VirusTotal MCP
OfficialRelated Servers
Alternatives to VirusTotal MCP
No user-submitted related servers found.
Related Servers
- FlicenseAqualityDmaintenanceMCP server for security analysis using VirusTotal API, enabling AI assistants to analyze URLs, files, IP addresses, and domains with automatic relationship fetching.81-
- AlicenseAqualityAmaintenanceEnables AI agents to access VirusTotal intelligence through MCP, supporting file, URL, domain, and IP lookups, plus analysis, via remote HTTP or local stdio.8MIT
- FlicenseNot gradedqualityCmaintenanceA production-ready MCP server providing comprehensive integration with Google Threat Intelligence and VirusTotal API v3, enabling AI agents to access threat intelligence data including IoCs, malware analysis, and network telemetry.-
- AlicenseAqualityBmaintenanceA MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.11342 npm150MIT
- AlicenseCqualityDmaintenanceA Model Context Protocol (MCP) server that enables LLMs to interact with the VirusTotal API for malware analysis, URL scanning, and threat intelligence.81MIT
- AlicenseBqualityDmaintenanceComprehensive forensic analysis MCP server enabling AI agents to analyze files, Chromium and Firefox browser artifacts, with VirusTotal, DIE, Binwalk integrations.51MIT
TDQS
Scored across 11 tools
Most tools have clearly distinct purposes (lookup vs. submit vs. reanalyze vs. retrieve analysis/receipt), and the long descriptions explicitly distinguish them. A few pairs could still be confused at a glance, notably submit_file vs. submit_local_file (both submit file content) and get_submission vs. get_analysis (both retrieve prior operation state).
All tool names use a consistent snake_case verb_noun pattern: get_*, submit_*, reanalyze_*. The only variation is that report-lookup tools include the resource suffix (_report), while get_submission and get_analysis do not, but this still fits the same verb_noun convention.
11 tools is well within the typical 3-15 range and each tool corresponds to a distinct VirusTotal operation or indicator type. The set is neither bloated nor thin for the server's threat-intelligence scope.
The surface covers core workflows: report lookups for file/URL/domain/IP, submissions (file, local file, URL), reanalysis for domain/IP, and analysis/receipt retrieval. Minor gaps exist, such as no reanalyze_url or reanalyze_file tool, and no search, relationship, or behavior endpoints, but agents can work around these for common tasks.