# Shodan MCP for AI Agents AI Agent Connect

> Shodan MCP lets you search for internet-connected devices and analyze open ports using your AI client. It helps you find vulnerabilities, resolve DNS records, and explore the IoT landscape through natural conversation. You can check your own IP, look up host details, and filter through millions of connected devices to map out attack surfaces or monitor your own organization's exposed services.

## Overview
- **Category:** security-compliance
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_v56kfVzaldu64N35xQgpbhSkfmWiw9wRo7KH9Xgc/ai-agent-connect
- **Tags:** cybersecurity, network-scanning, threat-intelligence, open-ports, banner-grabbing, attack-surface

## Description

This Connector connects your AI client to Shodan, the search engine for internet-connected devices. It lets you explore the digital landscape through natural conversation instead of manual queries. You don't have to worry about the exact syntax for filters or switching between browser tabs to find host information. If you need to know how many hosts are running a specific version in a certain country, or if you want to see the banner info for a suspicious IP, your agent handles the heavy lifting. This is built to work within the Vinkius catalog, making it easy to plug into your existing workflow. You get to spend less time on the mechanics of searching and more time on the actual analysis of the data you find. Imagine asking your agent to identify all exposed databases in a specific region or finding every instance of a certain software version across the globe. Instead of manually parsing through pages of results, you get a direct feed of data. You can quickly check your own public IP for firewall rules or resolve hostnames to IPs without leaving your chat. It turns a complex research process into a simple dialogue, giving you a clear view of the internet's attack surface as it exists right now. You can use it to map out the distribution of IoT devices, identify trends in infrastructure, or find vulnerabilities in specific products. Whether you're looking for a specific port or trying to understand the scale of a security issue, this connection gives you the data you need without the friction of a traditional web interface.

## Tools

### get_account_info
Check your remaining Shodan query credits and account status. This helps you stay on top of your usage limits.

### get_api_info
Monitor your current API plan limits and usage details. It ensures you don't run out of credits during a task.

### dns_resolve
Turn hostnames into IP addresses quickly without leaving your chat. It's great for rapid lookups during research.

### get_facets
Get available filters to build more specific and targeted search queries. This helps refine your search results.

### get_host_info
See every open port, location, and banner for a specific IP address. This provides the most detailed host view.

### get_host_count
See how many devices match your search criteria before you run the query. This saves you from wasting credits.

### get_my_ip
Find your current external IP address for firewall and access control rules. It's useful for quick debugging.

### get_ports
See a list of all ports that Shodan is currently scanning. Use this as a reference for building search queries.

### reverse_dns
Map IP addresses back to their hostnames in a single step. This is helpful for identifying unknown host origins.

### search_hosts
Find internet-connected devices using filters like product, OS, or country. It handles complex queries with ease.

## Prompt Examples

**Prompt:** 
```
Find all Nginx servers in Brazil.
```

**Response:** 
```
### Results for Nginx in Brazil

| IP Address | Port | Product | OS | Location |
| :--- | :--- | :--- | :--- | :--- |
| 186.123.xx.xx | 80 | nginx | Linux | São Paulo |
| 177.45.xx.xx | 443 | nginx | Ubuntu | Rio de Janeiro |
| 191.102.xx.xx | 8080 | nginx | CentOS | Brasília |

**Total results found:** 125,000+
**Common ports:** 80, 443, 8080
```

**Prompt:** 
```
Look up info for IP 8.8.8.8.
```

**Response:** 
```
### Host Details: 8.8.8.8

*   **Hostname:** dns.google
*   **Location:** Mountain View, CA, US
*   **Organization:** Google LLC
*   **Open Ports:**
    *   **53 (DNS):** DNS server
    *   **443 (HTTPS):** DoH (DNS over HTTPS)
*   **Banners:** 
    *   `google: dns server`
```

