{"name":"com.malwagon/malwagon","slug":"malwagon","title":"Malwagon","description":"Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.","url":"https://mcp.market/server/malwagon","rating":null,"grade":"C","score":67,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":8,"stars":null,"forks":null,"downloads_week":null,"last_push_at":null,"license":null},"uptime":{"percent":100,"checks":6,"ok":6,"last_checked_at":"2026-09-20T20:31:35.217Z","last_ok_at":"2026-09-20T20:31:35.217Z","latency_ms":853},"claimed":false,"transport":"remote","callable_via_gateway":true,"default_price_micros":0,"repository":null,"website":"https://malwagon.com","version":"1.1.0","remotes":[{"type":"streamable-http","url":"https://malwagon.com/mcp","headers":[{"description":"Bearer token: a Malwagon API key issued in the console.","isRequired":true,"isSecret":true,"placeholder":"Bearer <token>","name":"Authorization"}]}],"packages":[],"tools":[{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never contains the sample's bytes, its decompiled source, a download link or an artifact reference. Every list in the result reports what was returned, counted and truncated. Answers 'not found' for a scan that does not exist and for one this token may not read, identically.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"scan_id":{"type":"integer","description":"The scan's numeric id."}},"required":["scan_id"],"additionalProperties":false}},{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searches scans that already exist on this platform. Answers with an empty list when the hash is unknown or not visible to this token, without distinguishing the two.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"sha256":{"type":"string","description":"A 64 character hex SHA-256 digest.","minLength":64,"maxLength":64}},"required":["sha256"],"additionalProperties":false}},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_available' means get_report will return a full report. Answers 'not found' for an unknown scan and an unreadable one identically.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"scan_id":{"type":"integer","description":"The scan's numeric id."}},"required":["scan_id"],"additionalProperties":false}},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; defanged input such as 'evil[.]com' is refanged first. Only scans this token may read are searched.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"indicator":{"type":"string","description":"The exact indicator value. Defanged forms are accepted.","maxLength":512},"type":{"type":"string","description":"Optional indicator type to narrow the search: ip, domain, url, md5, sha1, sha256, imphash, mutex, registry, filepath, email, ja3, ja4, user_agent."}},"required":["indicator"],"additionalProperties":false}},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or a document is not possible over MCP. This spends the account's own credits and is subject to its plan limits. Poll the returned scan_id with poll_scan, then read it with get_report.","write_action":true,"price_micros":0,"input_schema":{"type":"object","properties":{"module":{"type":"string","enum":["hash","url","command","package"],"description":"hash: look up a SHA-256. url: visit a URL in a browser VM. command: run a command line in a Windows VM. package: install a package in a Linux VM. url and package detonate with internet access and are refused on a plan that does not include it."},"target":{"type":"string","description":"The digest, URL, command line or package specifier, matching the chosen module.","maxLength":2048},"private":{"type":"boolean","description":"Keep the scan off the public corpus. Free plans cannot make a scan private and this is ignored for them."}},"required":["module","target"],"additionalProperties":false}}],"scan":{"score":67,"grade":"C","scanned_at":"2026-09-19T19:16:57.181Z","report":{"scannerVersion":"0.1.5","scannedAt":"2026-09-19T19:16:57.200Z","components":{"code":{"score":-1,"max":25,"notes":["remote-only server, no package to scan"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 1770ms"]},"poisoning":{"score":15,"max":15,"notes":["5 tool descriptions checked"]},"auth":{"score":8,"max":15,"notes":["API key sent as a header"]},"maintenance":{"score":3,"max":15,"notes":["no repository listed"]},"identity":{"score":4,"max":10,"notes":["verified namespace with website, no repo"]}},"findings":[{"id":"maint.no-repo","severity":"low","component":"maintenance","title":"No source repository listed"}],"inputs":{"probes":[{"url":"https://malwagon.com/mcp","reachable":true,"authRequired":false,"latencyMs":1770,"serverInfo":{"name":"Malwagon","version":"1.0.0"}}],"packages":[],"repo":{"found":false},"icon":{"url":"https://malwagon.com/static/site/icons/favicon-512.png","source":"registry","width":512,"height":512},"presence":{"stars":null,"forks":null,"downloadsWeek":null,"license":null,"lastPushAt":null,"score":8}}}},"grade_history":[],"reviews":[]}