Security

Shodan MCP: IP exposure and CVE details for agents

Connects agents to the Shodan API and CVEDB: open ports and services for an IP, device search, CVSS, EPSS and KEV data for CVEs, and vulnerabilities by product.

Project and installation docs

View project

https://github.com/w0h1v/mcp-shodan

Checking out a suspicious IP, or seeing what your own servers expose to the internet, usually means a trip to the Shodan website followed by a search through NVD for the CVEs. Shodan MCP puts both steps inside the agent: one call returns an IP’s ports, services, certificates and ownership, and Shodan’s CVEDB supplies severity and exploitation data for vulnerabilities. It’s a community project with about 170 stars as of 2026-10-06.

What it does

  • IP reconnaissance: ip_lookup returns organization, ASN, location, open ports, service banners and cloud provider, plus per-service TLS certificate details (fingerprints, validity, JARM/JA3S); SAN hostnames from certificates roll up into the top-level hostname field.
  • Device search: shodan_search runs Shodan query syntax against internet-connected devices, with max_results controlling how many come back, a country breakdown, and a service summary for each device.
  • Vulnerability intelligence: cve_lookup gives CVSS v2/v3 scores, EPSS probability, KEV status and ransomware associations; cves_by_product lists vulnerabilities by product name or CPE with KEV filtering, EPSS sorting and date ranges; cpe_lookup searches CPEs by product and can return just a count.
  • DNS: dns_lookup and reverse_dns_lookup resolve in both directions and both accept a batch of hostnames or IPs.

Who it’s for

  • Threat intelligence analysts who need fast background on a suspicious IP without switching between the Shodan website and NVD.
  • Ops and security engineers who want to turn a recurring exposure check into a routine an agent can run on its own.

Setup

Needs Node.js and a Shodan API key. In Claude Code:

claude mcp add --transport stdio --env SHODAN_API_KEY=your-shodan-api-key shodan -- npx -y @burtthecoder/mcp-shodan

The README also covers Codex CLI, Gemini CLI and Claude Desktop; you can also install it globally with npm install -g and point the config at the resulting command, or clone and build it from source. The server is also listed in the official MCP Registry with its own server.json manifest, added in v1.0.22.

Our take

For threat intelligence, Shodan is about as directly useful as a data source gets. This server has few tools, but each one earns its place, and the output is formatted; CVE lookups put CVSS, EPSS and KEV side by side, which gives a model what it needs to prioritize. All tools are lookups, so nothing scans the target. Wireshark MCP reads traffic you captured yourself; Shodan reads what other people’s infrastructure exposes publicly, so the two complement rather than replace each other. The Shodan API bills against account credits: 401 means a bad key, 402 an exhausted quota, 429 a rate limit, and searches like shodan_search burn credits faster than a single lookup, so test a cheap call like dns_lookup first. Only investigate targets you’re authorized to look into. The npm package still carries the author’s old @burtthecoder scope, and the project recently moved off a hand-rolled @modelcontextprotocol/sdk integration onto FastMCP. Licensed MIT.