Virustotal MCP server
MCP server for querying VirusTotal API with comprehensive security analysis tools.
149 stars839 downloads/wk
Reviews
Write oneNobody has reviewed Virustotal yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Virustotal tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.10 · 2026-09-28 · same rubric, same numbers if you re-run it
- Code scan19 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 19 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Install Virustotal in Claude Code, Cursor or VS Code
Runs npx -y @burtthecoder/mcp-virustotal on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add virustotal -- npx -y @burtthecoder/mcp-virustotal
What the publisher says
From the Virustotal repository's README, as published. We do not edit it. Read it on GitHub
VirusTotal MCP Server
A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.
Quick Start (Recommended)
Claude Code
claude mcp add --transport stdio --env VIRUSTOTAL_API_KEY=your-key virustotal -- npx -y @burtthecoder/mcp-virustotalCodex CLI
codex mcp add virustotal --env VIRUSTOTAL_API_KEY=your-key -- npx -y @burtthecoder/mcp-virustotalGemini CLI
gemini mcp add -e VIRUSTOTAL_API_KEY=your-key virustotal npx -y @burtthecoder/mcp-virustotalInstalling via Smithery
To install VirusTotal Server for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @burtthecoder/mcp-virustotal --client claudeInstalling Manually
- Install the server globally via npm:
npm install -g @burtthecoder/mcp-virustotal- Add to your Claude Desktop configuration file:
{
"mcpServers": {
"virustotal": {
"command": "mcp-virustotal",
"env": {
"VIRUSTOTAL_API_KEY": "your-virustotal-api-key"
}
}
}
}Configuration file location:
- macOS: ~/Library/Application Support/Claude/claudedesktopconfig.json
- Windows: %APPDATA%\Claude\claudedesktopconfig.json
- Restart Claude Desktop
Using with VS Code
To use this MCP server in VS Code with GitHub Copilot:
- Install the server globally via npm:
npm install -g @burtthecoder/mcp-virustotal- Create or update your VS Code MCP configuration file at:
- macOS/Linux: ~/.vscode/mcp.json
- Windows: %USERPROFILE%\.vscode\mcp.json
- Add the following configuration:
{
"servers": {
"virustotal": {
"command": "mcp-virustotal",
"env": {
"VIRUSTOTAL_API_KEY": "your-virustotal-api-key"
}
}
}
}- Reload VS Code to activate the MCP server
You can then use the VirusTotal tools through GitHub Copilot in VS Code by referencing the available tools in your prompts.
Alternative Setup (From Source)
If you prefer to run from source or need to modify the code:
- Clone and build:
git clone <repository_url>
cd mcp-virustotal
npm install
npm run build- Add to your Claude Desktop configuration:
{
"mcpServers": {
"virustotal": {
"command": "node",
"args": ["/absolute/path/to/mcp-virustotal/build/index.js"],
"env": {
"VIRUSTOTAL_API_KEY": "your-virustotal-api-key"
}
}
}
}HTTP Streaming Transport
The server supports HTTP streaming transport in addition to the default stdio transport. This is useful for running the server as a standalone HTTP service that multiple clients can connect to.
Running in HTTP Streaming Mode
Set the MCP_TRANSPORT environment variable to httpStream:
MCP_TRANSPORT=httpStream MCP_PORT=3000 VIRUSTOTAL_API_KEY=your-key node build/index.jsEnvironment Variables
Docker with HTTP Streaming
docker build -t mcp-virustotal .
docker run -p 3000:3000 \
-e VIRUSTOTAL_API_KEY=your-key \
-e MCP_TRANSPORT=httpStream \
mcp-virustotalShortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Virustotal: common questions
- Is Virustotal MCP server safe?
- Mostly: it is graded B (80/100). Read the Virustotal safety report
- How do I install Virustotal?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Virustotal need an API key?
- Yes. The registry entry asks for
VIRUSTOTAL_API_KEY. - Is Virustotal maintained?
- The last commit was 20 days ago (2026-09-08). The latest release is v1.0.17.
- What can I use instead of Virustotal?
- Servers from other publishers that do the same job: CrowdStrike Falcon MCP Server, Wireshark MCP server and Reversecore MCP server. Compare all Virustotal alternatives.
Alternatives to Virustotal
Same job from other publishers: the closest match first, then the best rated.
- CrowdStrike Falcon MCP ServerConnects AI agents with CrowdStrike Falcon for security analysis and automation.not reviewedEstablishedA
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB
- Npm SentinelAdvanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.not reviewedGrowingA
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB