PG1 Threat Intelligence
by Project-Gifted1
What PG1 is
PG1 is a threat-intelligence service built for AI agents. An agent can ask it about a wallet address, a domain or a hostname before acting on it, and get back a structured, machine-readable answer.
The same checks are served over the Model Context Protocol (MCP), Agent2Agent (A2A) and a REST API. Results report facts and flags, never a “safe” or “clean” verdict, and a check that could not complete is reported as unknown rather than guessed.
Free tools
These MCP tools need no key and no payment. They are also available as A2A skills.
check_wallet_sanctions
Checks a cryptocurrency wallet address against a sanctions list synced daily. A “not listed” result is informational only, not compliance advice.check_domain_age
Looks up a domain’s registration date and age via RDAP. A domain registered less than 30 days ago is reported as a common phishing signal, not as proof of malicious intent.check_hostname_reputation
Checks one hostname against a phishing blocklist and allowlist, synced daily, plus a lookalike (typosquat) detector. Returnsallowlisted,listed,lookalikeornot_listed.check_wallet_age
Reports when an EVM wallet address first appeared on a chain, from its earliest on-chain transfer, and whether it is a contract or has an EIP-7702 delegation. Age and history only, never a safety verdict.get_usage_status
Returns your remaining free-tier calls for today and your licence status.
Anonymous callers are rate-limited. Fixed test inputs that always return the same answer are listed in /llms.txt.
Indicator feed: /api/ioc
GET /api/ioc returns a STIX 2.1 bundle (application/stix+json) of threat indicators, filterable by since, type, min_score and limit.
It is paid per call with x402: a request without payment gets HTTP 402 and an x402 v2 payment challenge for $0.01 in USDC on Base (eip155:8453). A licence key is also accepted. The MCP server lists further tools (bulk indicator feeds, CVE enrichment, threat-actor profiles) on the same terms.
How to connect
/api/mcp
MCP server (Streamable HTTP, JSON-RPC)./.well-known/agent-card.json
A2A agent card; the A2A endpoint is/api/a2a./openapi.json
OpenAPI description of the REST endpoints./.well-known/x402
x402 discovery document: paid resources, price, network and asset./llms.txt
Plain-text summary for language models, with example calls.
All paths are on https://pg1-ai-agent.vercel.app.
Integration guides: Example: a Telegram alert bot that screens wallets with PG1.
Listings
- MCP Registry:
io.github.Project-Gifted1/pg1-threat-intel - Glama: glama.ai/mcp/connectors/io.github.Project-Gifted1/pg1-threat-intel
- Smithery: smithery.ai/server/@gikewun/pg1-threat-intel
- x402scan: origin
pg1-ai-agent.vercel.app
Status and contact
Service status: stats.uptimerobot.com/Du0BQ84Hg3
Contact: gikewun@gmail.com