Skip to content
Official MCP RegistryListed

AlertsBar

Domain exposures: breaches, infostealers, ULP heap, cookies. Counts and samples, free.

First seen 2 Oct 2026. Evidence as of 2 Oct 2026.

2
Tools
From an anonymous probe
1
Source listings
Each with its own history
1
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
exposure_counts_for_domainCredential-exposure counters for a domain. Counts only - no credential values or per-account detail. Sources: known breaches, infostealer infections, unattributed heap of ULP (Url,Login,Password) bundles, stolen cookies. All figures are INDEXATION dates, not incident dates: _month/_week mean 'newly indexed', never 'newly leaked' - the underlying leak may be years old. Windows nest (_total includes _month includes _week) - never sum them. Counters are rebuilt once daily, so figures are up to 24h old and never real-time. Repeated calls for the same input within a day return identical values - do not re-query to check for changes. Accepts a bare domain or a full URL; scheme, path, port, case and a leading www. are stripped and subdomains collapse to the registrable domain (multi-tenant hosting suffixes such as github.io are not collapsed). An IDN must already be in punycode (xn--) form. Invalid input (not a domain, an IP address) returns an error. If the domain is not in the index at all, every counter and both dates are null: that means NO DATA, not that the domain is clean - never report it as 'no exposure'. first_indexed_at and last_indexed_at give the date range of the domain's records; use last_indexed_at as the 'last updated' date for the domain. Free, no auth.Read-only
exposure_samples_for_domainA small RANDOM sample of individual exposure records for a domain - metadata only, capped in number: up to 20 records per type (stealers_users, stealers_staff, heap_users, heap_staff, breaches). Cookies are not sampled - see cookies_* in exposure_counts_for_domain. The sample is neither the newest nor the largest nor the most severe records, and it can differ between calls; identical-looking records can repeat and because of different logins/passwords. Each record says WHICH url was affected, WHICH domain the captured login belonged to, from WHICH source type, roughly when the incident was, and when the record was indexed. It carries NO credentials: no password, no username, and the login's local part is redacted. Use exposure_counts_for_domain first for the scale of the problem and for freshness (last_indexed_at); use this only when the user asks to see concrete examples. Calling again returns another random subset, never the full set - do not call it repeatedly to collect more records.Read-only

Change history

  1. Description changed (registry)
Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registrybar.alerts/alertsbar2 Oct 20262 Oct 20262