Malwarebazaar
Server Details
MalwareBazaar MCP — abuse.ch malware sample database (free, key required)
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Uptime
- 43.3% over 38 days
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- pipeworx-io/mcp-malwarebazaar
- GitHub Stars
- 0
- Server Listing
- mcp-malwarebazaar
TDQS
Scored across 40 tools
Several tool clusters are hard to tell apart: ask_pipeworx, ask_pipeworx_beta, and ask_pipeworx_grounded are near-identical entry points, and the polymarket_* family has multiple overlapping edge/arbitrage tools. The descriptions are detailed, but an agent would often need to read long caveats to avoid picking the wrong one.
Names are uniformly snake_case and some families are predictably prefixed (ask_pipeworx_*, polymarket_*, resolution_*), but the set mixes verb-led names with noun-led names like entity_profile, bet_research, and recent_samples. The pattern is readable and searchable but not consistently verb_noun.
Forty tools is heavy for a server named Malwarebazaar, and only about five of them actually serve malware lookup; the rest form a general data/prediction-market toolkit. This feels like several unrelated servers merged into one rather than a well-scoped toolset.
For the advertised MalwareBazaar purpose, the surface is thin: hashes, recent samples, and family/tag/signature search are covered, but there is no sample download, submission, or deeper pivoting, and the 35 non-malware tools do not fill those gaps. Conversely, as a general Pipeworx server the malware tools are an irrelevant appendage, so coverage is mismatched in either reading.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
4 tool updates
- Added
kalshi_weather_edge - Added
release_calendar_markets - Added
resolution_audit - Added
resolution_diff
1 tool update
- Changed
bet_research2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "market": "when-will-bitcoin-hit-150k" - }, - { - "market": "https://polymarket.com/event/when-will-bitcoin-hit-150k" - } -]New value: +[ + { + "market": "will-kristi-noem-win-the-2028-republican-presidential-nomination" + }, + { + "market": "https://polymarket.com/event/will-kristi-noem-win-the-2028-republican-presidential-nomination" + } +] - changed
Input schema / properties / market / descriptionPrevious value: -"Polymarket slug (\"when-will-bitcoin-hit-150k\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."New value: +"Polymarket slug (\"will-kristi-noem-win-the-2028-republican-presidential-nomination\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."
2 tool updates
- Changed
bet_research2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "market": "will-bitcoin-reach-100k-in-july-2026" - }, - { - "market": "https://polymarket.com/event/will-bitcoin-hit-150k-by-june-30-2026" - } -]New value: +[ + { + "market": "when-will-bitcoin-hit-150k" + }, + { + "market": "https://polymarket.com/event/when-will-bitcoin-hit-150k" + } +] - changed
Input schema / properties / market / descriptionPrevious value: -"Polymarket slug (\"will-bitcoin-hit-150k-by-june-30-2026\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k by June 30?\")"New value: +"Polymarket slug (\"when-will-bitcoin-hit-150k\"), full URL (\"https://polymarket.com/event/...\"), or question text (\"Will Bitcoin hit $150k?\"). Dated slugs stop resolving once they settle — Polymarket de-indexes resolved markets — so prefer an undated one."
- Changed
polymarket_kalshi_spread2 fields changed- changed
Input schema / examplesPrevious value: -[ - { - "topic": "fed" - }, - { - "topic": "btc" - } -]New value: +[ + { + "topic": "fed" + }, + { + "topic": "btc" + }, + { + "topic": "bitcoin" + }, + { + "topic": "fed rate decision" + } +] - changed
Input schema / properties / topic / descriptionPrevious value: -"Pre-mapped: fed | btc | cpi | gdp | sp500 | recession | next_pope | next_uk_pm | next_israel_pm | 2028_president"New value: +"Subject to compare. Canonical keys: fed | btc | eth | cpi | gdp | sp500 | recession | next_pope | next_uk_pm | next_israel_pm | 2028_president — but aliases and keywords resolve too (\"bitcoin\", \"fed rate decision\", \"ethereum\", \"inflation\", \"s&p 500\", \"us recession\", \"next pope\", \"2028 election\"). Check resolution.topic_matched_by in the response: \"exact\"/\"alias\" is a curated pairing, \"phrase\"/\"token\" is a keyword guess."
Related MCP Connectors
ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)
URLhaus MCP — wraps abuse.ch URLhaus malware URL database (free, no auth)
VirusTotal MCP — file / URL / domain / IP reputation (BYO key)
AlienVault OTX MCP — Open Threat Exchange (free with key)
Related MCP Servers
- AlicenseAqualityCmaintenanceMCP server for accessing URLhaus malicious URL database from abuse.ch - provides threat intelligence for cybersecurity research76 npm5MIT
- AlicenseNot gradedqualityCmaintenanceAn AI-driven MCP server that autonomously interfaces with Malware Bazaar, delivering real-time threat intel and sample metadata for authorized cybersecurity research workflows.30Apache 2.0
- AlicenseNot gradedqualityDmaintenanceEnables querying threat intelligence data about files, URLs, IPs, and domains from multiple abuse.ch platforms (MalwareBazaar, URLhaus, and ThreatFox) through a unified API. Provides comprehensive security reports and threat analysis data for cybersecurity investigations.3MIT
- AlicenseAqualityFmaintenanceMCP server for Speakeasy — Windows API emulation for binary analysis. It runs a .exe in a Wine-like sandbox and returns a structured API trace.3MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.