The Precursor Intelligence MCP server exposes 71 tools. All cost 1 credit per successful call
except account_status, which is free. Click any tool for full
parameter, response, and example detail.
The Your Data tools (the *_my_*, get_open_ports, assess_cve_exposure, map_assets_to_actor,
and appliances_exploited_by_actor tools) return your own organisation's data — assets, alerts,
watchlist, supply-chain, and more — and cross-reference it with the threat intel. They require the
mcp:org scope on your key; the organisation is resolved from the key and never read from the
request. See Authentication.
Every tool's name is the exact string you pass to tools/call:
Full intelligence on a single CVE: NVD record, CVSS, EPSS, CISA KEV status, Shadowserver honeypot activity, notable events, and attributed threat actors with citations.
Full dossier: aliases, ATT&CK techniques, campaigns, related groups, ransomware tradecraft, and linked CVEs / industries / malware — each with an evidence quote and source URL.
Free. Caller's current credit balance and API key metadata.
Your Data (scope mcp:org)
These tools return your own organisation's data and require the mcp:org scope. The organisation is resolved from your API key and injected server-side — it is never read from the request, so a key can only ever read its own org.
Your Data · Cross-Reference
Join your own assets and findings with Precursor's threat intel.
Your exposure to a specific CVE: your findings + affected assets, watchlist/alert membership, inferred CPE matches, public intel, and recent exploitation.