TriageMCP (PE File Analysis)
TriageMCP is a server that enables LLMs to perform basic static analysis of PE (Portable Executable) files. It integrates with multiple security tools including detect-it-easy, YARA, capa, floss, and UPX to extract critical information such as import/export tables, section details, metadata, strings, and capabilities. The implementation provides tools for calculating file hashes, analyzing PE structures, scanning with YARA rules, unpacking UPX-compressed executables, and identifying malware capabilities - making it particularly valuable for security analysts who need to quickly triage suspicious Windows executables without manual tool interaction.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-19.
Scan details: Circle-IR · 2026-09-19 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- ai-ml
- Source
- PulseMCP
- Repository
- github.com/eversinc33/triagemcp
- Author type
- human
- Last scanned
- 2026-09-19
- Updated
- 2026-09-19
Use via MCP
Resolve TriageMCP (PE File Analysis) from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.