with injection protection

Pros

  • Provides direct MISP access through the MCP protocol
  • Includes prompt injection defense for safer AI interactions
  • Written in TypeScript for type safety and maintainability

Cons

  • Very early stage with only 1 GitHub star
  • Limited community adoption and documentation
  • Requires a running MISP instance to be useful

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Provides direct MISP access through the MCP protocol
  • Includes prompt injection defense for safer AI interactions
  • Written in TypeScript for type safety and maintainability

Cons

  • Very early stage with only 1 GitHub star
  • Limited community adoption and documentation
  • Requires a running MISP instance to be useful