Enterprise DNA Enterprise DNA
M MCP Servers Developer low

ppcvote/misp-mcp-server

by Various

MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via prompt-defense-audit

MCP

ppcvote/misp-mcp-server

Added 7 June 2026

#ai-security #claude #cybersecurity #llm-security #mcp #misp #model-context-protocol #prompt-injection

Overview

A TypeScript-based MCP server that connects to MISP (Malware Information Sharing Platform) for threat intelligence operations. It includes built-in prompt injection defense via the prompt-defense-audit library.

Best for

Best for
Developers building AI agents that need to query MISP threat intelligence with added security against prompt injection

Use cases

  • Query MISP events and attributes from an MCP client
  • Automate threat intelligence workflows with MISP data
  • Integrate MISP into AI agent pipelines with injection protection

How to use

Install

npm install -g @ultralab/misp-mcp-server

Tools exposed

  • misp_version
  • misp_list_events
  • misp_get_event
  • misp_search_events
  • misp_search_attributes
  • misp_list_tags
  • misp_list_feeds
  • misp_list_galaxies
  • MISP_URL
  • MISP_API_KEY
  • MISP_INSECURE_TLS
  • PROMPT_DEFENSE_DISABLED

Tested with

Claude Desktop, Cursor, Cline, Continue

Notes

A TypeScript-based MCP server that connects to MISP (Malware Information Sharing Platform) for threat intelligence operations. It includes built-in prompt injection defense via the prompt-defense-audit library.

1 stars on GitHub. Last updated 2026-05-29. Licensed MIT.

Use cases

  • Query MISP events and attributes from an MCP client
  • Automate threat intelligence workflows with MISP data
  • Integrate MISP into AI agent pipelines with injection protection

Pros

  • Provides direct MISP access through the MCP protocol
  • Includes prompt injection defense for safer AI interactions
  • Written in TypeScript for type safety and maintainability

Cons

  • Very early stage with only 1 GitHub star
  • Limited community adoption and documentation
  • Requires a running MISP instance to be useful

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Provides direct MISP access through the MCP protocol
  • Includes prompt injection defense for safer AI interactions
  • Written in TypeScript for type safety and maintainability

Cons

  • Very early stage with only 1 GitHub star
  • Limited community adoption and documentation
  • Requires a running MISP instance to be useful
Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks