Mmcp.market

Virustotal MCP server

by BurtTheCoder·io.github.BurtTheCoder/virustotal·v1.0.17·149 stars

MCP server for querying VirusTotal API with comprehensive security analysis tools.

B80/100grade B
What users say
No reviews yet
Be the first
Safety scan
B80/100

full report

Adoption
Established

149 stars839 downloads/wk

Reviews

Write one

Nobody has reviewed Virustotal yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Virustotal tools

No tool declarations could be read from the package source. They show once the server is installed.

Public scan report

scanner v0.1.10 · 2026-09-28 · same rubric, same numbers if you re-run it

no findings
  • Code scan19 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancelast push 19 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Virustotal in Claude Code, Cursor or VS Code

Runs npx -y @burtthecoder/mcp-virustotal on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add virustotal -- npx -y @burtthecoder/mcp-virustotal
Add to Cursor

What the publisher says

From the Virustotal repository's README, as published. We do not edit it. Read it on GitHub

VirusTotal MCP Server

A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.

Quick Start (Recommended)

Claude Code

claude mcp add --transport stdio --env VIRUSTOTAL_API_KEY=your-key virustotal -- npx -y @burtthecoder/mcp-virustotal

Codex CLI

codex mcp add virustotal --env VIRUSTOTAL_API_KEY=your-key -- npx -y @burtthecoder/mcp-virustotal

Gemini CLI

gemini mcp add -e VIRUSTOTAL_API_KEY=your-key virustotal npx -y @burtthecoder/mcp-virustotal

Installing via Smithery

To install VirusTotal Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @burtthecoder/mcp-virustotal --client claude

Installing Manually

  1. Install the server globally via npm:
npm install -g @burtthecoder/mcp-virustotal
  1. Add to your Claude Desktop configuration file:
{
  "mcpServers": {
    "virustotal": {
      "command": "mcp-virustotal",
      "env": {
        "VIRUSTOTAL_API_KEY": "your-virustotal-api-key"
      }
    }
  }
}

Configuration file location:

  • macOS: ~/Library/Application Support/Claude/claudedesktopconfig.json
  • Windows: %APPDATA%\Claude\claudedesktopconfig.json
  1. Restart Claude Desktop

Using with VS Code

To use this MCP server in VS Code with GitHub Copilot:

  1. Install the server globally via npm:
npm install -g @burtthecoder/mcp-virustotal
  1. Create or update your VS Code MCP configuration file at:
  • macOS/Linux: ~/.vscode/mcp.json
  • Windows: %USERPROFILE%\.vscode\mcp.json
  1. Add the following configuration:
{
  "servers": {
    "virustotal": {
      "command": "mcp-virustotal",
      "env": {
        "VIRUSTOTAL_API_KEY": "your-virustotal-api-key"
      }
    }
  }
}
  1. Reload VS Code to activate the MCP server

You can then use the VirusTotal tools through GitHub Copilot in VS Code by referencing the available tools in your prompts.

Alternative Setup (From Source)

If you prefer to run from source or need to modify the code:

  1. Clone and build:
git clone <repository_url>
cd mcp-virustotal
npm install
npm run build
  1. Add to your Claude Desktop configuration:
{
  "mcpServers": {
    "virustotal": {
      "command": "node",
      "args": ["/absolute/path/to/mcp-virustotal/build/index.js"],
      "env": {
        "VIRUSTOTAL_API_KEY": "your-virustotal-api-key"
      }
    }
  }
}

HTTP Streaming Transport

The server supports HTTP streaming transport in addition to the default stdio transport. This is useful for running the server as a standalone HTTP service that multiple clients can connect to.

Running in HTTP Streaming Mode

Set the MCP_TRANSPORT environment variable to httpStream:

MCP_TRANSPORT=httpStream MCP_PORT=3000 VIRUSTOTAL_API_KEY=your-key node build/index.js

Environment Variables

Docker with HTTP Streaming

docker build -t mcp-virustotal .
docker run -p 3000:3000 \
  -e VIRUSTOTAL_API_KEY=your-key \
  -e MCP_TRANSPORT=httpStream \
  mcp-virustotal

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Virustotal: common questions

Is Virustotal MCP server safe?
Mostly: it is graded B (80/100). Read the Virustotal safety report
How do I install Virustotal?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Virustotal need an API key?
Yes. The registry entry asks for VIRUSTOTAL_API_KEY.
Is Virustotal maintained?
The last commit was 20 days ago (2026-09-08). The latest release is v1.0.17.
What can I use instead of Virustotal?
Servers from other publishers that do the same job: CrowdStrike Falcon MCP Server, Wireshark MCP server and Reversecore MCP server. Compare all Virustotal alternatives.

Alternatives to Virustotal

Same job from other publishers: the closest match first, then the best rated.

All Virustotal alternatives →
  • CrowdStrike Falcon MCP Server
    Connects AI agents with CrowdStrike Falcon for security analysis and automation.
    A
  • Wireshark
    Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
    A
  • Reversecore MCP
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
    B
  • Npm Sentinel
    Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
    A
  • npm Registry MCP Server
    npm registry MCP server — package intelligence, security audits, dependency analysis
    B

More from BurtTheCoder →