Skip to main content
Glama
threat-zone

Threat.Zone MCP Server

by threat-zone

Related Servers

Alternatives to Threat.Zone MCP Server

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables AI agents to safely fetch malware samples, run isolated headless Ghidra static analysis, and retrieve decompiled function logic, imports, and strings through callable MCP tools.
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Wraps the ScanMalware.com API to enable phishing triage, malware scanning, and certificate inspection through natural language, allowing users to submit scans, retrieve results, and analyze threats via MCP tools.
      Apache 2.0
    • A
      license
      A
      quality
      A
      maintenance
      Enables AI agents to access VirusTotal intelligence through MCP, supporting file, URL, domain, and IP lookups, plus analysis, via remote HTTP or local stdio.
      8
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables LLMs to perform OSINT link-analysis by exposing transforms (DNS, WHOIS, Shodan, etc.) as MCP tools for autonomous investigation and graph enrichment.
      MIT

    TDQS

    B3.4/5.0

    Scored across 31 tools

    Disambiguation4/5

    Most tools have distinct purposes targeting specific submission data types or actions, but some overlap exists. For example, get_submission_indicators and get_submission_iocs could be confusing as both relate to threat indicators, though their descriptions suggest iocs might be a subset. The three scan_file_* tools are well-differentiated by analysis type (CDR, sandbox, static).

    Naming Consistency5/5

    Tool names follow a highly consistent verb_noun pattern throughout. All tools use snake_case with clear prefixes: 'get_' for retrieval, 'download_' for file downloads, 'scan_' for analysis submissions, 'interpret_' for value translation, and 'search_' for searching. This consistency makes the tool set predictable and easy to navigate.

    Tool Count3/5

    With 31 tools, the count feels heavy for a threat analysis server. While the domain involves detailed submission data retrieval, many tools are variations fetching specific artifact types (DNS, HTTP, TCP, UDP, etc.) that could potentially be consolidated. The number exceeds typical well-scoped ranges (3-15 tools), suggesting some tool proliferation.

    Completeness5/5

    The tool set provides comprehensive coverage for a threat analysis platform. It includes submission creation (multiple scan types), retrieval (detailed artifacts, statuses, reports), search capabilities, user/system information, and interpretation helpers. There are no apparent gaps in the core workflow from submission to analysis results retrieval.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues