w0h1v/mcp-virustotal

View on GitHub ↗

MCP server for VirusTotal API — analyze URLs, files, IPs, and domains with comprehensive security reports, relationship analysis, and pagination support.

145 ★21 forksTypeScriptUpdated 3mo ago

What you need to know

MCP server (npm @burtthecoder/mcp-virustotal) for comprehensive VirusTotal analysis of URLs, files, IPs, and domains, with automatic relationship fetching.

Install

npm install -g @burtthecoder/mcp-virustotal or npx via Smithery/Claude Code/Codex/Gemini.

Usage

  • Requires a VIRUSTOTAL_API_KEY; supports stdio and HTTP streaming modes.

Key features

  • URL/file/IP/domain reports with batched relationship fetching
  • 28 relationship query tools with pagination
  • corpus search with VTI-style modifiers
  • cross-sandbox behaviour summary
  • threat collection lookup
Clients: Claude Desktop · VS Code (GitHub Copilot) · Claude Code · Codex CLI · Gemini CLI

Reviewed 2026-08-11

Topics

ai-toolsclaudecybersecurityiocmalware-analysismalware-detectionmcpmcp-servermodel-context-protocolsecuritythreat-intelligencetypescriptvirus-scanningvirustotal
Stars
145★
Forks
21
Language
TypeScript
License
MIT
Created
2024-12-13
Last push
2026-05-24