Mlab Sh MCP Server
Public metadata and connection guide for the remote MCP server at https://mlab.sh/mcp, a threat intelligence server for SOC and DFIR work. Its 25 documented tools cover scan, cve, actors, domain.
Teams that work with scan, cve and actors and want a hosted endpoint instead of running a local process.
VERIFIED ACTIVE
LAST COMMIT 2026-08-31 · ★ 2 · #844 OF 945 MAINTAINED OTHER · VERIFIED 2026-09-18
MIT · how we verify → /methodology
01 · Install Mlab Sh
before you install - you'll need
The README does not document required environment variables for a basic install.
Claude Code
claude mcp add mlab-sh-mcp --transport http https://mlab.sh/mcp Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"mlab-sh-mcp": {
"url": "https://mlab.sh/mcp"
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
https://mlab.sh/mcp
transport: streamable-http
endpoint alive - authentication required · probed 2026-09-18
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as remote - your agent's requests go to mlab.sh
endpoint auth requires authentication - rejected our unauthenticated MCP initialize
repo age created 2026-08-31 - young repo, little track record yet
license MIT - declared in the repository
registry vendor namespace sh.mlab - domain-verified with the official MCP registry
03 · What Mlab Sh can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
What you can build
With this server connected, an agent can search threat actors, launch a domain scan: DNS, subdomains, SSL, security.txt, robots.txt, scan a dependency lockfile or SBOM for known CVEs, and remove a bookmarked IOC.
Capability map
Tools grouped from the project's README - what Mlab Sh lets an agent do.
Scan
13 tools - e.g. Threat intel for an IPv4 or IPv6 address; Static analysis of a URL without visiting it; File hash lookup (MD5, SHA1, SHA256) in CIRCL hashlookup
scan_ip · scan_url · scan_hash · scan_crypto · scan_email · scan_phone…
Cve
3 tools - e.g. Search CVEs; Full CVE record; Threat actors known to exploit a CVE
cve_search · cve_detail · actors_by_cve
read & search
3 tools - e.g. Full threat actor profile; Account details; List bookmarked IOCs
get_actor · get_account_info · get_bookmarks
Bookmark
2 tools - e.g. Bookmark an IOC; Remove a bookmarked IOC
add_bookmark · remove_bookmark
Detect
1 tool - e.g. Auto detect the IOC type of a value and return relevant threat intel
detect_ioc
Smishing
1 tool - e.g. Score an SMS for smishing
smishing_risk
Actors
1 tool - e.g. Search threat actors
search_actors
Hello
1 tool - e.g. Connectivity check
hello_world
04 · Who maintains Mlab Sh
mlab.sh is maintained by mlab-sh. It's the only MCP server we track from this author; the repo dates to Aug 2026.
05 · Facts
- repository
- github.com/mlab-sh/mcp
- website
- https://mlab.sh/
- category
- other - ranked #844 of 945 actively-maintained other servers as of 2026-09-18.
- registry
- sh.mlab/mcp (active, first published 2026-08-31)
06 · Mlab Sh FAQ
Is Mlab Sh still maintained?
Yes - as of 2026-09-18, its last commit was 2026-08-31. We re-verify nightly.
What can Mlab Sh do?
With this server connected, an agent can search threat actors, launch a domain scan: DNS, subdomains, SSL, security.txt, robots.txt, scan a dependency lockfile or SBOM for known CVEs, and remove a bookmarked IOC.
How do I install Mlab Sh?
Run `claude mcp add mlab-sh-mcp --transport http https://mlab.sh/mcp`. The README does not document required environment variables for a basic install. You can also paste the ready-made client config above.
Does Mlab Sh require authentication?
Yes - when we probed the endpoint on 2026-09-18, it rejected an unauthenticated MCP initialize; you'll need credentials to connect.
07 · Alternatives to Mlab Sh
Alternatives to Mlab Sh
Maintained other servers if Mlab Sh isn't the fit.
- Heyputer MCP Server Puter MCP enables AI tools to interact with Puter: manage files, websites, workers, and more ★ 43,552 · 2026-09-17
- Server Commands An MCP server to run arbitrary commands ★ 39,038 · 2026-09-11
- basebalance.cloud - x402 RPC & MCP gateway USDC-gated Base JSON-RPC: free 10 req/min, $0.50 per 10k. Failover, cache, /mcp, ledger. ★ 6,432 · 2026-08-26
- Zotero MCP (54yyyu) Search, read, annotate, and add to your Zotero research library, local or web. ★ 5,069 · 2026-09-15
- Firebase MCP Gives AI development tools Firebase-specific capabilities and expertise. ★ 4,470 · 2026-09-18
- Microsoft Fabric MCP Server MCP tools for interacting with Microsoft Fabric ★ 3,681 · 2026-09-17
More MCP servers to compare · PDF Modifier · Clipboard MCP · Molpha MCP · MolTrust MCP Server · Monday Com