Mallory MCP Server
OfficialMallory MCP Server (deprecated)
⚠️ This package is deprecated and no longer maintained.
The local
mallorymcpstdio server has been replaced by Mallory's hosted Remote MCP service. The remote service is fully managed, always up to date, and requires no local install.➡️ Migrate to the Remote MCP service: https://docs.mallory.ai/use/agent/mcp
What changed
mallorymcp was a local MCP server you ran via uvx/pip that proxied the
Mallory API to your AI client over stdio. It is no longer published with new
features and will receive no further updates.
All functionality now lives in the Mallory Remote MCP service, a hosted endpoint you connect your AI client to directly. It exposes the same threat intelligence capabilities (vulnerabilities, threat actors, malware, exploits, organizations, attack patterns, breaches, products, advisories, stories, mentions, search, and sources) without any local package to install or keep up to date.
How to migrate
Follow the setup guide for your AI client (Cursor, Claude Desktop, Claude Code, and others) here:
https://docs.mallory.ai/use/agent/mcp
Once you've connected the Remote MCP service, you can remove the local server from your MCP client config and uninstall this package:
pip uninstall mallorymcpLicense
Apache 2.0.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/malloryai/mallorymcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server