Skip to main content

For scripts, scanners & AI agents

You hit a rate limit. Here is the sanctioned path.

The report pages and their live streams are metered for humans: every open triggers a fan-out to rate-limited upstream sources, so anonymous automation gets refused past a small burst. The data itself is not closed - there are four supported ways to consume it programmatically, three of them free.

curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant

50 free requests/month · instant API key · no signup form

Four supported ways in

Add it to your agent in one line

The isMalicious MCP server gives any MCP client — Claude Desktop, Cursor, Windsurf, your own agent — six tools over the same API, with typed errors an agent can act on.

npx -y @ismalicious/mcp-server
  • scan_before_usePrompt-injection scan plus link reputation over untrusted content; block, warn or allow.
  • check_urlReputation of one URL, domain or IP before fetching it.
  • check_indicatorFull verdict for an IP, domain, URL or hash: risk score, citing blocklists, timeline, network, a headline you can relay and a recommended action.
  • get_cveOne CVE with CVSS, EPSS, CISA KEV status and due date, exploitation evidence and references.
  • recent_cvesLatest CVEs, optionally by severity.
  • search_indicatorsSearch the corpus by pattern, source or threat class; paginated.
  • check_indicatorsBulk check up to 100 indicators in one call; one request charged per indicator.
  • check_password_exposureWhether a password, or its SHA-1 or NTLM hash, is in known breach dumps and how often; the password is hashed locally and only a 5-character prefix is sent.
  • scan_emailScan one email message for phishing and malware: verdict, recommended action and reasons, from the sender, links and attachment hashes; one scan per message.
  • bootstrap_keyWithout a configured key: mint a free one from an email address.

npm · MCP registry: com.ismalicious/mcp-server

What is refused, and why

  • Anonymous report streams without a page token are served from cache only. A cold miss returns 429 - the live fan-out costs us rate-limited upstream calls.
  • Declared crawlers keep the report pages and cached verdicts, but never trigger live enrichment.
  • Per-IP anonymous API burst is 10 requests/hour. A free key raises the burst to 60 requests a minute, within 50 requests a month, and makes your usage attributable - which is what lets us keep the anonymous tier open at all.
  • Without a key, an address also gets 50 requests a month on the routes a key pays for - the Free key's own quota, one month shared across those routes and both of our APIs, reset on the 1st at 00:00 UTC. Report pages opened in a browser do not count toward it.