MCP server · CyberMax
CyberMax Data MCP server
Free US data lookups: ZIP demographics, CISA KEV/EPSS CVEs, domain rank, county spending, recalls.
Free: Free, no key neededConnect
Streamable HTTP endpoint: https://data.cybermaxtools.com/mcp (the original https://data.cybermax-tools.workers.dev/mcp keeps working). Add it to Claude Desktop, Cursor, Windsurf or VS Code:
{
"mcpServers": {
"cybermax-data": {
"type": "http",
"url": "https://data.cybermaxtools.com/mcp"
}
}
}No key needed for the free tier. For more calls, add your paid key as the x-api-key header. Full API docs: https://data.cybermaxtools.com/docs · Product page: CyberMax Data
Tools
| Tool | What it does | Effect | Inputs (* required) |
|---|---|---|---|
zip_lookup | Look up a US ZIP code: city, state, county, coordinates, time zone and Census ACS 2020-2024 demographics (population, median age, household and per-capita income, median home value, median gross rent, housing units, owner-occupied share). | read-only, answers from its own data, never destructive | zip_code* |
cve_kev_lookup | Check whether a CVE is in CISA's Known Exploited Vulnerabilities (KEV) catalog; if so return vendor, product, date added, federal due date, known ransomware use, EPSS probability/percentile, CVSS score/severity/vector, CWE and required action. | read-only, answers from its own data, never destructive | cve_id* |
latest_kev | List the CVEs most recently added to CISA's Known Exploited Vulnerabilities catalog, newest first, with EPSS, CVSS and due date in the summary. | read-only, answers from its own data, never destructive | limit |
domain_rank | Link-graph rank of a popular website (top 5,000): Common Crawl harmonic-centrality and PageRank rank, hosts crawled, previous-crawl rank, Majestic Million rank and referring subnets. For any other domain use Linkheft on Apify (apify.com/cybermax/domain-authority). | read-only, answers from its own data, never destructive | domain* |
county_federal_spending | FY2025 federal prime contract and grant obligations in a US county (USAspending.gov, place of performance): dollars, per-resident values, population and the county's contract rank in its state. | read-only, answers from its own data, never destructive | county_fips* |
vehicle_recall | Look up an NHTSA vehicle/equipment recall campaign from the last 12 months: manufacturer, component, units affected, do-not-drive and park-outside flags, summary, risk, remedy and affected make/model/year list. | read-only, answers from its own data, never destructive | campaign* |
latest_recalls | List the newest US vehicle and equipment recalls from NHTSA, newest first, with risk and remedy. | read-only, answers from its own data, never destructive | limit |
Security and data handling
- Your tool arguments are used only to answer that call. They are not saved to a database, shared, sold or used for training.
- To make repeat lookups fast, some servers keep the public answer to a lookup in Cloudflare's edge cache for up to 7 days (most for 1 hour or less). It holds the public result, not who asked.
- Free tier: a per-day counter keyed by a SHA-256 hash of your IP address and the date (in a Cloudflare Durable Object). The raw IP is not stored.
- Paid key: the key is checked with the payment provider (Stripe; Polar for older keys) and the result is cached for 10 minutes; usage is counted per key per month.
- No accounts, cookies or tracking on the MCP endpoint. Errors may appear in Cloudflare's short-lived Worker logs.
- Every tool is read-only: it looks up public data and returns it. No tool writes, deletes, sends messages or spends money.
Registry and source
- Official MCP Registry:
dev.workers.cybermax-tools.cybermax/cybermax-data, version 1.0.0. - Public manifest, tool schemas and security notes (MIT): gitlab.com/CyberMax.tools/agent-tools/mcp/cybermax-data. The hosted service code is not public.
- Report a vulnerability: security policy.