Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.
https://haveibeenpwned.com/mcp17 Tools · 139 mshibp_list_breachesList public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.List public HIBP breaches, optionally filtered by domain, spam-list flag, and verification status.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain | string | Filter to breaches for a specific domain. |
| isSpamList | boolean | Filter to breaches that are or are not flagged as spam lists. |
| includeUnverified | boolean | Include unverified breaches. Defaults to true. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_breachLook up a single public HIBP breach by its canonical breach name, such as Adobe.Look up a single public HIBP breach by its canonical breach name, such as Adobe.
| Parameter | Typ | Beschreibung |
|---|---|---|
| name* | string | The breach name to retrieve, for example Adobe. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_latest_breachReturn the most recently added public breach currently loaded into HIBP.Return the most recently added public breach currently loaded into HIBP.
| Parameter | Typ | Beschreibung |
|---|---|---|
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_list_data_classesList the data classes used across public HIBP breach models, such as email addresses or passwords.List the data classes used across public HIBP breach models, such as email addresses or passwords.
| Parameter | Typ | Beschreibung |
|---|---|---|
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_pwned_passwords_rangeQuery the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.Query the public Pwned Passwords k-anonymity API with a 5-character SHA-1 or NTLM prefix and return matching suffixes with prevalence counts.
| Parameter | Typ | Beschreibung |
|---|---|---|
| prefix* | string | The first 5 hexadecimal characters of a SHA-1 or NTLM hash. |
| mode | string | Use SHA-1 by default or NTLM when mode is set to ntlm. |
| addPadding | boolean | Send the Add-Padding header and discard padded zero-count entries. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_breached_accountSearch HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.Search HIBP for breaches affecting a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; use domain and verification filters to refine the result.
| Parameter | Typ | Beschreibung |
|---|---|---|
| account* | string | The email address to search for. |
| domain | string | Filter results to a specific breach domain. |
| includeUnverified | boolean | Include unverified breaches. Defaults to true. |
| responseMode | string | Choose full breach objects, truncated objects, or breach names. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_breached_account_rangeQuery the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.Query the authenticated HIBP k-anonymity breached-account range endpoint with the first 6 characters of a SHA-1 email hash. Requires a subscription with k-anonymity access; compare each returned suffix with the remaining hash characters locally because a prefix alone cannot identify an account.
| Parameter | Typ | Beschreibung |
|---|---|---|
| prefix* | string | The first 6 hexadecimal characters of the SHA-1 hash of an email address. Compare each returned suffix with the remaining 34 characters locally; a prefix alone… |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_paste_accountSearch for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.Search for public pastes containing a single email address. Requires an OAuth bearer token linked to an active HIBP API subscription; run this separately from breached-account lookup.
| Parameter | Typ | Beschreibung |
|---|---|---|
| account* | string | The email address to search for pastes. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_breached_domainReturn breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.Return breached aliases for a verified domain. This tool requires an authorized subscription via OAuth bearer token.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain* | string | The verified domain to search. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_list_subscribed_domainsList the domains associated with the authenticated HIBP subscription.List the domains associated with the authenticated HIBP subscription.
| Parameter | Typ | Beschreibung |
|---|---|---|
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_subscription_statusReturn the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.Return the current plan, quotas, rate limits, expiry, and feature flags for the active HIBP API subscription linked to the authenticated OAuth connection. Use it to confirm access before feature-dependent lookups.
| Parameter | Typ | Beschreibung |
|---|---|---|
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_stealer_logs_by_emailReturn website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.Return website domains historically observed in stealer logs for an email address. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
| Parameter | Typ | Beschreibung |
|---|---|---|
| email* | string | The email address to search for in stealer logs. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_stealer_logs_by_website_domainReturn email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.Return email addresses historically observed in stealer logs for a website domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain* | string | The website domain to search for in stealer logs. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_get_stealer_logs_by_email_domainReturn email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.Return email aliases and associated website domains historically observed in stealer logs for an email domain. Requires an OAuth-linked active subscription with the stealer-log feature; results do not establish current account access.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain* | string | The email domain to search for in stealer logs. |
| limit | integer | Maximum number of items to include in the response. Defaults to 25. |
| offset | integer | Number of items to skip before returning results. Defaults to 0. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_generate_domain_verification_dns_tokenGenerate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.Generate the TXT record value required to verify domain control via DNS, creating or reusing the private HIBP domain-verification records needed for the request. Requires an authenticated subscription with domain-verification access.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain* | string | The domain to generate a verification token for. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_verify_domain_verification_dns_tokenComplete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.Complete domain verification by checking the expected HIBP TXT record on the target domain. Requires an authenticated subscription with domain-verification access.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain* | string | The domain to verify by DNS. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
hibp_send_domain_verification_emailSend a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.Send a domain verification email to an approved alias such as admin or security. Requires an authenticated subscription with domain-verification access.
| Parameter | Typ | Beschreibung |
|---|---|---|
| domain* | string | The domain to verify by email. |
| emailAlias* | string | The approval alias to send the verification email to, for example admin. |
| response_format | string | Format only the text content as markdown (default) or a JSON string. The same machine-readable data is always returned in structuredContent. |
17 von 17 Tools haben eine Beschreibung veröffentlicht.
Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.
Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
Verlinkte Namen öffnen den Forge-Index aller Einträge, bei denen dieses Tool beobachtet wurde. Alle indexierten Tools durchsuchen.
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.