← Back to search

@burtthecoder/mcp-virustotal

GitHub Actions Scanned 10d ago

MCP server for VirusTotal API integration

B
75.2 / 100

Versions

1.0.25latest
May 24, 2026
1.0.24
May 24, 2026
1.0.23
May 24, 2026
1.0.22
May 24, 2026
1.0.21
Mar 31, 2026
+ show 16 moreshow less
1.0.20
Mar 3, 2026
1.0.19
Mar 3, 2026
1.0.18
Mar 3, 2026
1.0.17
Mar 3, 2026
1.0.16
Feb 21, 2026
1.0.10
Mar 3, 2025
1.0.9
Jan 16, 2025
1.0.8
Dec 19, 2024
1.0.7
Dec 19, 2024
1.0.6
Dec 19, 2024
1.0.5
Dec 19, 2024
1.0.4
Dec 13, 2024
1.0.3
Dec 13, 2024
1.0.2
Dec 13, 2024
1.0.1
Dec 13, 2024
1.0.0
Dec 13, 2024
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 11

get_url_report
annotations: none low

Get a comprehensive URL analysis report including security scan results and key relationships (communicating files, contacted domains/IPs, downloaded files, redirects, threat actors). Returns the cached VirusTotal report when available, or submits the URL for scanning and waits for results.

get_url_relationship
annotations: none low

Query a specific relationship type for a URL with pagination support. Choose from ${RELATIONSHIPS.url.length} relationship types including communicating files, contacted domains/IPs, downloaded files, redirects, referrers, threat actors, and collections. Useful for paging through the full list when the summary in get_url_report is truncated.

get_file_report
annotations: none low

Get a comprehensive file analysis report using its hash (MD5/SHA-1/SHA-256). Includes detection results, file properties, and key relationships (behaviors, dropped files, network connections, embedded content, threat actors). Returns both the basic analysis and automatically fetched relationship data.

get_file_relationship
annotations: none low

Query a specific relationship type for a file with pagination support. Choose from ${RELATIONSHIPS.file.length} relationship types including behaviors, network connections, dropped files, embedded content, execution chains, and threat actors. Useful for detailed investigation of specific relationship types.

get_ip_report
annotations: none low

Get a comprehensive IP address analysis report including geolocation, reputation data, and key relationships (communicating files, historical certificates/WHOIS, resolutions). Returns both the basic analysis and automatically fetched relationship data.

get_ip_relationship
annotations: none low

Query a specific relationship type for an IP address with pagination support. Choose from ${RELATIONSHIPS.ip.length} relationship types including communicating files, historical SSL certificates, WHOIS records, resolutions, and threat actors. Useful for detailed investigation of specific relationship types.

get_domain_report
annotations: none low

Get a comprehensive domain analysis report including DNS records, WHOIS data, and key relationships (SSL certificates, subdomains, historical data). Optionally specify which relationships to include in the report. Returns both the basic analysis and relationship data.

get_domain_relationship
annotations: none low

Query a specific relationship type for a domain with pagination support. Choose from ${RELATIONSHIPS.domain.length} relationship types including subdomains, resolutions, SSL certificates, WHOIS history, and threat actors. Useful for detailed investigation of specific relationship types.

search_vt
annotations: none low

Search the VirusTotal corpus for files, URLs, domains, IPs, or comments matching a query. Accepts plain IOCs (hash, URL, domain, IP), free text against comments, or VTI-style search modifiers like "type:peexe size:90kb+ tag:signed positives:5+". Paginated via cursor.

get_file_behaviour_summary
annotations: none low

Get a consolidated sandbox behaviour summary for a file (MD5/SHA-1/SHA-256), merged across every sandbox that analyzed it. Returns processes, files, registry, network activity, MITRE ATT&CK techniques, IDS alerts, and signature matches in a single view — far more useful than iterating individual behaviour reports.

get_collection
annotations: none low

Retrieve a VirusTotal collection by ID. Collections represent threat actors, malware families, campaigns, intel reports, and curated IOC sets — often referenced from the related_threat_actors and collections relationships on other tools. Optionally include relationships (files, urls, domains, ip_addresses, references, threat_actors, related_collections, related_references, comments, owner, autogenerated_graphs) to fetch member IOCs in the same call.

Permissions 2

filesystem low
Server uses filesystem capabilities via: fs sync ops
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 63

low
Tool 'get_url_report' has no annotations annotation_checker · 100%
low
Tool 'get_url_relationship' has no annotations annotation_checker · 100%
low
Tool 'get_file_report' has no annotations annotation_checker · 100%
low
Tool 'get_file_relationship' has no annotations annotation_checker · 100%
low
Tool 'get_ip_report' has no annotations annotation_checker · 100%
low
Tool 'get_ip_relationship' has no annotations annotation_checker · 100%
low
Tool 'get_domain_report' has no annotations annotation_checker · 100%
low
Tool 'get_domain_relationship' has no annotations annotation_checker · 100%
low
Tool 'search_vt' has no annotations annotation_checker · 100%
low
Tool 'get_file_behaviour_summary' has no annotations annotation_checker · 100%
low
Tool 'get_collection' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-35jp-ww65-95wh) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-3g43-6gmg-66jw) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-3p68-rc4w-qgx5) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-3w6x-2g7m-8v23) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-42h9-826w-cgv3) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-43fc-jf86-j433) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-445q-vr5w-6q77) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-4hjh-wcwx-xvwj) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-5c9x-8gcm-mpgx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-62hf-57xw-28j9) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-6chq-wfr3-2hj9) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-7q8q-rj6j-mhjq) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-898c-q2cr-xwhg) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-8hc4-vh64-cxmj) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-fvcv-3m26-pcqx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-hfxv-24rg-xrqf) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-j5f8-grm9-p9fc) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-jr5f-v2jv-69x6) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-m7pr-hjqh-92cm) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-mmx7-hfxf-jppx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-p92q-9vqr-4j8v) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-pf86-5x62-jrwf) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-pmv8-rq9r-6j72) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-pmwg-cvhr-8vh7) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-q8qp-cvcw-x6jj) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-vf2m-468p-8v99) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-w9j2-pvgh-6h63) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-wf5p-g6vw-rhxx) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-xhjh-pmcv-23jw) dependency_analyzer · 95%
medium
Vulnerable dependency: axios@1.4.0 (GHSA-xx6v-rp6x-q39c) dependency_analyzer · 95%
medium
Vulnerable dependency: zod@3.22.2 (GHSA-m95q-7qp3-xv42) dependency_analyzer · 95%
medium
Hex string literal (>50 chars) in w0h1v-mcp-virustotal-364ce0d/scripts/smoke-test.mjs:31 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in w0h1v-mcp-virustotal-364ce0d/scripts/smoke-test.mjs:32 entropy_analyzer · 70%
info
package.json metadata manifest_parser · 100%
info
Tool: get_url_report manifest_parser · 75%
info
Tool: get_url_relationship manifest_parser · 75%
info
Tool: get_file_report manifest_parser · 75%
info
Tool: get_file_relationship manifest_parser · 75%
info
Tool: get_ip_report manifest_parser · 75%
info
Tool: get_ip_relationship manifest_parser · 75%
info
Tool: get_domain_report manifest_parser · 75%
info
Tool: get_domain_relationship manifest_parser · 75%
info
Tool: search_vt manifest_parser · 75%
info
Tool: get_file_behaviour_summary manifest_parser · 75%
info
Tool: get_collection manifest_parser · 75%
info
Required env vars (6) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
low
Permission: filesystem access detected permission_analyzer · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 154 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%