The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Proofpoint listing page.
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.
Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
Set the following environment variables:
| Variable | Required | Description |
|---|---|---|
PROOFPOINT_SERVICE_PRINCIPAL | Yes | Your Proofpoint TAP service principal |
PROOFPOINT_SERVICE_SECRET | Yes | Your Proofpoint TAP service secret |
PROOFPOINT_BASE_URL | No | Custom base URL (default: tap-api-v2.proofpoint.com) |
MCP_TRANSPORT | No | Transport mode: stdio (default) or http |
Add to your Claude Desktop claude_desktop_config.json:
proofpoint_threat_get_by_id renders as an interactive, read-only card in
MCP Apps hosts (Claude Desktop/web) showing the threat name, status,
category, severity, and resolved actor / malware-family / campaign names;
plain-JSON behavior is unchanged in other hosts. The card is neutral by
default and brandable via window.__BRAND__ injection or MCP_BRAND_* env
vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR,
MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild
needed.
Data loss prevention policies
Security event stream and SIEM export
Forensic analysis of threats
Very Attacked People (VAP) reporting
Email policy management
Email quarantine management
Security reports and summaries
Advanced email search
Targeted Attack Protection events and campaigns
Threat intelligence and indicators of compromise
URL rewriting and click defense
Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.
Licensed under the Apache License, Version 2.0. See LICENSE for details.