ContrastAPI · emploidai Marketplace
emploidai Marketplace
Add-onsAppletsPlugins
Search tools, teams, and capabilitiesPublish
MarketplacePluginsContrastAPI
Plugin
Limited listing

ContrastAPI

by contrastcyber · v0.8.0

Security intelligence API — CVE/KEV lookup, MITRE ATLAS/D3FEND, threat intel, OSINT and more (53 tools).

214 installsUpdated Jun 22, 2026
Documentation
Publisher information is incomplete

This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.

Capabilities

Tools

Available inside your emploidai workspace after installation.

Data sources

Available inside your emploidai workspace after installation.

Category

tool

Version

0.8.0contrastcyber

Requirements

Maximum memory 1MB

Pricing

Not disclosed by publisher

Security & access

Review before installing

CompatibleRequires emploidai 1.0.0+

Permissions

  • Uses tool capability

Dependencies

No additional dependencies

Resources

DocumentationPrivacy policy
emploidai Marketplace

Discover capabilities. Review access. Install inside your workspace.

DocumentationSecuritySupportPrivacyTerms

ContrastAPI Plugin for Dify

Security intelligence API with 53 tools — CVE/EPSS/KEV lookup, domain recon & active web scanning, threat intelligence, IOC enrichment, code security, MITRE ATLAS/D3FEND, Sigma detection rules, and OSINT. No API key required to get started — add a Pro key for higher rate limits.

Tools (53)

Web & Domain Intelligence (15): whois_lookup, dns_lookup, ssl_check, subdomain_enum, domain_report, audit_domain (orchestrated passive audit), contrast_scan (active website security scan — C engine, 11 modules), tech_fingerprint, scan_headers, robots_txt, redirect_chain, brand_assets, seo_audit, wayback_lookup, threat_intel

CVE & Vulnerability Intelligence (9): cve_lookup, cve_search, cve_leading, bulk_cve_lookup (up to 50 CVEs in one call), exploit_lookup, kev_detail, cwe_lookup, get_cvss_details, calculate_risk_score

Threat Intelligence / IOC (5): threat_report (orchestrated IP threat report — Shodan + AbuseIPDB + ASN), ioc_lookup, bulk_ioc_lookup (up to 50 indicators in one call), hash_lookup, phishing_check

Network / OSINT (8): ip_lookup, asn_lookup, email_mx, email_disposable, email_verify, email_security_posture, phone_lookup, username_lookup

Code Security (4): check_secrets, check_injection, check_headers, check_dependencies

Detection Engineering — MITRE ATLAS / D3FEND / Sigma (11): atlas_technique_lookup, atlas_technique_search, bulk_atlas_technique_lookup, atlas_case_study_lookup, atlas_case_study_search, d3fend_defense_lookup, d3fend_defense_search, d3fend_defense_for_attack, d3fend_attack_coverage, sigma_rule_lookup, bulk_sigma_rule_lookup

Authentication (1): password_check — HIBP-style breach check. The plain-text password is SHA-1 hashed inside the plugin process before any network call. The raw password never leaves your machine.

Usage

  1. Install the ContrastAPI plugin from the Dify Marketplace
  2. No configuration needed — it works key-less out of the box; add a Pro API key for higher rate limits
  3. Add any tool to your workflow or agent

Privacy & Data Handling

  • No query logging. Submitted domains, IPs, CVE IDs, file hashes, emails, phone numbers, usernames, and code are not stored. Only the endpoint category and a salted IP hash are logged for rate limiting.
  • No API key required for key-less use, so no identity binding.
  • All upstream sources are public (NVD, EPSS, CISA KEV, Shodan InternetDB, abuse.ch, HIBP via k-anonymity, MalwareBazaar, MITRE ATLAS/D3FEND, SigmaHQ, etc.) — no opaque proprietary feeds.
  • Verify in real time: curl https://api.contrastcyber.com/v1/privacy/my-data returns every row our database has about you.

Full data-handling details: DATA_HANDLING.md.

Links

  • API: https://api.contrastcyber.com
  • Privacy: https://contrastcyber.com/privacy
  • GitHub: https://github.com/UPinar/contrastapi
  • MCP server: the same tools plus the MCP-only tech_stack_cve_audit composite, at https://api.contrastcyber.com/mcp/