MCP server for Abnormal Security β AI-powered email threat detection, cases, and remediation.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
MCP server for Abnormal Security β AI-powered threat detection, case management, and email remediation.
This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.
| Tool | Description |
|---|---|
abnormal_navigate | Navigate to a domain (threats, messages, remediation, abuse, cases) |
abnormal_back | Return to domain selection |
| Tool | Description |
|---|---|
abnormal_threats_list | List detected threat cases (paginated) |
abnormal_threats_get | Get full details of a specific threat by ID |
| Tool | Description |
|---|---|
abnormal_messages_list | List messages within a threat case |
abnormal_messages_get | Get detailed message analysis (headers, URLs, attachments, AI analysis) |
| Tool | Description |
|---|---|
abnormal_remediation_manage | Trigger or check remediation actions for a message |
| Tool | Description |
|---|---|
abnormal_abuse_list | List phishing emails reported via the Abuse Mailbox |
| Tool | Description |
|---|---|
abnormal_cases_list | List active security investigation cases |
abnormal_cases_get | Get details of a specific case |
abnormal_threats_get renders as an interactive threat card in MCP Apps
hosts (Claude Desktop/web): subject, sender, attack classification,
remediation status, and the messages in the threat. The card is read-only β
remediation stays a deliberate, model-mediated action. Plain-JSON behavior
is unchanged in other hosts. Neutral by default, brandable via
window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME,
MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR,
MCP_BRAND_BG, MCP_BRAND_TEXT) β no rebuild needed.Abnormal Security uses Bearer token authentication.
Generate your token in the Abnormal portal under Settings > Integrations > API.
When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.
Apache-2.0
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/abnormal-security)<a href="https://allmcps.com/mcp/abnormal-security"><img src="https://allmcps.com/api/badge/abnormal-security?style=directory" alt="Abnormal Security on AllMCPs" /></a>