
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
regon-mcp
Advanced tools
A Model Context Protocol server that gives AI assistants clean, typed access to the Polish REGON business register (GUS BIR1). Look up any Polish company by NIP, REGON, or KRS and get back structured data — name, address, legal form, activity codes — without touching the underlying SOAP API.
The official GUS BIR1 API is a WCF SOAP
service with WS-Addressing, MTOM multipart responses, an HTTP-header session
token, and XML-nested-inside-XML result payloads. regon-mcp hides all of that
behind a handful of simple tools.
Built and maintained by Smart Mobile House — secure AI implementation for enterprise.
| Tool | Description |
|---|---|
search_by_nip(nip) | Look up an entity by 10-digit NIP (tax id). |
search_by_regon(regon) | Look up an entity by 9- or 14-digit REGON. |
search_by_krs(krs) | Look up an entity by 10-digit KRS (court register). |
search_bulk(identifiers, id_type) | Look up up to 20 entities of one type at once. |
get_full_report(regon, report_type) | Fetch a detailed report for one entity. |
list_report_types() | List valid report names, with guidance on which to use. |
Every response includes a source block that names the register (REGON / GUS),
the environment, and a UTC retrieved_at timestamp — so downstream use can cite
the data correctly, as GUS requires.
No install needed — run it straight from the repo with uv:
uvx --from git+https://github.com/SmartMobileHouse/regon-mcp regon-mcp
By default it uses the public test key against the anonymized GUS test
database, so it runs with zero setup. For live data, request a free USER_KEY
from regon_bir@stat.gov.pl and set the environment variables below.
Add to your MCP config (e.g. claude_desktop_config.json or a project
.mcp.json):
{
"mcpServers": {
"regon": {
"command": "uvx",
"args": ["--from", "git+https://github.com/SmartMobileHouse/regon-mcp", "regon-mcp"],
"env": {
"REGON_API_KEY": "your-user-key",
"REGON_ENV": "prod"
}
}
}
}
During development, point it at a local checkout instead:
{
"mcpServers": {
"regon": {
"command": "uvx",
"args": ["--from", "/absolute/path/to/regon-mcp", "regon-mcp"],
"env": { "REGON_API_KEY": "abcde12345abcde12345" }
}
}
}
| Variable | Default | Description |
|---|---|---|
REGON_API_KEY | public test key | Your GUS BIR USER_KEY. |
REGON_ENV | test | test (anonymized data) or prod (live data). |
REGON_TIMEOUT | 30 | HTTP timeout in seconds. |
Use REGON_ENV=prod only with a real USER_KEY; the test key works only
against the test environment.
git clone https://github.com/SmartMobileHouse/regon-mcp
cd regon-mcp
uv sync # create the venv and install deps
uv run pytest # offline tests: validation, parsing, mocked client,
# and an in-memory MCP tool-discovery smoke test.
# (network tests are deselected by default)
uv run regon-mcp # run the server over stdio
# Live tests against the GUS endpoint (deselected unless opted in):
REGON_RUN_NETWORK=1 uv run pytest -m network # session lifecycle (test env)
REGON_PROD_KEY=<your-key> uv run pytest -m network # positive-control on live data
The client is a small hand-rolled SOAP layer over httpx (see
src/regon_mcp/client.py) — no heavyweight SOAP stack, no runtime WSDL fetch.
USER_KEY with REGON_ENV=prod.source block).MIT © Smart Mobile House
FAQs
Model Context Protocol server for the Polish GUS REGON business register (BIR1 API).
We found that regon-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.