STIX Bundle Check
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Use in your browser
Validate a hosted STIX 2.1 bundle or TAXII 2.1 collection with the OASIS stix2-validator: schema errors, unresolved relationship endpoints, and indicator-pattern failures. Compare two bundles by total finding counts and changes among returned findings; capped evidence cannot establish complete or unique differences.
Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.
Open the apps workspace
Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.
Copy one ready-to-send prompt for any agent that supports remote MCP connections.
For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.
ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide
https://powmcp.com/taxii-stix-bundle-check/mcp {
"mcpServers": {
"powmcp-taxii-stix-bundle-check": {
"type": "http",
"url": "https://powmcp.com/taxii-stix-bundle-check/mcp"
}
}
}Terminal agents add this app with one command:
claude mcp add --transport http powmcp-taxii-stix-bundle-check https://powmcp.com/taxii-stix-bundle-check/mcpcodex mcp add powmcp-taxii-stix-bundle-check --url https://powmcp.com/taxii-stix-bundle-check/mcpgemini mcp add --transport http powmcp-taxii-stix-bundle-check https://powmcp.com/taxii-stix-bundle-check/mcpManage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.
Proof
Check a hosted STIX 2.1 threat-intel bundle against the OASIS validator, with exact object, relationship-endpoint, and pattern evidence
Validate one public STIX 2.1 bundle or TAXII 2.1 collection page against the OASIS stix2-validator with exact schema, relationship-endpoint reference, and indicator-pattern evidence, or compare two same-lineage bundles before and after a publish, with a clear spec-conformance-versus-intelligence-truth boundary.
Request cost1 completed result
Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.
bundle_check
Validates one directly hosted public STIX 2.1 threat-intelligence bundle (a bundle URL, a TAXII 2.1 collection objects endpoint, or a pasted bundle up to ~5 MB, fetched under a 64 MB / 5-TAXII-page cap) against the OASIS stix2-validator run offline in a no-network sandbox. Runs --enforce-refs checks for relationship source_ref/target_ref endpoints (not every object-reference field), the stix2-patterns ANTLR indicator-pattern grammar, and the numbered SHOULD/vocab checks under --strict-types/--strict-properties, against the bundled OASIS STIX 2.1 JSON schemas. Returns conformance pass/fail (conforms), the engine version and strictness posture, the detected STIX version, MUST schema errors grouped by object, unresolved references (danglingRefs), indicator-pattern grammar failures (patternErrors), coded SHOULD warnings with their numbered codes, a structural inventory (object counts by type, SROs, indicators, TAXII pages), distinguished states (not-a-stix-bundle vs a bundle that fails; version detected vs not-detected vs unsupported; ref-valid vs enforce-refs-unresolved; pattern-valid vs pattern-grammar-invalid), and truncation. Use for one-bundle conformance and diagnosis: 'is this valid STIX 2.1', 'do its relationship endpoints resolve', 'are its indicator patterns well-formed', 'will it pass our ingest'. A pass means only spec conformance and grammatically valid patterns at the named engine version; relationship-endpoint resolution is reported separately in refState. A pass never establishes that the threat intelligence is true, current, high-confidence, deduplicated, or actionable, which always needs human review. Downloads and validates a live multi-megabyte bundle and can take most of a two-minute budget for large bundles. Tell the user before calling. Never repeat bundle or collection URL query strings or credentials in narration.
bundle_compare
Runs the identical offline stix2-validator validation over exactly two directly hosted public STIX 2.1 bundles (baseline first, revised second) sequentially under one shared two-minute deadline, then reports which returned finding groups increased or decreased. Returns per-bundle hashes, detected STIX versions, conformance verdicts and error/warning counts (documents); a comparability note asserting both resolved to the same STIX version and lineage (flagging the pair not-comparable otherwise); a difference table of returned finding groups with increased counts (regressions) and reduced or removed counts (resolved), keyed by schema/pattern/reference/should family; capped findings cannot establish complete differences or issues unique to either bundle; and a ranking by validation success, conformance state, fewer errors, then fewer warnings, with equal measurements sharing rank. Use for 'did this re-publish regress the bundle', 'which conformance issues changed between the two feeds', and feed-over-feed conformance questions: the same feed before and after a change, or two comparable bundles under one profile. The ranking orders automated conformance only (it never means one bundle's intelligence is truer, more current, or higher-confidence), and human review remains required for both. Each URL may be a STIX bundle or a TAXII collection objects endpoint; caller-asserted lineage sameness is checked against the detected versions, not assumed.
Other apps for the jobs next to STIX Bundle Check.
Scope and boundaries for STIX Bundle Check.
Validate OASIS's hosted APT1 example bundle with enforceRefs, strictTypes, and strictProperties enabled and maxFindings set to 400; a public TAXII 2.1 collection objects URL or pasted bundle can be used instead.
Read documentState, versionState, and checkState first, then interpret conforms with refState, patternState, and typeState. Fix schema and pattern errors, resolve dangling relationship source/target endpoints, and review SHOULD warnings even when conforms is true. Unsupported or unchecked input, aborted strict checks, fetch caps, and finding caps make evidence incomplete. Comparison groups cover returned findings only; capped results cannot establish complete or unique differences.
Reference checks cover relationship source_ref and target_ref endpoints, not every object-reference field. Conformance does not establish that intelligence is true, current, high-confidence, deduplicated, or actionable. Public TAXII acquisition is limited to five pages within 64 MB, pasted bundles to about 5 MB, and per-category caps may truncate findings.