@ismalicious/mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ISMALICIOUS_API_KEY | No | isMalicious API key from https://ismalicious.com/app/account. Optional: without it and ISMALICIOUS_API_SECRET the server still starts, offering only the bootstrap_key tool which mints a free key from an email address. | |
| ISMALICIOUS_API_BASE | No | Base URL of the isMalicious API. Defaults to https://ismalicious.com/api. | https://ismalicious.com/api |
| ISMALICIOUS_API_SECRET | No | API secret paired with ISMALICIOUS_API_KEY. Optional; used together with the key. | |
| ISMALICIOUS_TIMEOUT_MS | No | Overrides every tool timeout (gate tools 15s, check_indicator 25s, CVE tools 10s, search_indicators 20s, check_indicators 60s, bootstrap_key 15s). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| bootstrap_keyA | No API key is configured. Mint a free isMalicious API key from an email address, use it for the rest of this session, and return it so it can be saved in the MCP client config (ISMALICIOUS_API_KEY / ISMALICIOUS_API_SECRET). One key per IP address per day; the address receives a link to claim the account. Ask the user for their email before calling. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| quota | Scan quota (GET /gate/quota) and the request quota headers seen on the last billed call. |
TDQS
Scored across 1 tool
With only one tool in the set, there is no possibility of overlap or misselection between tools. The single tool has a single, clearly stated purpose (minting an API key).
The lone tool uses a readable snake_case verb_noun style (bootstrap_key), which is a sensible convention. However, a single name provides no evidence of a consistent pattern across the set, so it cannot be rated as exemplary.
One tool is far too few for a server fronting the isMalicious API, which implies a broader surface (e.g. checking URLs/domains/hashes). The server only exposes an onboarding/auth step rather than the API's actual functionality.
The surface covers only a one-time key bootstrap and none of the security-checking operations the isMalicious API presumably offers. There is no core CRUD/query capability at all, leaving the server severely incomplete for its stated purpose.