
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@whisper-security/whisper-mcp
Advanced tools
Give an AI agent a real, routable IPv6 identity, verifiable egress and DNS policy. Keyless: verify any agent's identity and query the infrastructure graph. With a key: register, govern and route agents.
Give an AI agent a real, routable IPv6 identity, egress anyone can verify from outside, and DNS policy you control. Plus the infrastructure graph, to ask "is this host safe?" before connecting.
{
"mcpServers": {
"whisper": {
"command": "npx",
"args": ["-y", "@whisper-security/whisper-mcp"]
}
}
}
That is the whole setup. Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, Cline, Zed: same three lines.
No key, no signup, 45 tools, real answers:
whisper_verify - is this address or hostname a real Whisper agent, and whose?whisper_rdap - the IP-anchored registration record for a /128explain_indicator - one-call threat assessment for a domain, IP, ASN or hashquery - Cypher against WhisperGraph, the internet's infrastructure graphread_docs, list_workflows, run_workflow - documentation and ready-made investigationsAdd an API key and the same server also registers agents, sets resolver policy, hands out egress configuration and reads your agents' activity. Nothing is hidden behind the key that could have been answered without it.
https://whisper.online - an email address, no human in the loop. Then either set
WHISPER_API_KEY in the server's env block, or run whisper login.
It resolves the whisper binary for your platform from the GitHub release tagged for
this exact package version, checks it against the .sha256 published beside it, caches it,
and runs whisper mcp. The verified digest is recorded beside the binary and re-checked on
every run, so a given version of this package always resolves to the same bytes and a cached
copy that no longer matches the digest we recorded is never executed.
Already have the CLI (brew install whisper-sec/tap/whisper, apt install whisper,
scoop install whisper)? Then whisper mcp is the same server and you do not need this
package at all.
linux (amd64, arm64, arm, 386, riscv64, mips, mipsle), darwin (amd64, arm64), windows (amd64, arm64).
MIT.
FAQs
Give an AI agent a real, routable IPv6 identity, verifiable egress and DNS policy. Keyless: verify any agent's identity and query the infrastructure graph. With a key: register, govern and route agents.
We found that @whisper-security/whisper-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.