Get full metadata for an IP: DNS, ASN, ports, TLS, and location.
AI agents call lookup_ip to retrieve information from MCP-Censys without modifying anything — typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
lookup_ip retrieves and queries existing data about IP addresses without altering or deleting anything. It returns read-only metadata (DNS records, ASN, open ports, TLS certificates, geolocation). Censys is a reconnaissance/search platform, and all sibling tools (host_services, lookup_domain, lookup_domain_detailed, new_fqdns) follow the same read-only pattern. This is a typical low-risk information lookup operation.
From the tool's definition Tool performs 'Get full metadata for an IP' with retrieval operations (DNS, ASN, ports, TLS, location) and is part of a 'reconnaissance' server using the 'Search API' for 'querying' — no modifications, deletions, or code execution.
Documented attack patterns abuse exactly the kind of access lookup_ip gives an agent:
PolicyLayer is an MCP gateway — it sits between your AI agents and MCP-Censys, and nothing reaches the server without passing your rules. This is the rule we recommend for lookup_ip:
{
"version": "1",
"default": "deny",
"tools": {
"lookup_ip": {}
}
} lookup_ip is read-only, so it stays allowed — but everything else on the server is denied unless you say otherwise.
Free to start. No card required.
Get full metadata for an IP: DNS, ASN, ports, TLS, and location. It is categorised as a Read tool in the MCP-Censys MCP Server, which means it retrieves data without modifying state.
Register the MCP-Censys MCP server in PolicyLayer and add a rule for lookup_ip: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches MCP-Censys. Nothing to install.
lookup_ip is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the lookup_ip rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for lookup_ip. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
lookup_ip is provided by the MCP-Censys MCP server (nickpending/mcp-censys). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Start from MCP-Censys, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.
Free to start. No card required.
5 MCP-Censys tools catalogued and risk-classified — across an index of 43,000+ MCP servers.