list_my_favorite_threat_groups
List the threat groups/actors your organisation has favourited / follows. Costs 1 credit.
tools/callCost: 1 credit per successful call · Scope: mcp:org · Response shape: jsonb
Returns data scoped to your own organisation only — the organisation is resolved from your API key and injected server-side, never read from the request.
Parameters
This tool takes no parameters.
Example invocation
Ask your agent: "Which threat groups are we tracking?"
curl -s https://api.precursorintelligence.com/functions/v1/mcp \
-H "Authorization: Bearer $PRECURSOR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_my_favorite_threat_groups","arguments":{}}}'Response
{
"count": 2,
"items": [
{
"threat_group": "Akira",
"created_at": "2026-03-04T14:22:00.000Z"
},
{
"threat_group": "Scattered Spider",
"created_at": "2026-01-19T09:48:00.000Z"
}
],
"generated_at": "2026-06-18T08:15:00.000Z"
}The full MCP envelope, including _meta.precursor with request_id, credits, and response_truncated, is documented in Response Format.
Response fields
countintegeroptionalNumber of entries returned (equals items.length).
itemsarrayoptionalThreat groups your organisation follows. Each object contains the fields below.
items[].threat_groupstringoptionalName of the favourited threat group / actor.
items[].created_atstringoptionalISO 8601 timestamp of when the group was added to your favourites (UTC).
generated_atstringoptionalISO 8601 timestamp indicating when this response was generated.
Errors
| Code | Message | When |
|---|---|---|
-32001 | unauthorized | The API key is invalid/revoked, the IP is not allowed, or the key lacks the mcp:org scope. |
-32002 | insufficient_credits | Your credit balance is zero; top up from the dashboard |
-32603 | internal | Unexpected server error; the credit is automatically refunded |