Developer Tools · Security

threatzonemcp

threat-zone/threatzonemcp

A Model Context Protocol (MCP) server for the Threat.Zone API, built with FastMCP. This server provides LLMs with access to Threat.Zone's malware analysis capabilities through standardized MCP tools.

Install

pip install threatzone-mcp

Client configuration

{
  "mcpServers": {
    "threatzone": {
      "command": "uv",
      "args": [
        "run",
        "--directory",
        "/full/path/to/your/threatzonemcp",
        "threatzone-mcp"
      ],
      "env": {
        "THREATZONE_API_KEY": "<THREATZONE_API_KEY>",
        "THREATZONE_API_URL": "<THREATZONE_API_URL>"
      }
    }
  }
}

Environment variables

THREATZONE_API_KEYTHREATZONE_API_URL
Category
Developer Tools, Security
License
GPL-3.0
Updated
Oct 6, 2026

Features

  • File Analysis: Submit files for malware analysis including sandbox execution, static analysis, and CDR (Content Disarm and Reconstruction)

  • URL Analysis: Analyze URLs for threats and malicious content

  • Submission Management: Retrieve detailed analysis results, indicators, IoCs, and YARA rules

  • Network Analysis: Access DNS queries, HTTP/TCP/UDP requests, and network threats

  • Report Generation: Download sanitized files and HTML reports

  • User Management: Get user information and submission limits

Tools (11)

  • Artifacts

    get_submission_artifacts, get_submission_config_extractor

  • Constants

    get_metafields, get_levels, get_statuses, get_sample_metafield

  • Search

    search_by_hash

  • Files

    download_sanitized_file (CDR-cleaned files)

  • Reports

    download_html_report (detailed analysis reports)

  • get_metafields

    Get available metafields for advanced configuration

  • get_levels

    Get threat levels

  • get_statuses

    Get submission statuses

  • get_sample_metafield

    Get sample configuration for sandbox analysis

  • get_server_config

    Get current server configuration and connection status

  • get_user_info

    Get current user information and limits

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools