{
  "serverInfo": {
    "name": "tweetfeed-mcp",
    "version": "0.1.0",
    "description": "MCP server exposing the public TweetFeed IOC feed (URLs, domains, IPs, MD5/SHA-256 hashes shared by the infosec community on Twitter/X) as agent tools."
  },
  "transport": {
    "type": "streamable-http",
    "endpoint": "https://mcp.tweetfeed.live/"
  },
  "capabilities": {
    "tools": {}
  },
  "protocolVersion": "2025-11-25",
  "license": "CC0-1.0 (data); MIT (server source)",
  "source": "https://github.com/0xDanielLopez/tweetfeed-mcp",
  "documentation": "https://tweetfeed.live/agents/",
  "tools": [
    {
      "name": "query_iocs",
      "description": "Query the TweetFeed API for Indicators of Compromise (IOCs: URLs, domains, IPs, MD5/SHA256 hashes) shared by the infosec community on Twitter/X. Returns matching rows with date, researcher handle, type, value, tags, and tweet URL. All data CC0 licensed. The 'year' time window is not supported here (too large for a tool response) - use the /v1/year HTTP redirect directly if you need it."
    },
    {
      "name": "check_url",
      "description": "Check whether a URL (or substring) appears in the TweetFeed corpus over the past 30 days. Useful for confirming if an observed URL has been flagged by the public infosec Twitter/X community. Case-insensitive substring match against the 'value' field of type=url IOCs. Returns matching rows with date, researcher handle, value, tags, and source tweet URL."
    },
    {
      "name": "check_ip",
      "description": "Check whether an IP address appears in the TweetFeed corpus. Exact match over the past 365 days (falls back to a 30-day substring window if there's no exact hit, so '1.2.3' will still match '1.2.3.4' there). Useful for confirming if an observed IP has been flagged as attacker infrastructure (C2, scanner, phishing host) by the public infosec Twitter/X community. Pass a full IPv4 / IPv6 string for the best exact-match hit rate."
    },
    {
      "name": "check_hash",
      "description": "Check whether a file hash (MD5 or SHA-256) appears in the TweetFeed corpus. Exact match over the past 365 days (falls back to a 30-day window if there's no exact hit). Useful for confirming if a binary sample has been shared by the public infosec Twitter/X community. Hash type auto-detected from length (32 hex = MD5, 64 hex = SHA-256). Exact match on hex value, case-insensitive throughout."
    },
    {
      "name": "list_recent_iocs",
      "description": "List TweetFeed IOCs added since a given date, useful for delta-syncing a blocklist or Threat Intelligence pipeline. Source is the 30-day month window so 'since' must be within the past 30 days; older queries return only the part within the month window. Optional 'type' and 'tag' filters narrow the result. Sorted newest first."
    },
    {
      "name": "get_tag_info",
      "description": "Bundle of TweetFeed activity for a single tag: aggregate counts across today/week/month/year windows plus the most recent IOCs. Saves the agent from making three separate calls to assemble a tag overview. Tag can be passed with or without a leading '#'."
    },
    {
      "name": "get_trending",
      "description": "Top tags and IOC-type distribution for a given time window, computed from the live counts.json aggregate. Useful for 'what is the infosec community talking about right now' or 'which malware family is spiking this week' queries. Source: GET https://api.tweetfeed.live/v1/counts (regenerated every 15 min, mirrors counts.json)."
    },
    {
      "name": "enrich_ioc",
      "description": "Look up an IOC value in TweetFeed. First an EXACT lookup over the past 365 days (aggregated: first_seen, last_seen, count, reporters, tags, last source tweets; accepts defanged input and http/https variants), including AI-generated context (summary, malware family, threat type) when available. If no exact match, falls back to a 30-day substring scan with auto-detected type (URL / domain / IP / MD5 / SHA-256)."
    },
    {
      "name": "get_campaigns",
      "description": "AI-clustered campaign groupings of the last 7 days of community-shared TweetFeed IOCs: each campaign bundles related URLs/domains/IPs/hashes under a name, a short context summary, a clustering confidence (high/medium/low), and a targeted brand when one was identified, plus a sample of member IOCs. Regenerated daily from a rolling 7-day window. Useful for 'what phishing campaigns are active right now' or 'is this IOC part of a larger campaign' queries. Optional filters narrow by targeted brand or minimum confidence."
    },
    {
      "name": "get_trends",
      "description": "IOC trend analytics from the last 31 days: daily volume by type, top moving tags week-over-week, most-abused TLDs, new vs recurring indicator ratio, and feed producer concentration."
    }
  ],
  "dataEndpoints": [
    {
      "name": "campaigns",
      "url": "https://api.tweetfeed.live/v1/campaigns",
      "format": "application/json",
      "description": "AI-clustered campaign groupings of the last 7 days of community IOCs. Deterministic pre-grouping (shared registered domain, URL path patterns, tags) plus AI naming/context; regenerated daily. `stale: true` means the daily refresh failed and this is the previous day's document."
    },
    {
      "name": "stix_2_1_bundles",
      "url": "https://tweetfeed.live/stix/manifest.json",
      "format": "application/stix+json;version=2.1",
      "description": "Static STIX 2.1 indicator bundles for SIEM/Threat Intelligence platforms. Manifest indexes today/week/month bundles, each a spec-compliant, self-contained Bundle: the TweetFeed Identity, the canonical TLP:CLEAR marking-definition and the Indicator objects, so every created_by_ref and object_marking_refs resolves inside the bundle itself. Regenerated every 15 minutes."
    },
    {
      "name": "diff_endpoint",
      "url": "https://api.tweetfeed.live/v1/since/{ISO8601}",
      "format": "application/json",
      "description": "Returns IOCs added after the given ISO 8601 timestamp. Same /{filter1}/{filter2} syntax as /v1/{window}. 410 if since > 365d ago, 400 on malformed ISO."
    },
    {
      "name": "per_tag_rss",
      "url": "https://tweetfeed.live/rss/tag/{slug}.xml",
      "format": "application/rss+xml",
      "description": "One RSS 2.0 feed per active tag (>=1 hit in the last 7 days). Subscribe to a single threat type without polling the firehose."
    }
  ]
}
