# PG1 Sovereign Threat Intelligence > PG1 Sovereign Threat Intelligence: threat-intelligence tools for AI agents, covering wallet sanctions screening, domain age lookups, hostname/phishing reputation checks, bulk STIX 2.1 indicator feeds, CVE enrichment, and threat actor dossiers — served over MCP, A2A, and REST. ## Free tools - [check_wallet_sanctions](https://pg1-ai-agent.vercel.app/api/mcp): Checks a cryptocurrency wallet address against the OFAC SDN sanctions list; informational only, never phrased as "safe" or "clean". - [check_domain_age](https://pg1-ai-agent.vercel.app/api/mcp): Looks up a domain's registration age via RDAP; a newly registered domain is reported as a phishing signal, not proof of malicious intent. - [check_hostname_reputation](https://pg1-ai-agent.vercel.app/api/mcp): Screens a hostname against a phishing/lookalike blocklist; returns allowlisted, listed, lookalike, or not_listed — never "safe" or "clean". - [check_wallet_age](https://pg1-ai-agent.vercel.app/api/mcp): Reports when an EVM wallet address first appeared on a chain, based on its earliest on-chain transfer history; reports age and history only, never a safety verdict. Age is per chain: the same address can be old on one chain and new on another. Also reports EIP-7702 delegation, checked live on every call and never cached: `delegated` is true when the address's code on that chain is exactly 0xef0100 plus a 20-byte delegate address (given in `delegate_address`), false otherwise, and null when the code check did not complete (never guessed false; the age is still returned). A delegated address gets reason code WALLET_DELEGATED, which states the fact only and never changes `status` on its own (an old delegated wallet is `status: "no_flags"`). check_wallet_age status rule: "flagged" only with WALLET_NO_HISTORY; otherwise "unknown" if anything didn't complete (WALLET_AGE_PARTIAL, which is listed in reasons but never flags, or `delegated: null`); otherwise "no_flags". Cached answers count against the 60/hour anonymous rate limit. `is_contract` is unchanged and is still true for a delegated address. - [get_usage_status](https://pg1-ai-agent.vercel.app/api/mcp): Returns your remaining free-tier calls for today and current license status. ## Endpoints - [MCP](https://pg1-ai-agent.vercel.app/api/mcp): Model Context Protocol server (Streamable HTTP, JSON-RPC). - [A2A](https://pg1-ai-agent.vercel.app/api/a2a): Agent2Agent JSON-RPC endpoint exposing the five free tools; agent card at https://pg1-ai-agent.vercel.app/.well-known/agent-card.json. - [REST](https://pg1-ai-agent.vercel.app/api/ioc): Simple GET endpoint returning a STIX 2.1 threat indicator feed. - [Health](https://pg1-ai-agent.vercel.app/api/health): Uptime/health check. - [OpenAPI spec](https://pg1-ai-agent.vercel.app/openapi.json): Machine-readable schema for the REST endpoint. - [About](https://pg1-ai-agent.vercel.app/about): Human-readable overview of PG1, its free tools, endpoints and listings. ## Integration guides - [Example: an alert bot that screens wallets with PG1](https://pg1-ai-agent.vercel.app/docs/crypto-alert-bot): A worked integration that screens wallets with the free check_wallet_sanctions and check_wallet_age tools over A2A, with exact requests and responses, status-based drop/hold/allow rules, caching and rate-limit backoff. ## Quick start Call a free tool over MCP (POST, no key needed): ``` curl -X POST https://pg1-ai-agent.vercel.app/api/mcp -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"check_domain_age","arguments":{"domain":"example.com"}}}' ``` The same call over A2A (version 1.0 response shape): ``` curl -X POST "https://pg1-ai-agent.vercel.app/api/a2a?A2A-Version=1.0" -H "Content-Type: application/json" -d '{"jsonrpc":"2.0","id":1,"method":"SendMessage","params":{"message":{"messageId":"example-1","role":"ROLE_USER","parts":[{"data":{"skill":"check_domain_age","arguments":{"domain":"example.com"}}}]}}}' ``` ## Response metadata Every free tool response (and every paid MCP/A2A response) adds `reasons: [{code, message}]` (permanent machine-readable codes, empty when nothing is flagged), `status: "flagged" | "no_flags" | "unknown"` (never "no_flags" when a check didn't complete), `checks: [{source, result, checked_at, data_as_of}]` (generic source labels, never a vendor name), and `request_id` (a UUID, also sent as the `X-Request-Id` header on `/api/mcp` and `/api/a2a`). Full reason-code list: https://pg1-ai-agent.vercel.app/docs/reason-codes ## Test your integration Fixed fixture inputs always return the same answer, free for every caller (no key, no payment, no rate-limit use), with the real response shape plus `test_fixture: true` and `checks[].source: "fixture"`. Exact values only; anything else, even one character off, is a real lookup. UNKNOWN reproduces that tool's real upstream-failure response (for check_wallet_age: the `upstream_unavailable` isError result, never `found: false`). For `check_domain_age`, always check `status` before `found`: `found: false` with `status: "unknown"` means the lookup did not complete, not that the domain is new. MCP covers every tool with a reason code to flag with; A2A covers its 4 free check_* skills. The REST endpoints (/api/ioc) have no fixtures. Full table: https://pg1-ai-agent.vercel.app/docs/testing - Wallets (check_wallet_sanctions, check_wallet_age): FLAGGED `0x7067312d746573742d6669787475726500000001`, CLEAN `...00000002`, UNKNOWN `...00000003`; check_wallet_age only: DELEGATED `0x7067312d746573742d6669787475726500000004` (delegated: true, reason WALLET_DELEGATED, status "no_flags") - Domains/hostnames (check_domain_age, check_hostname_reputation): `pg1-test-flagged.invalid`, `pg1-test-clean.invalid`, `pg1-test-unknown.invalid` - get_ioc_context: `192.0.2.1`, `198.51.100.1`, `203.0.113.1`; get_ioc_batch: `["2001:db8::1"]`, `["2001:db8::2"]`, `["2001:db8::3"]` - get_cve_details / get_cve_batch: `CVE-0000-0001`, `CVE-0000-0002`, `CVE-0000-0003`; get_cve_by_product: vendor `pg1-test.invalid`, product `flagged` / `clean` / `unknown` ``` curl -X POST https://pg1-ai-agent.vercel.app/api/mcp -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"check_hostname_reputation","arguments":{"hostname":"pg1-test-flagged.invalid"}}}' ``` Invalid input keeps its error code (usually -32602); the message says what was wrong, the expected format, one valid example and the request_id, and never echoes your input. ## Paid tools - [Paid MCP tools](https://pg1-ai-agent.vercel.app/api/mcp): Bulk indicator feeds, CVE enrichment, threat actor dossiers, alert subscriptions, and indicator submission — $0.01 per call via x402 on Base, or a licence key in the `x-api-key` header. ## Listings - [Official MCP Registry](https://registry.modelcontextprotocol.io): io.github.Project-Gifted1/pg1-threat-intel - [Smithery](https://smithery.ai/server/@gikewun/pg1-threat-intel) - [Glama](https://glama.ai/mcp/connectors/io.github.Project-Gifted1/pg1-threat-intel)