mcp server
under construction
MIT
mecfeedmcp
Governed threat-intel feeds for firewalls (planned)
Planned: governed threat-intel to firewall feeds, built on mecmcp. Under construction: no working code yet, not usable.
About
mecfeedmcp will turn "block this indicator on every firewall" into a governed change: propose, validate, approve, publish. Firewalls pull a versioned feed, so nothing is committed to a device per indicator.
It will be built on the shared mecmcp foundation, with a hardened read-only Rust feed server for firewalls to pull from. It is planned and under construction: there is no working code yet, and it must not be deployed.
Features
- Planned: read indicators from threat-intel sources (MISP first, OpenCTI later), read-only
- Planned: propose feed changes as mecmcp change sets, with deterministic validators (reserved ranges, own prefixes, allowlist, mandatory expiry, entry caps)
- Planned: human approval of the exact digest, and a second human for production
- Planned feed formats: PAN-OS External Dynamic Lists, Junos SRX feeds, FortiGate threat feeds and OPNsense URL tables
- Planned: a hardened read-only Rust feed server (rustls, no unsafe code, signed manifests) that firewalls pull from