pulsedive_indicator
Pack: pulsedive · Connect: https://pipeworx.io/mcp (see Connect below for a single-pack URL)
No MCP client? Call it directly: GET https://gateway.pipeworx.io/v1/tools/pulsedive_indicator for the schema, then POST the same URL with its arguments for the data.
Is this IP/domain/URL/hash malicious — risk score + threats. Looks up an indicator of compromise (IOC) in Pulsedive and returns its risk level, contributing risk factors, associated threats, and intel feeds. Example: pulsedive_indicator({ indicator: “8.8.8.8”, _apiKey: “your-key” })
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
indicator | string | yes | The IOC to look up — an IP, domain, URL, or file hash. e.g. “1.2.3.4”, “example.com”, “http://bad.tld/x” |
_apiKey | string | yes | Pulsedive API key (free tier 50/day at pulsedive.com) |
Example call
Arguments
{
"indicator": "8.8.8.8",
"_apiKey": "your-pulsedive-api-key"
}
curl
curl -X POST https://gateway.pipeworx.io/pulsedive/mcp \
-H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"pulsedive_indicator","arguments":{"indicator":"8.8.8.8","_apiKey":"your-pulsedive-api-key"}}}'
TypeScript (@pipeworx/sdk)
import { Pipeworx } from '@pipeworx/sdk';
const pipeworx = new Pipeworx();
const result = await pipeworx.call('pulsedive_indicator', {
"indicator": "8.8.8.8",
"_apiKey": "your-pulsedive-api-key"
});
More examples
{
"indicator": "example.com",
"_apiKey": "your-pulsedive-api-key"
}
Connect
Add this to your MCP client config — every tool in the catalog, including this one — or use one-click install buttons:
{
"mcpServers": {
"pipeworx": {
"url": "https://pipeworx.io/mcp"
}
}
}
Connect to just the pulsedive pack
{
"mcpServers": {
"pulsedive": {
"url": "https://gateway.pipeworx.io/pulsedive/mcp"
}
}
}
See Getting Started for client-specific install steps.