Malwagon

Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
100%
Integridad del esquema
100%
Calidad de los nombres
92%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~1,282Tokens (definiciones de herramientas)
~1.9 KBTamaño de respuesta típico
Impacto moderado en la atención (1.00% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "malwagon": {
      "url": "https://malwagon.com/mcp"
    }
  }
}

Puntos de conexión remotos

https://malwagon.com/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (5)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
🟢lookup_hash(sha256)

Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searches scans that already exist on this platform. Answers with an empty list when the hash is unknown or not visible to this token, without distinguishing the two.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string",
      "description": "A 64 character hex SHA-256 digest.",
      "minLength": 64,
      "maxLength": 64
    }
  },
  "required": [
    "sha256"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "sha256": {
      "type": "string"
    },
    "scans": {
      "type": "object",
      "description": "A bounded list: items plus what was returned, counted and cut.",
      "properties": {
        "items": {
          "type": "array"
        },
        "returned": {
          "type": "integer"
        },
        "total": {
          "type": "integer"
        },
        "truncated": {
          "type": "boolean"
        }
      },
      "required": [
        "items",
        "returned",
        "total",
        "truncated"
      ]
    }
  },
  "required": [
    "sha256",
    "scans"
  ]
}
🟢get_report(scan_id)

The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never contains the sample's bytes, its decompiled source, a download link or an artifact reference. Every list in the result reports what was returned, counted and truncated. Answers 'not found' for a scan that does not exist and for one this token may not read, identically.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "integer",
      "description": "The scan's numeric id."
    }
  },
  "required": [
    "scan_id"
  ],
  "additionalProperties": false
}
🟢search_indicator(indicator, type)

Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; defanged input such as 'evil[.]com' is refanged first. Only scans this token may read are searched.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "indicator": {
      "type": "string",
      "description": "The exact indicator value. Defanged forms are accepted.",
      "maxLength": 512
    },
    "type": {
      "type": "string",
      "description": "Optional indicator type to narrow the search: ip, domain, url, md5, sha1, sha256, imphash, mutex, registry, filepath, email, ja3, ja4, user_agent."
    }
  },
  "required": [
    "indicator"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "indicator": {
      "type": "string"
    },
    "matches": {
      "type": "object",
      "description": "A bounded list: items plus what was returned, counted and cut.",
      "properties": {
        "items": {
          "type": "array"
        },
        "returned": {
          "type": "integer"
        },
        "total": {
          "type": "integer"
        },
        "truncated": {
          "type": "boolean"
        }
      },
      "required": [
        "items",
        "returned",
        "total",
        "truncated"
      ]
    }
  },
  "required": [
    "indicator",
    "matches"
  ]
}
🟢poll_scan(scan_id)

The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_available' means get_report will return a full report. Answers 'not found' for an unknown scan and an unreadable one identically.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "integer",
      "description": "The scan's numeric id."
    }
  },
  "required": [
    "scan_id"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "integer"
    },
    "module": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "verdict": {
      "type": [
        "string",
        "null"
      ]
    },
    "score": {
      "type": [
        "integer",
        "null"
      ]
    },
    "tags": {
      "type": "object"
    },
    "submitted_at": {
      "type": [
        "string",
        "null"
      ]
    },
    "finished_at": {
      "type": [
        "string",
        "null"
      ]
    },
    "sha256": {
      "type": [
        "string",
        "null"
      ]
    },
    "size": {
      "type": [
        "integer",
        "null"
      ]
    },
    "mime": {
      "type": [
        "string",
        "null"
      ]
    },
    "terminal": {
      "type": "boolean"
    },
    "report_available": {
      "type": "boolean"
    }
  }
}
🟡submit_scan(module, target, private)

Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or a document is not possible over MCP. This spends the account's own credits and is subject to its plan limits. Poll the returned scan_id with poll_scan, then read it with get_report.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "module": {
      "type": "string",
      "enum": [
        "hash",
        "url",
        "command",
        "package"
      ],
      "description": "hash: look up a SHA-256. url: visit a URL in a browser VM. command: run a command line in a Windows VM. package: install a package in a Linux VM. url and package detonate with internet access and are refused on a plan that does not include it."
    },
    "target": {
      "type": "string",
      "description": "The digest, URL, command line or package specifier, matching the chosen module.",
      "maxLength": 2048
    },
    "private": {
      "type": "boolean",
      "description": "Keep the scan off the public corpus. Free plans cannot make a scan private and this is ignored for them."
    }
  },
  "required": [
    "module",
    "target"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "integer"
    },
    "module": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "verdict": {
      "type": [
        "string",
        "null"
      ]
    },
    "score": {
      "type": [
        "integer",
        "null"
      ]
    },
    "tags": {
      "type": "object"
    },
    "submitted_at": {
      "type": [
        "string",
        "null"
      ]
    },
    "finished_at": {
      "type": [
        "string",
        "null"
      ]
    },
    "sha256": {
      "type": [
        "string",
        "null"
      ]
    },
    "size": {
      "type": [
        "integer",
        "null"
      ]
    },
    "mime": {
      "type": [
        "string",
        "null"
      ]
    },
    "terminal": {
      "type": "boolean"
    },
    "report_available": {
      "type": "boolean"
    }
  }
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada5 herramientas
verificadoversión no registrada5 herramientas