mcp-virustotal
Provides tools for checking file, URL, domain, and IP reputation using VirusTotal's API.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-virustotalCheck the reputation of example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@pipeworx/virustotal
VirusTotal MCP — file / URL / domain / IP reputation. BYO API key.
Part of Pipeworx — an MCP gateway connecting AI agents to 1394+ live data sources.
Tools
lookup_file(hash)lookup_url(url)lookup_domain(domain)lookup_ip(ip)
Related MCP server: Threat Intelligence MCP Server
Auth
BYO only — free tier is 4 req/min and 500/day per key. Pass ?_apiKey=<key> on the gateway URL. Register at https://www.virustotal.com/gui/join-us.
Data source
https://www.virustotal.com/api/v3 — header x-apikey.
Quick Start
Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):
{
"mcpServers": {
"virustotal": {
"url": "https://gateway.pipeworx.io/virustotal/mcp"
}
}
}Or connect to the full Pipeworx gateway for access to all 1394+ data sources:
{
"mcpServers": {
"pipeworx": {
"url": "https://gateway.pipeworx.io/mcp"
}
}
}Using with ask_pipeworx
Instead of calling tools directly, you can ask questions in plain English:
ask_pipeworx({ question: "your question about Virustotal data" })The gateway picks the right tool and fills the arguments automatically.
More
License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceProvides comprehensive security analysis tools for querying the VirusTotal API, enabling detailed security reports on URLs, files, IP addresses, and domains with automatic relationship data fetching.3Apache 2.0
- AlicenseAqualityAmaintenanceAggregates real-time threat intelligence from multiple sources including Feodo Tracker, URLhaus, CISA KEV, and ThreatFox, with IP/hash reputation checking via VirusTotal, AbuseIPDB, and Shodan for comprehensive security monitoring.11291MIT
- FlicenseNot gradedqualityDmaintenanceProvides real-time threat intelligence and malware metadata by integrating with MalwareBazaar and VirusTotal APIs. Users can search for IOCs, analyze local file hashes, and access data transformation tools for defensive security research.
- AlicenseAqualityDmaintenanceEnables security analysis of URLs, files, IPs, and domains using the VirusTotal API, with automatic fetching of relationship data to provide comprehensive reports.7431MIT
Related MCP Connectors
Third-party sandbox verdict on any artifact in one call, no account. Also an agent marketplace.
URLhaus MCP — wraps abuse.ch URLhaus malware URL database (free, no auth)
Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/pipeworx-io/mcp-virustotal'
If you have feedback or need assistance with the MCP directory API, please join our Discord server