Malwagon
Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"malwagon": {
"url": "https://malwagon.com/mcp"
}
}
}远程端点
https://malwagon.com/mcpstreamable-http它能做什么
工具清单
工具(5)
🟢lookup_hash(sha256)
Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searches scans that already exist on this platform. Answers with an empty list when the hash is unknown or not visible to this token, without distinguishing the two.
输入模式
{
"type": "object",
"properties": {
"sha256": {
"type": "string",
"description": "A 64 character hex SHA-256 digest.",
"minLength": 64,
"maxLength": 64
}
},
"required": [
"sha256"
],
"additionalProperties": false
}输出模式
{
"type": "object",
"properties": {
"sha256": {
"type": "string"
},
"scans": {
"type": "object",
"description": "A bounded list: items plus what was returned, counted and cut.",
"properties": {
"items": {
"type": "array"
},
"returned": {
"type": "integer"
},
"total": {
"type": "integer"
},
"truncated": {
"type": "boolean"
}
},
"required": [
"items",
"returned",
"total",
"truncated"
]
}
},
"required": [
"sha256",
"scans"
]
}🟢get_report(scan_id)
The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never contains the sample's bytes, its decompiled source, a download link or an artifact reference. Every list in the result reports what was returned, counted and truncated. Answers 'not found' for a scan that does not exist and for one this token may not read, identically.
输入模式
{
"type": "object",
"properties": {
"scan_id": {
"type": "integer",
"description": "The scan's numeric id."
}
},
"required": [
"scan_id"
],
"additionalProperties": false
}🟢search_indicator(indicator, type)
Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; defanged input such as 'evil[.]com' is refanged first. Only scans this token may read are searched.
输入模式
{
"type": "object",
"properties": {
"indicator": {
"type": "string",
"description": "The exact indicator value. Defanged forms are accepted.",
"maxLength": 512
},
"type": {
"type": "string",
"description": "Optional indicator type to narrow the search: ip, domain, url, md5, sha1, sha256, imphash, mutex, registry, filepath, email, ja3, ja4, user_agent."
}
},
"required": [
"indicator"
],
"additionalProperties": false
}输出模式
{
"type": "object",
"properties": {
"indicator": {
"type": "string"
},
"matches": {
"type": "object",
"description": "A bounded list: items plus what was returned, counted and cut.",
"properties": {
"items": {
"type": "array"
},
"returned": {
"type": "integer"
},
"total": {
"type": "integer"
},
"truncated": {
"type": "boolean"
}
},
"required": [
"items",
"returned",
"total",
"truncated"
]
}
},
"required": [
"indicator",
"matches"
]
}🟢poll_scan(scan_id)
The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_available' means get_report will return a full report. Answers 'not found' for an unknown scan and an unreadable one identically.
输入模式
{
"type": "object",
"properties": {
"scan_id": {
"type": "integer",
"description": "The scan's numeric id."
}
},
"required": [
"scan_id"
],
"additionalProperties": false
}输出模式
{
"type": "object",
"properties": {
"scan_id": {
"type": "integer"
},
"module": {
"type": "string"
},
"status": {
"type": "string"
},
"verdict": {
"type": [
"string",
"null"
]
},
"score": {
"type": [
"integer",
"null"
]
},
"tags": {
"type": "object"
},
"submitted_at": {
"type": [
"string",
"null"
]
},
"finished_at": {
"type": [
"string",
"null"
]
},
"sha256": {
"type": [
"string",
"null"
]
},
"size": {
"type": [
"integer",
"null"
]
},
"mime": {
"type": [
"string",
"null"
]
},
"terminal": {
"type": "boolean"
},
"report_available": {
"type": "boolean"
}
}
}🟡submit_scan(module, target, private)
Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or a document is not possible over MCP. This spends the account's own credits and is subject to its plan limits. Poll the returned scan_id with poll_scan, then read it with get_report.
输入模式
{
"type": "object",
"properties": {
"module": {
"type": "string",
"enum": [
"hash",
"url",
"command",
"package"
],
"description": "hash: look up a SHA-256. url: visit a URL in a browser VM. command: run a command line in a Windows VM. package: install a package in a Linux VM. url and package detonate with internet access and are refused on a plan that does not include it."
},
"target": {
"type": "string",
"description": "The digest, URL, command line or package specifier, matching the chosen module.",
"maxLength": 2048
},
"private": {
"type": "boolean",
"description": "Keep the scan off the public corpus. Free plans cannot make a scan private and this is ignored for them."
}
},
"required": [
"module",
"target"
],
"additionalProperties": false
}输出模式
{
"type": "object",
"properties": {
"scan_id": {
"type": "integer"
},
"module": {
"type": "string"
},
"status": {
"type": "string"
},
"verdict": {
"type": [
"string",
"null"
]
},
"score": {
"type": [
"integer",
"null"
]
},
"tags": {
"type": "object"
},
"submitted_at": {
"type": [
"string",
"null"
]
},
"finished_at": {
"type": [
"string",
"null"
]
},
"sha256": {
"type": [
"string",
"null"
]
},
"size": {
"type": [
"integer",
"null"
]
},
"mime": {
"type": [
"string",
"null"
]
},
"terminal": {
"type": "boolean"
},
"report_available": {
"type": "boolean"
}
}
}社区
证据