---
title: "whisper-graph"
description: "Investigation playbooks for the WhisperGraph internet-infrastructure graph: indicator triage that reads coverage before it reports a verdict, bulk triage over a SIEM export, Cypher that passes the server's validator, and"
canonical: https://agentpluginsdirectory.com/plugins/whisper-graph
last-updated: 2026-09-22
---

# whisper-graph
Investigation playbooks for the WhisperGraph internet-infrastructure graph: indicator triage that reads coverage before it reports a verdict, bulk triage over a SIEM export, Cypher that passes the server's validator, and brand-protection sweeps.
- Slug: whisper-graph
- Publisher: Whisper Security
- Repository: https://github.com/whisper-sec/whisper-skills
- Manifest: plugin.json
- Version: 2.0.0
- License: MIT
- Category (editorial): security
- Skills: 4 (whisper-brand-protection, whisper-bulk-triage, whisper-cypher, whisper-investigate)
- MCP servers: 0
- Stars: 1
- Repository created: 2026-05-14
- Repository last pushed: 2026-08-09
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/whisper-graph
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What whisper-graph does, in the publisher's words

WhisperGraph Skills

Investigation playbooks for the WhisperGraph MCP connector, for Claude Code, Claude.ai, and every other client that reads Agent Skills.

WhisperGraph is an internet-infrastructure graph: DNS, BGP and RPKI, IP allocation and GeoIP, WHOIS ownership, email authentication, certificate transparency, web links, physical backbone, and threat feeds, pre-joined, so one traversal crosses layers that are separate products everywhere else. The MCP connector gives an AI assistant read access to it.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/whisper-sec/whisper-skills/HEAD/README.md

## Skills

- whisper-brand-protection: WhisperGraph brand-protection and takedown playbook: find registered lookalike domains impersonating a brand, work out which ones are actually dangerous, attribute them to a registrant, and assemble evidence a registrar or hosting provider will act on. Use when the user asks about typosquats, look…
- whisper-bulk-triage: WhisperGraph bulk indicator triage: score a list of hostnames, IPs, ASNs, CIDRs or prefixes in one pass and return a ranked table an analyst can act on. Use when the user pastes or points at many indicators at once, mentions a list, batch, spreadsheet, CSV, SIEM export, EDR export, firewall log, p…
- whisper-cypher: WhisperGraph Cypher authoring: write read-only queries that pass the server's safety validator and return in milliseconds instead of timing out on billion-node labels. Use when a question has no ready-made WhisperGraph workflow and needs a custom query, when a query was rejected, rewritten, timed…
- whisper-investigate: WhisperGraph investigation playbook: triage a domain, IP, ASN, CIDR or prefix against an internet-infrastructure graph covering DNS, BGP and RPKI, WHOIS ownership, GeoIP, email (SPF/DMARC/DKIM), certificate transparency, TLS fingerprints, web links and threat feeds. Use when the user asks whether…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
