Odel
TweetFeed

TweetFeed

@0xdaniellopezTypeScriptMITUpdated 5 days ago

IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter. No auth, CC0.

Server endpointStreamable HTTPNo authProbed

This is the third-party server itself — Odel doesn't run it. Hitting this URL directly talks straight to the upstream server with no auth or proxying. Connect through Odel to front it with managed auth.

tweetfeed-mcp

Model Context Protocol (MCP) server for tweetfeed.live.

Exposes the public IOC feed (URLs, domains, IPs, SHA256/MD5 hashes shared by the infosec community on Twitter/X) as MCP tools so AI agents can query threat intel programmatically.

  • Endpoint: https://mcp.tweetfeed.live/ (HTTP JSON-RPC 2.0, POST)
  • Protocol version: 2025-11-25 (negotiated; older clients fall back automatically)
  • Auth: none (all IOC data is CC0)
  • License (data): CC0-1.0 · License (code): MIT

Tools

NamePurpose
query_iocsQuery IOCs by time window (today/week/month) with optional user, tag, and type filters.
check_urlCheck whether a specific URL appears in the feed.
check_ipCheck whether an IPv4/IPv6 address appears in the feed.
check_hashCheck whether an MD5 or SHA-256 hash appears in the feed (type auto-detected).
list_recent_iocsList IOCs added since a given date, with optional type/tag filters.
get_tag_infoWindow aggregates plus recent IOCs for a tag (leading # optional).
get_trendingTop tags and IOC-type distribution for a window (today/week/month/year).
enrich_iocExact lookup of an IOC (auto-detected type: url/domain/ip/md5/sha256) over the past 365 days, with AI/external-corroboration/net/domain-registration (reg) context when available, plus an archive of history older than 365 days when it exists (can accompany a live match); falls back to a 30-day substring scan on a miss.
get_campaignsAI-clustered campaign groupings from the last 30 days, with optional brand and min-confidence filters.
get_trends31-day IOC trend analytics: daily volume by type, top moving tags week-over-week, most-abused TLDs, new vs recurring ratio, producer concentration.

Use with Claude Desktop / Claude.ai / other MCP clients

{
  "mcpServers": {
    "tweetfeed": {
      "url": "https://mcp.tweetfeed.live/"
    }
  }
}

Or from the Claude Code CLI:

claude mcp add tweetfeed https://mcp.tweetfeed.live/

Quick test

curl -sX POST https://mcp.tweetfeed.live/ \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","method":"tools/list","id":1}' | jq .

# Example tool call:
curl -sX POST https://mcp.tweetfeed.live/ \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","method":"tools/call","id":2,
       "params":{"name":"query_iocs",
                 "arguments":{"time":"today","tag":"phishing","type":"url","limit":5}}}' | jq .

Develop

npm install
npm run dev          # wrangler dev on http://localhost:8787
MCP_URL=http://localhost:8787 npm test

Deploy

npm run deploy       # wrangler deploy (routes mcp.tweetfeed.live/*)
MCP_URL=https://mcp.tweetfeed.live npm test