VirusTotal MCP Server
# VirusTotal MCP Server (https://mcp.so/server/virustotal-mcp/yassinech-99)
A [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that enables LLMs to interact with the VirusTotal API for malware analysis, URL scanning, and threat intelligence.
## š Features
* **File Analysis**: Upload files or retrieve reports via MD5, SHA-1, or SHA-256 hashes.
* **URL & Domain Intelligence**: Scan URLs and get reputation reports for domains.
* **IP Reputation**: Look up threat data associated with specific IP addresses.
* **Threat Hunting**: Perform advanced searches using VirusTotal query syntax.
* **Community Interaction**: Post comments on files, URLs, domains, or IPs.
## š Prerequisites
1. **VirusTotal API Key**: Obtain one from [VirusTotal](https://www.virustotal.com/).
2. **Python 3.13+**: Required as per `pyproject.toml`.
3. **uv**: Recommended for fast dependency management.
## š Installation
### 1. Clone & Setup
```bash
git clone https://github.com/your-username/virustotal-mcp.git
cd virustotal-mcp
```
2. Configure Environment
Create a .env file in the root directory:
```bash
VIRUSTOTAL_API_KEY=your_api_key_here
API_BASE_URL=https://www.virustotal.com/api/v3
REQUEST_TIMEOUT=30.0
```
3. Install Dependencies
```bash
uv pip install -e .
```
š Claude Desktop Configuration
Add this to your claude_desktop_config.json:
```json
{
"mcpServers": {
"virustotal": {
"command": "uv",
"args": [
"--directory",
"D:\\coolAI\\mcp-client",
"run",
"virustotal_mcp.py"
],
"env": {
"VIRUSTOTAL_API_KEY": "<api_key_here>",
"API_BASE_URL": "https://www.virustotal.com/api/v3",
"REQUEST_TIMEOUT": "30.0"
}
}
}
}
```
## š Available Tools
| Tool | Description |
|------|-------------|
| `virustotal_scan_file` | Upload a local file for analysis. |
| `virustotal_get_file_report` | Get reports via hash. |
| `virustotal_scan_url` / `virustotal_get_url_report` | Scan and analyze URLs. |
| `virustotal_get_domain_report` | Domain-specific threat intel. |
| `virustotal_get_ip_report` | IP address reputation. |
| `virustotal_search` | Search VT intelligence. |
| `virustotal_post_comment` | Add community notes to resources. |
TDQS
Scored across 8 tools
Each tool targets a distinct VirusTotal resource and action: file scan/report, URL scan/report, domain report, IP report, comment posting, and search. The paired scan/get tools are clearly differentiated by verb, so an agent should not confuse them.
All tools use a consistent virustotal_ prefix with snake_case and action-first naming (scan_file, get_file_report, post_comment). The lone 'search' is slightly more general but still follows the prefix and casing convention.
Eight tools is well-scoped for a VirusTotal MCP server. It covers the main object types and operations without bloating the surface with rarely used endpoints.
Core workflows are covered: scanning files/URLs and retrieving file/URL/domain/IP reports, plus search and commenting. Minor gaps remain around comment retrieval/management and possibly advanced analysis features, but no critical dead end for typical threat-intel queries.