io.github.whisper-sec/whisper
pkg:npm:@whisper-security/whisper-mcp
One routable IPv6 per AI agent, verifiable from the DNS root. Keyless tools need no signup.
- transport:
- remote + stdio
- credential class:
- self-provisionable
Owner verification
Not yet verified. Verifying proves you control this server and is free, permanently — it never changes a published score.
Start verification →Tools
- whisper_assessshallow
Assess the risk/policy posture of one or more indicators. Answers without an API key. Example call: {"skill":"assess","input":"example.com"}
- whisper_assetshallow
Resolve an asset and its catalog of attributes. Answers without an API key. Example call: {"skill":"asset","input":"example.com"}
- whisper_explainshallow
Explain a verdict - the evidence and reasoning behind it. Answers without an API key. Example call: {"skill":"explain","input":"example.com"}
- whisper_historyshallow
Historical records for an indicator (incl. whois/bgp history). Answers without an API key. Example call: {"skill":"history","input":"example.com"}
- whisper_identifyshallow
Identify an indicator (domain, IP, hash, …) against the graph. Answers without an API key. Example call: {"skill":"identify","input":"example.com"}
- whisper_lookupTlsFingerprintshallow
Look up a TLS (JA3/JA4) fingerprint in the graph. Answers without an API key. Example call: {"skill":"lookupTlsFingerprint","input":"ja3:771,4865-4866-4867"}
- whisper_lookupTorRelayshallow
Look up Tor relay metadata for an address. Answers without an API key. Example call: {"skill":"lookupTorRelay","input":"185.220.101.1"}
- whisper_originsshallow
Trace the origins/provenance of an indicator. Answers without an API key. Example call: {"skill":"origins","input":"example.com"}
- whisper_pslshallow
Public-suffix-list family (tld-plus-one, is-public-suffix, affiliation). A family verb: name the sub-verb as "sub" alongside the input. Sub-verbs: tldPlusOne, isPublicSuffix, affiliation.. Answers without an API key. Example call: {"skill":"psl","sub":"tldPlusOne","input":"a.b.example.co.uk"}
- whisper_rdapshallow
The public registration record for any address in Whisper's space, in RFC 9083 form: the handle, the agent's label, its country, and the entities behind it. The same document the RDAP service serves at /ip/{address}, which any RDAP client can already read. Answers without an API key. Example call: {"skill":"rdap","input":"2a04:2a01:b69a:6717:e3b0:51ff:3bf7:f478"}
- whisper_signupshallow
Start or complete Whisper signup from an email address alone, and receive an API key that unlocks the provisioning and governance skills on this card. Send {"email":"..."} to start; a six-digit code arrives by email; send {"signup_id":"...","code":"123456"} to complete. No human step, no account needed first. Example call: {"skill":"signup","input":{"email":"agent@example.com"}}
- whisper_threatintelshallow
Threat-intelligence indicator family (candidate apex/CDN/hosting). A family verb: name the sub-verb as "sub" alongside the input. Sub-verbs: candidateCdnApex, candidateMultiTenantApex, candidateSharedHostingIp.. Answers without an API key. Example call: {"skill":"threatintel","sub":"candidateCdnApex","input":5}
- whisper_topAsnsByPrefixCountshallow
Top ASNs ranked by announced-prefix count. Answers without an API key. Example call: {"skill":"topAsnsByPrefixCount","input":10}
- whisper_variantsshallow
Enumerate variants/permutations of an indicator. Answers without an API key. Example call: {"skill":"variants","input":"example.com"}
- whisper_verifyshallow
Is this IPv6 address or hostname a real Whisper agent, and whose? Grades the full keyless trust chain: the reverse DNS record, the forward AAAA confirming it back to the same address, and the DANE-EE certificate pin published in DNSSEC-signed DNS. Returns is_whisper_agent with the evidence for the verdict either way, so a negative answer is an answer and not an error. Answers without an API key, and every leg of it is independently checkable from the DNS root with dig. Example call: {"skill":"verify","input":"2a04:2a01:b69a:6717:e3b0:51ff:3bf7:f478"}
- whisper_walkshallow
Walk the graph from an indicator across its relationships. Answers without an API key. Example call: {"skill":"walk","input":"example.com"}
- whisper_watchshallow
Watch an indicator for change/activity over time. Answers without an API key. Example call: {"skill":"watch","input":{"action":"list"}}
Embed this server’s score
Tool count and median score across every tool in this server’s corpus — honest in a way a single cherry-picked tool’s badge wouldn’t be.
[](https://vouch.tools/servers/c2ad310a-83b1-4481-b31b-52c9c5c4634f)