SerpShield

SerpShield

Enables AI agents to scan real-time search data for brand threats, security vulnerabilities, and DeFi risks via MCP-compatible tools.

Category
访问服务器

README

🛡️ SerpShield — AI Threat Intelligence from Real-Time Search Data

An AI agent that uses SerpApi real-time search data to detect brand threats, security vulnerabilities, and DeFi protocol risk signals across the live web — exposed as MCP-compatible tools for agent orchestration.

Built for the DevNetwork [API + Cloud + AI] Hackathon 2026 — SerpApi "Best AI Use Case" track.

Problem

Threat intelligence is reactive and slow. Security teams learn about phishing campaigns, brand impersonation, and DeFi exploits after the damage is done — usually from a breach notification or a social media post. By then, the attack has already succeeded.

Meanwhile, the answer is already on Google. Search results contain real-time signals: phishing pages indexed hours ago, vulnerability disclosures trending on forums, rug pull discussions appearing in news. But nobody is systematically converting that search data into structured threat intelligence that an AI agent can act on.

Solution

SerpShield is an AI agent that queries SerpApi for real-time search results, classifies them into threat signals (phishing, vulnerability, DeFi risk, brand impersonation, reputation), and produces actionable threat intelligence reports — all exposed as MCP-compatible tools that any AI agent can call.

How it works:

  1. Agent constructs threat-hunting queries (e.g., "OpenAI" phishing OR scam OR impersonation)
  2. Queries SerpApi for real-time Google search results
  3. Classifies each result using threat-type keywords and severity heuristics
  4. Aggregates into a threat intelligence report with a 0–100 threat score and recommendations
  5. Exposes everything as MCP tools so other agents can call them

Unique Angle

Unlike existing SerpApi demos (SEO trackers, price monitors, search aggregators), SerpShield turns search data into security intelligence — and exposes every tool as an MCP-compatible endpoint for AI agent orchestration. It's a threat intel SaaS powered by search data, not a search tool.

Architecture

┌─────────────────────────────────────────────────────┐
│                   Web UI (HTML/CSS/JS)               │
│              Dark dashboard — threat scanner         │
└──────────────────┬──────────────────────────────────┘
                   │ fetch() calls
                   ▼
┌─────────────────────────────────────────────────────┐
│              FastAPI Application (app/main.py)        │
│                                                      │
│  /api/health          → service status                │
│  /api/agent/status    → agent config + tool list     │
│  /api/mcp/tools       → MCP tool discovery endpoint   │
│  /api/mcp (POST)      → MCP tool dispatch endpoint    │
│  /api/demo            → full monitoring cycle (demo) │
│  /api/tools/*         → individual tool endpoints     │
└──────────────────┬──────────────────────────────────┘
                   │ calls
                   ▼
┌─────────────────────────────────────────────────────┐
│              SerpShield Agent (app/agent.py)          │
│                                                      │
│  scan_brand_threats()      → phishing/impersonation  │
│  scan_security_advisories() → CVE/vuln detection      │
│  scan_defi_risks()         → rug pull/exploit scan    │
│  generate_threat_report()  → aggregated report        │
│  list_monitoring_targets() → dashboard summary        │
└──────────────────┬──────────────────────────────────┘
                   │ HTTP GET
                   ▼
┌─────────────────────────────────────────────────────┐
│                    SerpApi                            │
│       Real-time Google search results JSON API       │
│       (falls back to realistic mock data in demo)     │
└─────────────────────────────────────────────────────┘

Deployed on Vercel as a serverless Python function.

Setup (Under 5 Commands)

git clone https://github.com/0xConsole/serpshield.git
cd serpshield
pip install -r requirements.txt
export SERPAPI_API_KEY="your_key"   # optional — demo mode works without it
uvicorn api.index:app --reload       # local dev at http://localhost:8000

Tech Stack

Layer Technology
Backend FastAPI (Python)
Hosting Vercel serverless (free tier)
Data Source SerpApi (real-time Google search results)
Agent Protocol MCP-compatible tools (Model Context Protocol)
Frontend Vanilla HTML/CSS/JS — dark threat intel dashboard
No paid services 100% free tier

What's Real vs. Mocked

Component Status
FastAPI backend ✅ Real — deployed and live
SerpApi integration ✅ Real — live calls when SERPAPI_API_KEY is set
Threat classification engine ✅ Real — keyword + severity heuristics
MCP-compatible tool endpoints ✅ Real — /api/mcp/tools + /api/mcp POST
Web dashboard ✅ Real — interactive threat scanner UI
Demo mode (no API key) ✅ Real — uses realistic mock data so judges can demo without a key
Threat score calculation ✅ Real — weighted severity aggregation
Recommendations engine ✅ Real — rule-based from detected signals

API Endpoints

Endpoint Method Description
/ GET Web dashboard
/api/health GET Service health + SerpApi mode
/api/agent/status GET Agent configuration + tool inventory
/api/mcp/tools GET MCP tool discovery (for agent orchestration)
/api/mcp POST MCP tool dispatch ({"tool": "scan_brand_threats", "args": {"target": "OpenAI"}})
/api/demo GET Full autonomous monitoring cycle (judge demo flow)
/api/tools/scan_brand_threats GET Scan for brand threats (?target=OpenAI)
/api/tools/scan_security_advisories GET Scan for CVEs (?technology=FastAPI)
/api/tools/scan_defi_risks GET Scan DeFi risks (?protocol=Uniswap)
/api/tools/generate_threat_report GET Full threat report (?target=OpenAI)
/api/tools/list_monitoring_targets GET All monitoring targets + scores

SerpApi Track Fit

SerpApi's challenge asks for "an innovative AI application using SerpApi APIs to access reliable, structured, real-time web data" that "solves a meaningful real-world problem."

SerpShield delivers:

  • Innovation: Security/threat intelligence is an unexpected SerpApi use case (judges favor unexpected applications over incremental tweaks)
  • Real-time web data: Every scan queries live Google results via SerpApi
  • Meaningful problem: Threat intelligence is a $10B+ market
  • AI agent: Not just a search tool — an autonomous agent with MCP-compatible tools

License

Apache 2.0 — See LICENSE

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选