# Joe Sandbox Cloud

> Use this tool when you need to analyze malware and extract threat intelligence through file and URL submissions, with capabilities for IOC extraction, AI-powered threat summaries, and artifact downloads. It solves problems in threat intelligence gathering, malware research, and incident response automation by providing detailed behavioral insights and dynamic and static analysis capabilities. The tool accepts API key authentication and offers configurable parameters for sandbox environments, making it ideal for building AI assistants and integrating with existing security workflows.

Canonical page: https://skillsregistry.net/skills/joe-sandbox-cloud  
JSON: https://api.skillsregistry.net/v1/skills/joe-sandbox-cloud

## Description

This Joe Sandbox Cloud MCP server by Joe Security LLC provides AI agents with malware analysis capabilities through the Joe Sandbox Cloud API, offering tools for file and URL submission, analysis querying, IOC extraction (domains, IPs, URLs, signatures), AI-powered threat summaries, and artifact downloads (unpacked files, PCAP network captures). Built with Python using FastMCP and featuring async report caching, XML parsing for detailed analysis data, process tree extraction, and comprehensive error handling, the implementation supports both immediate and polling-based analysis workflows with configurable parameters for sandbox environments. The server integrates with Claude Desktop through API key authentication and Terms & Conditions acceptance, making it valuable for threat intelligence gathering, malware research, incident response automation, and building AI assistants that need professional-grade dynamic and static malware analysis capabilities with detailed behavioral insights.

## Trust

- **Trust score (0–1):** 0.88
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** media
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/joe-sandbox-cloud)
- **Repository:** <https://github.com/joesecurity/joesandboxmcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "joe-sandbox-cloud"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/joe-sandbox-cloud` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/joe-sandbox-cloud/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
