Back to Browse

Proofpoint MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

About

MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

4 files analyzed · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Proofpoint TAP service principal (API user identifier)Optional

Environment variable: PROOFPOINT_SERVICE_PRINCIPAL

Proofpoint TAP service secretRequired

Environment variable: PROOFPOINT_SERVICE_SECRET

Proofpoint TAP API base URL (defaults to https://tap-api-v2.proofpoint.com)Optional

Environment variable: PROOFPOINT_BASE_URL

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

Documentation

View on GitHub

From the project's GitHub README.

Proofpoint MCP Server

License Node.js

A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.

This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.

Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.

Installation

npm install @wyre-ai/proofpoint-mcp

Configuration

Set the following environment variables:

VariableRequiredDescription
PROOFPOINT_SERVICE_PRINCIPALYesYour Proofpoint TAP service principal
PROOFPOINT_SERVICE_SECRETYesYour Proofpoint TAP service secret
PROOFPOINT_BASE_URLNoCustom base URL (default: tap-api-v2.proofpoint.com)
MCP_TRANSPORTNoTransport mode: stdio (default) or http

Usage

Running with Claude Desktop

Add to your Claude Desktop claude_desktop_config.json:

{
  "mcpServers": {
    "proofpoint-mcp": {
      "command": "npx",
      "args": ["@wyre-ai/proofpoint-mcp"],
      "env": {
        "PROOFPOINT_SERVICE_PRINCIPAL": "your-proofpoint-service-principal"
        "PROOFPOINT_SERVICE_SECRET": "your-proofpoint-service-secret"
      }
    }
  }
}

Running with Claude Code (CLI)

claude mcp add proofpoint-mcp \
  -e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
  -e PROOFPOINT_SERVICE_SECRET=your-value \
  -- npx -y @wyre-ai/proofpoint-mcp

Docker

docker build -t proofpoint-mcp .
docker run \
  -e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
  -e PROOFPOINT_SERVICE_SECRET=your-value \
  -p 8080:8080 proofpoint-mcp

Features

Interactive Threat Card (MCP Apps)

proofpoint_threat_get_by_id renders as an interactive, read-only card in MCP Apps hosts (Claude Desktop/web) showing the threat name, status, category, severity, and resolved actor / malware-family / campaign names; plain-JSON behavior is unchanged in other hosts. The card is neutral by default and brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild needed.

Available Domains

Dlp

Data loss prevention policies

Events

Security event stream and SIEM export

Forensics

Forensic analysis of threats

People

Very Attacked People (VAP) reporting

Policy

Email policy management

Quarantine

Email quarantine management

Reports

Security reports and summaries

Smart Search

Advanced email search

Tap

Targeted Attack Protection events and campaigns

Threat Intel

Threat intelligence and indicators of compromise

Url Defense

URL rewriting and click defense

Development

# Clone the repository
git clone https://github.com/WYRE-AI/proofpoint-mcp.git
cd proofpoint-mcp

# Install dependencies
npm install

# Build
npm run build

# Run tests
npm test

Contributing

Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.

License

Licensed under the Apache License, Version 2.0. See LICENSE for details.

Reviews

No reviews yet

Be the first to review this server!