abnormal-mcp
abnormal-mcp is an MCP server for Abnormal Security that enables AI-powered email threat detection, investigation, case management, and remediation.
Navigate & Discover: Use
abnormal_navigateto explore available tools by domain (threats, messages, remediation, abuse, cases) andabnormal_statusto check connection status.Threat Management: List paginated detected threat cases (
abnormal_threats_list) and retrieve full details of a specific threat by ID (abnormal_threats_get), including classification, severity, and related messages — rendered as an interactive card in compatible MCP Apps hosts (e.g., Claude Desktop/web).Message Analysis: List all messages within a threat case (
abnormal_messages_list) and get deep analysis of individual emails (abnormal_messages_get), including headers, URLs, attachments, and AI-based threat assessment.Remediation: Trigger email remediation to remove a malicious message from mailboxes, restore it (unremediate), or check the current remediation status (
abnormal_remediation_manage).Abuse Mailbox: List and review phishing emails reported by users (
abnormal_abuse_list), including whether Abnormal confirmed the threat.Security Cases: List active security investigation cases (
abnormal_cases_list) and retrieve detailed information about a specific case (abnormal_cases_get), including status, analyst notes, associated threats, and timeline.
abnormal-mcp
MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.
Tools
This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.
Navigation
Tool | Description |
| Navigate to a domain (threats, messages, remediation, abuse, cases) |
| Return to domain selection |
Threats domain
Tool | Description |
| List detected threat cases (paginated) |
| Get full details of a specific threat by ID |
Messages domain
Tool | Description |
| List messages within a threat case |
| Get detailed message analysis (headers, URLs, attachments, AI analysis) |
Remediation domain
Tool | Description |
| Trigger or check remediation actions for a message |
Abuse domain
Tool | Description |
| List phishing emails reported via the Abuse Mailbox |
Cases domain
Tool | Description |
| List active security investigation cases |
| Get details of a specific case |
Interactive Threat Card (MCP Apps)
abnormal_threats_getrenders as an interactive threat card in MCP Apps hosts (Claude Desktop/web): subject, sender, attack classification, remediation status, and the messages in the threat. The card is read-only — remediation stays a deliberate, model-mediated action. Plain-JSON behavior is unchanged in other hosts. Neutral by default, brandable viawindow.__BRAND__injection orMCP_BRAND_*env vars (MCP_BRAND_NAME,MCP_BRAND_LOGO_URL,MCP_BRAND_PRIMARY_COLOR,MCP_BRAND_ACCENT_COLOR,MCP_BRAND_BG,MCP_BRAND_TEXT) — no rebuild needed.
Related MCP server: blumira-mcp
Authentication
Abnormal Security uses Bearer token authentication.
Standalone (env mode)
export ABNORMAL_API_TOKEN=your-api-token
node dist/index.jsGenerate your token in the Abnormal portal under Settings > Integrations > API.
Gateway mode
When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.
Running
stdio (for Claude Desktop)
npm install
npm run build
node dist/index.jsHTTP Streamable (for hosted/gateway deployment)
MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.jsDocker
docker compose upDevelopment
npm install
npm run dev # watch mode
npm test # run tests
npm run typecheck # TypeScript type check
npm run build:ui # rebuild the MCP Apps card bundle (only needed when ui/ changes)License
Apache-2.0
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceAn MCP server that integrates ThreatBook's threat intelligence API, offering 15 specialized tools for security analysis. It enables AI models to perform IP reputation checks, domain investigations, file sandbox analysis, and vulnerability intelligence lookups.Last updated47MIT
- Flicense-qualityAmaintenanceAn MCP server for Blumira SIEM platform, enabling management of security event detection, alerts, and threat response through Blumira's API.Last updated
- Alicense-qualityAmaintenanceAn MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.Last updatedApache 2.0
- Flicense-qualityAmaintenanceAn MCP server for Huntress managed security platform, enabling management of agents, incidents, reports, and threat detections through Huntress's API.Last updated1
Related MCP Connectors
An MCP server for Arcjet - the runtime security platform that ships with your AI code.
MCP server for Appcircle mobile CI/CD platform.
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/wyre-technology/abnormal-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server