Skip to main content
Glama
malloryai

Mallory MCP Server

Official
by malloryai
README.md
# Mallory MCP Server (deprecated)

[![PyPI](https://img.shields.io/pypi/v/mallorymcp.svg)](https://pypi.org/project/mallorymcp/)
[![License: Apache 2.0](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)

> **⚠️ This package is deprecated and no longer maintained.**
>
> The local `mallorymcp` stdio server has been replaced by Mallory's hosted
> **Remote MCP** service. The remote service is fully managed, always
> up to date, and requires no local install.
>
> **➡️ Migrate to the Remote MCP service: https://docs.mallory.ai/use/agent/mcp**

## What changed

`mallorymcp` was a local MCP server you ran via `uvx`/`pip` that proxied the
Mallory API to your AI client over stdio. It is no longer published with new
features and will receive no further updates.

All functionality now lives in the **Mallory Remote MCP service**, a hosted
endpoint you connect your AI client to directly. It exposes the same threat
intelligence capabilities (vulnerabilities, threat actors, malware, exploits,
organizations, attack patterns, breaches, products, advisories, stories,
mentions, search, and sources) without any local package to install or keep
up to date.

## How to migrate

Follow the setup guide for your AI client (Cursor, Claude Desktop, Claude Code,
and others) here:

**https://docs.mallory.ai/use/agent/mcp**

Once you've connected the Remote MCP service, you can remove the local server
from your MCP client config and uninstall this package:

```bash
pip uninstall mallorymcp
```

## License

Apache 2.0.

TDQS

A4.4/5.0

Scored across 10 tools

Disambiguation4/5

Most tools have distinct purposes focused on different aspects of threat intelligence (vulnerabilities, threat actors, exploitations), but there is some overlap between 'get_exploitation' and 'get_vulnerability_exploitations' that could cause confusion. The descriptions help clarify that one is for a specific exploitation incident and the other is for exploitations of a specific vulnerability, but the naming doesn't make this distinction clear.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern with snake_case throughout. The naming convention is predictable with 'get_' for retrieving specific items, 'list_' for collections, and 'find_' for search operations, creating a coherent naming scheme.

Tool Count5/5

With 10 tools, this server is well-scoped for a threat intelligence domain. Each tool serves a distinct purpose in vulnerability analysis, threat actor intelligence, and exploitation tracking, providing comprehensive coverage without being overwhelming.

Completeness5/5

The tool set provides complete coverage for threat intelligence operations with clear CRUD-like patterns: find/get vulnerabilities, get vulnerability configurations/detection signatures/exploitations, list/get threat actors, and get/list exploitations. There are no obvious gaps for the stated domain of vulnerability and threat actor intelligence.

Maintenance

ActivityInactive
ResponsivenessNo issues