# Have I Been Pwned Muse connector

From musedirectory.ai, the independent directory of Meta Muse connectors. Not affiliated with Meta.

## Have I Been Pwned

Check if your email or password has been exposed in a data breach

- Record: https://musedirectory.ai/connector/have-i-been-pwned
- Category: Health
- Developer: Pipeworx (https://pipeworx.io/packs/hibp)
- Muse status: Extra setup. Not in Muse's Connectors list yet. Muse can still use it: its page gives you a request to paste into Muse.
- Health: Working, 488ms, checked 2026-09-28T09:16:11Z
- Endpoint: https://gateway.pipeworx.io/hibp/mcp
- Auth: No account needed; Pricing: unknown
- Screening: Screened, no issues found (2026-09-25T16:31:54Z)
- Source: Found in the official MCP Registry (io.github.pipeworx-io/hibp) https://registry.modelcontextprotocol.io/v0/servers?search=io.github.pipeworx-io%2Fhibp

Connects to Have I Been Pwned to search whether your email address or password appears in known data breaches. Helps you identify compromised accounts and take action to secure them.

Example request: "Check if my email address has been in any data breaches"

How to connect: Not in Muse's Connectors list yet, but Muse can still use it. Paste this into Muse: "Use Have I Been Pwned to help me. It is a free service with an MCP server at https://gateway.pipeworx.io/hibp/mcp. It does not need an API key. Ask me before you share anything with it." Muse asks before it shares anything with the app's site. Meta does not review apps used this way, so only use ones you trust. We tested this in the Muse app on September 24, 2026: Muse used an app's link directly this way and returned a live answer.

Screening checks:
- MCP handshake: pass (Answered in 184ms)
- Domain against threat feeds (Cloudflare security DNS): pass (gateway.pipeworx.io, pipeworx.io not flagged)
- Published packages against the OSV malicious-package database: n/a (No npm or PyPI package published)
- Hidden instructions or invisible characters in tool text: n/a (Tools are behind sign-in)
- Inputs asking for passwords, card numbers or seed phrases: n/a (Tools are behind sign-in)
- Domain and redirects: pass (No redirects off the domain)
- AI review of purpose and tool behavior: pass (No concerns)