**Prompt:** 
```
Resolve google.com and github.com to IPs.
```

**Response:** 
```
### DNS Resolution Results

*   **google.com** $\rightarrow$ 142.250.189.14
*   **github.com** $\rightarrow$ 140.82.121.4

*Note: You can ask for more detailed host info for these IPs using the host lookup tool.*
```

## Capabilities

### Find internet-connected devices
Locate specific hardware by product name, operating system, or geographic location.

### Analyze host details
Get a full breakdown of open ports, banners, and location data for any IP address.

### Resolve DNS records
Turn hostnames into IP addresses or perform reverse lookups within your chat.

### Monitor API usage
Keep track of your remaining query credits and current plan details.

### Identify active ports
See which specific ports Shodan is currently scanning across the internet.

### Check public IP
Find your current external IP address for firewall and access control rules.

## Use Cases

### Finding exposed databases
A researcher asks the agent to find all exposed databases in a specific region to check for open ports and banners.

### Checking for banner leaks
A sysadmin asks the agent to check if their web host is showing a specific software version banner to the public.

### Mapping IoT trends
An analyst asks for the distribution of smart cameras in a specific country to identify regional infrastructure trends.

### Quick IP discovery
A developer asks for their current public IP to quickly update a firewall rule for a new remote connection.

## Benefits

- Query complex device sets using natural language instead of memorizing Shodan's specific syntax for every search.
- Get host banners and vulnerability data instantly with get_host_info to prioritize your threat response.
- Save on query costs by using get_host_count to preview results before you commit to a full search.
- Perform rapid DNS and reverse DNS lookups with dns_resolve and reverse_dns during incident response.
- Keep your API usage in check by using get_api_info and get_account_info directly through your agent.
- Identify your public-facing IP for firewall debugging and access control with get_my_ip.

## How It Works

The bottom line is you get a conversational interface for one of the most powerful cybersecurity search engines available.

1. Subscribe to the Shodan MCP in the Vinkius marketplace.
2. Add your Shodan API key to your configuration settings.
3. Ask your AI client to find devices, check ports, or analyze vulnerabilities.

## Frequently Asked Questions

**What is the Shodan MCP for?**
The Shodan MCP lets you search for internet-connected devices, analyze open ports, and discover vulnerabilities using natural language.

**Can I use Shodan MCP for security research?**
Yes, it's a primary tool for security researchers to map attack surfaces, find exposed services, and analyze banners across the globe.

**How do I check my Shodan credits with this?**
You can simply ask your agent to check your account info, and it will pull your remaining query credits and plan details automatically.

**Can it find specific devices like cameras?**
Yes, you can search for specific products like smart cameras, web hosts, or any other internet-connected hardware.

**Does Shodan MCP do DNS lookups?**
Yes, it can resolve hostnames to IP addresses and perform reverse DNS lookups without you needing to leave your current chat.

**Can I find my own public IP address?**
Yes, the Connector can identify your current external IP address, which is very helpful for configuring firewall rules or debugging access.

**How do I get a Shodan API key?**
Sign up for a free account at [**shodan.io**](https://account.shodan.io/register). Your API key is displayed on your account dashboard. Free accounts get limited query credits per month.

**What kind of devices can I find?**
Shodan indexes web servers, routers, smart TVs, webcams, IoT devices, industrial control systems (ICS/SCADA), databases, Docker instances, cloud services and virtually any internet-connected device with an open port.

**How do I search for vulnerabilities?**
Use the vuln: filter in your search query. For example: 'vuln:CVE-2021-44228' for Log4Shell, 'vuln:CVE-2024-3094' for XZ backdoor. Requires a paid Shodan membership for vulnerability search.

**What are some useful search queries?**
Popular queries: 'nginx' (all nginx servers), 'port:3389 country:US' (RDP servers in US), 'apache os:Windows', 'product:"MongoDB" has_screenshot:true', 'port:21' (FTP servers), 'city:"São Paulo" port:80'.