Skip to main content
Glama
yassinech-99

VirusTotal MCP Server

by yassinech-99
README.md

# VirusTotal MCP Server (https://mcp.so/server/virustotal-mcp/yassinech-99)

A [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that enables LLMs to interact with the VirusTotal API for malware analysis, URL scanning, and threat intelligence.

## šŸš€ Features

* **File Analysis**: Upload files or retrieve reports via MD5, SHA-1, or SHA-256 hashes.
* **URL & Domain Intelligence**: Scan URLs and get reputation reports for domains.
* **IP Reputation**: Look up threat data associated with specific IP addresses.
* **Threat Hunting**: Perform advanced searches using VirusTotal query syntax.
* **Community Interaction**: Post comments on files, URLs, domains, or IPs.

## šŸ“‹ Prerequisites

1.  **VirusTotal API Key**: Obtain one from [VirusTotal](https://www.virustotal.com/).
2.  **Python 3.13+**: Required as per `pyproject.toml`.
3.  **uv**: Recommended for fast dependency management.

## šŸ›  Installation

### 1. Clone & Setup
```bash
git clone https://github.com/your-username/virustotal-mcp.git
cd virustotal-mcp
```

2. Configure Environment
Create a .env file in the root directory:
```bash
VIRUSTOTAL_API_KEY=your_api_key_here
API_BASE_URL=https://www.virustotal.com/api/v3
REQUEST_TIMEOUT=30.0
```
3. Install Dependencies
```bash
uv pip install -e .
```

šŸ”Œ Claude Desktop Configuration
Add this to your claude_desktop_config.json:

```json

{
  "mcpServers": {
    "virustotal": {
      "command": "uv",
      "args": [
        "--directory",
        "D:\\coolAI\\mcp-client",
        "run",
        "virustotal_mcp.py"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "<api_key_here>",
        "API_BASE_URL": "https://www.virustotal.com/api/v3",
        "REQUEST_TIMEOUT": "30.0"
      }
    }
}
}
```

## šŸ›  Available Tools

| Tool | Description |
|------|-------------|
| `virustotal_scan_file` | Upload a local file for analysis. |
| `virustotal_get_file_report` | Get reports via hash. |
| `virustotal_scan_url` / `virustotal_get_url_report` | Scan and analyze URLs. |
| `virustotal_get_domain_report` | Domain-specific threat intel. |
| `virustotal_get_ip_report` | IP address reputation. |
| `virustotal_search` | Search VT intelligence. |
| `virustotal_post_comment` | Add community notes to resources. |

TDQS

C2.1/5.0

Scored across 8 tools

Disambiguation5/5

Each tool targets a distinct VirusTotal resource and action: file scan/report, URL scan/report, domain report, IP report, comment posting, and search. The paired scan/get tools are clearly differentiated by verb, so an agent should not confuse them.

Naming Consistency5/5

All tools use a consistent virustotal_ prefix with snake_case and action-first naming (scan_file, get_file_report, post_comment). The lone 'search' is slightly more general but still follows the prefix and casing convention.

Tool Count5/5

Eight tools is well-scoped for a VirusTotal MCP server. It covers the main object types and operations without bloating the surface with rarely used endpoints.

Completeness4/5

Core workflows are covered: scanning files/URLs and retrieving file/URL/domain/IP reports, plus search and commenting. Minor gaps remain around comment retrieval/management and possibly advanced analysis features, but no critical dead end for typical threat-intel queries.

Maintenance

ActivityInactive
ResponsivenessNo issues