Connects Claude to the URLhaus database from abuse.ch, a free threat intelligence feed tracking malicious URLs associated with malware distribution. No authentication required. Hosted by Pipeworx as a streamable HTTP endpoint, so you can drop the gateway URL directly into your MCP config and start querying. The source doesn't list specific tools, but URLhaus typically offers lookups by URL, hash, tag, and signature to check if domains or links are flagged for malware. Useful when you need Claude to verify suspicious URLs during security analysis, threat hunting, or incident response workflows without leaving the conversation.
claude mcp add --transport http io.github.pipeworx-io-urlhaus https://gateway.pipeworx.io/urlhaus/mcp