
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@whiteintel/mcp-server
Advanced tools
Model Context Protocol server for WhiteIntel — corporate & offshore ownership intelligence. Look up companies, search entities (companies + people), screen sanctions, and trace ownership chains to the ultimate beneficial owner. Freemium: anonymous free ti
Trace ownership. Expose the network. A Model Context Protocol server that gives any AI agent (Claude Desktop, Cursor, …) corporate & offshore ownership intelligence from WhiteIntel: look up companies, search entities (companies and people), screen sanctions, and trace ownership chains to the ultimate beneficial owner.
Freemium — works anonymously on the free tier, or set WHITEINTEL_API_KEY to
authenticate as your plan and lift the limits (see Configuration).
Forwards to WhiteIntel's public REST API
(https://whiteintel.dev/api/public/*) — OpenAPI spec.
No install needed — run via npx:
npx -y @whiteintel/mcp-server
Add to your MCP client config:
{
"mcpServers": {
"whiteintel": {
"command": "npx",
"args": ["-y", "@whiteintel/mcp-server"],
"env": { "WHITEINTEL_API_KEY": "wi_…" }
}
}
}
The env block is optional — omit it to use the anonymous free tier.
| Tool | What it does |
|---|---|
lookup_company | UK company by Companies House number → record + ownership graph (officers, PSCs, parent/subsidiary edges). |
search_companies | Free-text company-name search → registration number. |
search_entities | Search the corpus (companies + people), live + demo investigations → entity ids. |
get_entity | Full record for one entity + its direct relationships. |
get_dossier | Structured, fully-cited dossier: cross-source identity, ownership/UBO chain, risk signals, provenance. |
trace_ownership_path | Walk ownership upward from a root entity to the ultimate beneficial owner. |
lookup_by_identifier | Resolve an entity by a strong id — LEI, OFAC/EU/UN/UK sanctions id, UEN, NIP, SEC CIK, KRS, GB-COH. |
get_sanctions | An entity's sanctions exposure (OFAC/EU/UN/UK) for it and its resolved cluster siblings, with sources. |
check_offshore_exposure | Walk the ownership chain and flag sanctioned + secrecy-jurisdiction hops (offshore-layering lead). |
source: "demo".| Env var | Default | Purpose |
|---|---|---|
WHITEINTEL_API_KEY | (none) | Optional wi_ key (whiteintel.dev → Settings → API keys). Forwarded as a Bearer token to authenticate as your plan and lift free-tier limits. |
WHITEINTEL_API_BASE | https://whiteintel.dev | API origin (SSRF-guarded to whiteintel.dev hosts). |
WHITEINTEL_TIMEOUT_MS | 30000 | Per-request timeout. |
MIT © whiteintel.dev
FAQs
Model Context Protocol server for WhiteIntel — corporate & offshore ownership intelligence. Look up companies, search entities (companies + people), screen sanctions, and trace ownership chains to the ultimate beneficial owner. Freemium: anonymous free ti
The npm package @whiteintel/mcp-server receives a total of 410 weekly downloads. As such, @whiteintel/mcp-server popularity was classified as not popular.
We found that @whiteintel/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.