VirusTotal reports, file and URL submissions, domain/IP reanalysis, and analysis recovery.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
The official VirusTotal MCP server gives your agent threat intelligence before it opens a link, runs a downloaded file or investigates suspicious infrastructure. vt-mcp connects MCP clients to VTAI, with reports for files, URLs, domains and IP addresses, file and network analysis submission, and receipt recovery.
Use the free VTAI service with its current access limits. You do not need your own VirusTotal API key.
Use https://ai.virustotal.com/mcp in a compatible remote MCP client. Sign in
with your VTAI account and approve the connection's permissions; no local Python
installation, static token or personal VirusTotal API key is required.
The official plugin includes the OAuth connection, a threat-intelligence skill and local file uploads without model-generated base64.
Requires Claude Code 2.1.283 or later and Node.js 22 or later on its PATH. Node.js 22 and 24 are verified by the plugin CI. The plugin includes https://ai.virustotal.com/mcp.
If you previously used claude mcp add virustotal, run claude mcp remove virustotal
(use the same --scope if specified); see migration and recovery details.
Start a new session or use /reload-plugins, then /mcp to complete browser
sign-in when needed. The plugin already supplies the MCP connection; do not add
a duplicate. See plugin setup, file access and credential-name protection.
For report lookups without the local upload hook, use the direct connection:
Open Claude Code, run /mcp, select virustotal and complete browser sign-in.
See the Claude Code OAuth instructions
and the VirusTotal connection guide.
Choose this alternative or the plugin. Adding a server configures it; complete authentication and a tool call to check
that your connection works.
OAuth connections share the signed-in VTAI account's free quota and use the
permissions approved for each connection. Existing Agent Tokens keep their rights
and quotas. If your client needs configurable HTTP headers, use one protected
Authorization: Bearer or x-apikey credential instead of OAuth. Other local
clients can use the stdio installation below.
~/.config/vt-mcp/token. Set the MCP server's environment variable VTAI_TOKEN_FILE to that path and its command to vt-mcp. The file contains only the token; never put the token itself in chat, command arguments or project files.| Client | Setup |
|---|---|
Antigravity CLI (agy) | Local stdio or native OAuth recipe |
| Claude Code | OAuth plugin with local file uploads, HTTP or local stdio |
| Codex | HTTP or local stdio |
| ChatGPT Work | Personal OAuth connection |
| Cursor | HTTP recipe |
| VS Code with GitHub Copilot | HTTP recipe |
| GitHub Copilot CLI | HTTP OAuth recipe or local stdio |
| Devin CLI | HTTP OAuth recipe or local stdio |
| Windsurf / Devin Desktop | Cascade HTTP recipe |
| Antigravity IDE | Local stdio configuration or native OAuth recipe |
| Gemini CLI | Install the OAuth extension |
Remote OAuth configuration for GitHub Copilot CLI and Devin CLI follows their official documentation; an OAuth-authenticated VirusTotal tool workflow has not yet been verified in either client.
The client guide distinguishes documented configuration, local transport checks and workflows exercised with a model. A recipe is not a claim of full validation in every client. Other agents can use the same MCP endpoint or the VTAI API directly.
In ChatGPT, creating a plugin/application and connecting your personal account are separate steps. The ChatGPT setup guide covers both, then a first MCP query in a new Work chat. Initial OAuth consent, an IP report, automatic token renewal and a subsequent report after token expiry were verified on 2026-09-24; the guide records the remaining validation limits.
For a first query, ask your agent:
Use VirusTotal to look up the SHA-256 hash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Explain the source, analysis date, coverage and limitations.
This is the empty-file hash. A report lookup does not read or upload local files. A missing report remains unknown, and zero detections do not establish safety.
For local stdio, install uv and run:
The local MCP server supports Linux, macOS and Windows, including both file submission tools. Windows submission receipts require local NTFS storage; network shares and reparse points are rejected. The separate vt-mcp guard command remains Linux-only.
For automatic client configuration, use the setup guide and choose your operating system. It configures Agy, Claude Code or Codex and protects the token using owner-only POSIX permissions or a Windows user-only ACL.
The command installs the package from the official PyPI index in an isolated tool environment. Python 3.12 or newer is required. Keep vt-mcp on the MCP client's PATH, or use its absolute executable path. The package does not modify client configuration.
Use the setup guide to check the configured transport and update a setup-managed installation without creating another token. Restart the client after an update. A configuration check does not exercise a tool or certify the model's behavior.
If your client runs a manually installed vt-mcp executable, upgrade that environment:
A client configured with uvx ... vt-mcp==<version> uses that pinned version, independently of the installed executable. Update its pin or use the setup guide. Hosted HTTP connections use the deployed server; they do not need a local package upgrade. Keep existing tokens and submission receipts.
Missing-report, quota and temporary-service errors include next_steps and a documentation link. For unfamiliar files without a report, submit their actual bytes using the available file submission tools and the sharing guidance below. A hash alone cannot start an analysis. An unknown URL can use submit_url; domain and IP analyses can be refreshed with reanalyze_domain and reanalyze_ip. Retain a new UUIDv4 request_id before an intended network operation, then recover using that ID. VTAI report lookups do not explicitly submit an analysis request. On quota or temporary service failures, honor retry_after_seconds when present, retain credentials and avoid tight retry loops. Never automatically replay an uncertain submission or replace its request ID: recover its receipt first.
In the agent panel, open MCP Servers β Manage MCP Servers β View raw config and merge this entry with your existing configuration:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/virustotal-2)<a href="https://allmcps.com/mcp/virustotal-2"><img src="https://allmcps.com/api/badge/virustotal-2?style=directory" alt="VirusTotal on AllMCPs" /></a>