MCP 服务器

Malwagon

com.malwagon/malwagon
安全 公开且可连接 MCP 2025-11-25

此 MCP 可以做什么

Submits URLs, commands, packages, or hashes to a malware sandbox and retrieves scan status, reports, hashes, and observed indicators.

get_report
Read an analysis report
The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never contains the sample's bytes, its decompiled source, a download link or an artifact reference. Every list in the result reports what was returned, counted and truncated. Answers 'not found' for a scan that does not exist and for one this token may not read, identically.
只读
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'integer', 'description': "The scan's numeric id."}}, 'additionalProperties': False}
lookup_hash
Look up a SHA-256
Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searches scans that already exist on this platform. Answers with an empty list when the hash is unknown or not visible to this token, without distinguishing the two.
只读
输入模式
{'type': 'object', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'maxLength': 64, 'minLength': 64, 'description': 'A 64 character hex SHA-256 digest.'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'required': ['sha256', 'scans'], 'properties': {'scans': {'type': 'object', 'required': ['items', 'returned', 'total', 'truncated'], 'properties': {'items': {'type': 'array'}, 'total': {'type': 'integer'}, 'returned': {'type': 'integer'}, 'truncated': {'type': 'boolean'}}, 'description': 'A bounded list: items plus what was returned, counted and cut.'}, 'sha256': {'type': 'string'}}}
poll_scan
Poll a scan's progress
The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_available' means get_report will return a full report. Answers 'not found' for an unknown scan and an unreadable one identically.
只读
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'integer', 'description': "The scan's numeric id."}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'mime': {'type': ['string', 'null']}, 'size': {'type': ['integer', 'null']}, 'tags': {'type': 'object'}, 'score': {'type': ['integer', 'null']}, 'module': {'type': 'string'}, 'sha256': {'type': ['string', 'null']}, 'status': {'type': 'string'}, 'scan_id': {'type': 'integer'}, 'verdict': {'type': ['string', 'null']}, 'terminal': {'type': 'boolean'}, 'finished_at': {'type': ['string', 'null']}, 'submitted_at': {'type': ['string', 'null']}, 'report_available': {'type': 'boolean'}}}
search_indicator
Search for an indicator
Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; defanged input such as 'evil[.]com' is refanged first. Only scans this token may read are searched.
只读
输入模式
{'type': 'object', 'required': ['indicator'], 'properties': {'type': {'type': 'string', 'description': 'Optional indicator type to narrow the search: ip, domain, url, md5, sha1, sha256, imphash, mutex, registry, filepath, email, ja3, ja4, user_agent.'}, 'indicator': {'type': 'string', 'maxLength': 512, 'description': 'The exact indicator value. Defanged forms are accepted.'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'required': ['indicator', 'matches'], 'properties': {'matches': {'type': 'object', 'required': ['items', 'returned', 'total', 'truncated'], 'properties': {'items': {'type': 'array'}, 'total': {'type': 'integer'}, 'returned': {'type': 'integer'}, 'truncated': {'type': 'boolean'}}, 'description': 'A bounded list: items plus what was returned, counted and cut.'}, 'indicator': {'type': 'string'}}}
submit_scan
Submit a scan
Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or a document is not possible over MCP. This spends the account's own credits and is subject to its plan limits. Poll the returned scan_id with poll_scan, then read it with get_report.
可访问外部资源
输入模式
{'type': 'object', 'required': ['module', 'target'], 'properties': {'module': {'enum': ['hash', 'url', 'command', 'package'], 'type': 'string', 'description': 'hash: look up a SHA-256. url: visit a URL in a browser VM. command: run a command line in a Windows VM. package: install a package in a Linux VM. url and package detonate with internet access and are refused on a plan that does not include it.'}, 'target': {'type': 'string', 'maxLength': 2048, 'description': 'The digest, URL, command line or package specifier, matching the chosen module.'}, 'private': {'type': 'boolean', 'description': 'Keep the scan off the public corpus. Free plans cannot make a scan private and this is ignored for them.'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'mime': {'type': ['string', 'null']}, 'size': {'type': ['integer', 'null']}, 'tags': {'type': 'object'}, 'score': {'type': ['integer', 'null']}, 'module': {'type': 'string'}, 'sha256': {'type': ['string', 'null']}, 'status': {'type': 'string'}, 'scan_id': {'type': 'integer'}, 'verdict': {'type': ['string', 'null']}, 'terminal': {'type': 'boolean'}, 'finished_at': {'type': ['string', 'null']}, 'submitted_at': {'type': ['string', 'null']}, 'report_available': {'type': 'boolean'}}}
已添加
submit_scan
2026年9月17日 12:36
已添加
poll_scan
2026年9月17日 12:36
已添加
search_indicator
2026年9月17日 12:36
已添加
get_report
2026年9月17日 12:36
已添加
lookup_hash
2026年9月17日 12:36