SS
Shodan Search MCP
Defensive Shodan search and host intelligence MCP using customer-provided SHODAN_API_KEY for authorized exposure review.
Tools
| host_exposure | Show the public attack surface of one IP - open ports, software, hostnames, known CVEs. |
| exposure_report | Full defensive review of one IP: attack surface plus severity-ranked detail for every known CVE. |
| cve_details | Look up one CVE - CVSS, EPSS exploit-probability, KEV status, affected products. |
| product_cves | List recent CVEs affecting a product, e.g. nginx or openssl. |
| safe_query_examples | Examples of scoped, defensive Shodan queries. |
| network_ownership | Who operates the network an address sits in, from RDAP. Replaces the org and ASN fields the key-gated Shodan host lookup used to provide. RDAP is the registries' own protocol and needs no credential. |
| domain_exposure | Exposure review for every address a domain resolves to. Replaces the key-gated banner search with something a defender can act on: resolve the domain you are responsible for, then report open ports, detected products and known CVEs per address. Uses DNS plus Shodan InternetDB, both , and performs no scanning of its own. |
| list_sources | Every upstream this server uses. |