proofpoint-mcp
Related Servers
Alternatives to proofpoint-mcp
No user-submitted related servers found.
Related Servers
- AlicenseBqualityAmaintenanceMCP server for KnowBe4 — security awareness training, phishing simulation, and user risk management API integration30Apache 2.0
- AlicenseAqualityAmaintenanceMCP server for Checkpoint Harmony Email & Collaboration (Avanan). Enables AI assistants to manage email security, anti-phishing, anti-malware, and threat detection via the Avanan API.131Apache 2.0
- AlicenseNot gradedqualityAmaintenanceMCP server for Mailprotector — email security management for MSPs, enabling management of customers, domains, users, quarantine, allow/block rules, logs, configuration, and the full long-tail API via a router.Apache 2.0
- AlicenseNot gradedqualityCmaintenanceMCP server for Mimecast Email Security — message tracking, threat intelligence, and email queue management. Enables AI assistants to investigate and manage email security events.1Apache 2.0
- AlicenseAqualityAmaintenanceMCP server for Ironscales — phishing incident management, email classification, and remediation2Apache 2.0
- AlicenseAqualityAmaintenanceMCP server for SpamTitan email security — manage quarantine, allowlists, blocklists, and view email stats9Apache 2.0
TDQS
Scored across 40 tools
Tools are grouped by domain with detailed descriptions, but overlap exists between threat and forensics tools (e.g., threat_get_campaign vs forensics_get_campaign), between TAP all-threats and message/click-specific retrievals, and between multiple report/event summary tools. The sheer number of similarly-shaped list/get/report tools leaves room for misselection without careful reading.
Nearly all tools follow a proofpoint_<domain>_<action/object> snake_case pattern, with clear domain prefixes making navigation predictable. Minor inconsistencies include report tools using noun phrases like reports_threat_summary instead of action verbs, and standalone tools like proofpoint_navigate and proofpoint_status that don't follow the domain-action pattern.
With 40 tools, the surface is heavy and exceeds the typical well-scoped range for an agent toolkit. While Proofpoint is a broad platform and each domain has only a few tools, exposing all of them under one server creates a large, potentially unwieldy namespace. It isn't extreme enough for a 1, but is clearly in the 'too many' range.
The server covers major Proofpoint domains well: quarantine lifecycle, TAP events, DLP incidents, forensic search and pull, smart search, reporting, policy read access, URL handling, and detection events. However, the policy and threat-response surfaces are read-mostly, with no create/update/delete policy, no blocklist/sender remediation, and limited actions beyond forensics pull. This leaves notable admin and response gaps.