Threat.Zone
This MCP server provides AI assistants with comprehensive malware analysis capabilities through integration with the Threat.Zone API, built by the Malwation Team using Python with FastMCP, httpx, and Pydantic. It offers multiple analysis methods including static analysis, dynamic sandbox execution with configurable environments (Windows, macOS, Android, Linux), URL scanning, and CDR (Content Disarm and Reconstruction) processing, alongside detailed result retrieval for indicators of compromise, YARA rules, network traffic, and configuration extraction. The implementation features extensive sandbox customization options (timeout settings, environment selection, evasion techniques), artifact management with download capabilities for sanitized files and HTML reports, and supports both public and private scan modes, making it valuable for security researchers, malware analysts, and AI assistants that need programmatic access to advanced threat analysis workflows.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- security
- Source
- PulseMCP
- Repository
- github.com/threat-zone/threatzonemcp
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve Threat.Zone from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.