Ansvar: Threat Intelligence MCP Server

CVE intelligence, STRIDE, OWASP test cases via Ansvar Gateway. Cited, OAuth + paid.

Remote serverstreamable-http

What is the Ansvar: Threat Intelligence MCP server?

Ansvar: Threat Intelligence MCP server exists for a simple reason — assistants are far more useful when they can act on Ansvar: Threat Intelligence directly instead of describing what you should do. CVE intelligence, STRIDE, OWASP test cases via Ansvar Gateway. Cited, OAuth + paid.

What you get

Ansvar Gateway is a remote MCP server for compliance, legal, and security work. One OAuth connection gives your agent scoped search and get_provision across audited law corpora — Europe-led, with growing North American and APAC coverage; the live, licence-audited jurisdiction list is at ansvar.eu/coverage — plus the EU regulations corpus (GDPR, NIS2, DORA, AI Act, CRA, …), the security-frameworks corpus, and live CVE/KEV/EPSS intelligence.

This is the public home of the hosted Ansvar Gateway — documentation and listing anchor only; the gateway service itself is not developed in this repository. Open-source law-connector code lives across the Ansvar-Systems organization (Apache-2.0).

What the assistant can call

Once Ansvar: Threat Intelligence is connected, these are the calls the assistant has available:

Setting it up

Being a remote server, there is no local install. You register the endpoint with your client, authorise it once, and the tools appear.

Choosing this one

Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Ansvar: Threat Intelligence's toolset — list_coverage, Per, Endpoint and 7 more — is a fair guide to whether it matches your workflow. It is maintained by eu.ansvar; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Before you rely on it

  • Your data travels to the provider's service, so the usual questions apply about what you send and what they retain.
  • With 10 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Ansvar: Threat Intelligence.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the ansvar: threat intelligence mcp server does with a few real requests.

Available tools

ToolWhat it does
list_coveragediscover what corpora and jurisdictions are live, by domain.
Peritem attribution:** every served row carries source URL, publisher, and licence; content with unresolved licensing is withheld with an explicit notice, not silently dropped.
Endpointhttps://gateway.ansvar.eu/mcp (streamable HTTP)
AuthOAuth 2.1 with Dynamic Client Registration — no API keys
Registry[eu.ansvar/gateway](https://registry.modelcontextprotocol.io/v0/servers?search=eu.ansvar%2Fgateway) in the official MCP registry
Quickstarthttps://ansvar.eu/docs/quickstart
PricingFree tier (B2B signup, 100 searches/day) → https://ansvar.eu/pricing
Coveragehttps://ansvar.eu/coverage
Termshttps://ansvar.eu/terms
llms.txthttps://ansvar.eu/llms.txt

Example prompts to try

  • Use Ansvar: Threat Intelligence to list coverage.
  • Use Ansvar: Threat Intelligence to Per.
  • Use Ansvar: Threat Intelligence to Endpoint.

Frequently asked questions

It connects Ansvar: Threat Intelligence to MCP-compatible AI assistants such as Claude and Cursor, exposing 10 tools (list_coverage, Per, Endpoint, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Ansvar: Threat Intelligence directly.