Back to Browse

Abnormal MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.

About

MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.

Security Report

4.2
Use Caution4.2High Risk

The MCP server is well-structured with proper authentication, appropriate permissions for its security integration purpose, and no critical vulnerabilities. A large embedded HTML/JavaScript bundle (threat-card-html.ts) and minor code quality issues slightly lower the score, but the overall security posture is sound. Supply chain analysis found 2 known vulnerabilities in dependencies (2 critical, 0 high severity).

3 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Abnormal Security API token (Bearer credential)Required

Environment variable: ABNORMAL_API_TOKEN

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-wyre-technology-abnormal-mcp": {
      "env": {
        "AUTH_MODE": "your-auth-mode-here",
        "LOG_LEVEL": "your-log-level-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "ABNORMAL_API_TOKEN": "your-abnormal-api-token-here"
      },
      "args": [
        "-y",
        "@wyre-technology/abnormal-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

abnormal-mcp

MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.

Tools

This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.

Navigation

ToolDescription
abnormal_navigateNavigate to a domain (threats, messages, remediation, abuse, cases)
abnormal_backReturn to domain selection

Threats domain

ToolDescription
abnormal_threats_listList detected threat cases (paginated)
abnormal_threats_getGet full details of a specific threat by ID

Messages domain

ToolDescription
abnormal_messages_listList messages within a threat case
abnormal_messages_getGet detailed message analysis (headers, URLs, attachments, AI analysis)

Remediation domain

ToolDescription
abnormal_remediation_manageTrigger or check remediation actions for a message

Abuse domain

ToolDescription
abnormal_abuse_listList phishing emails reported via the Abuse Mailbox

Cases domain

ToolDescription
abnormal_cases_listList active security investigation cases
abnormal_cases_getGet details of a specific case

Interactive Threat Card (MCP Apps)

  • abnormal_threats_get renders as an interactive threat card in MCP Apps hosts (Claude Desktop/web): subject, sender, attack classification, remediation status, and the messages in the threat. The card is read-only — remediation stays a deliberate, model-mediated action. Plain-JSON behavior is unchanged in other hosts. Neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild needed.

Authentication

Abnormal Security uses Bearer token authentication.

Standalone (env mode)

export ABNORMAL_API_TOKEN=your-api-token
node dist/index.js

Generate your token in the Abnormal portal under Settings > Integrations > API.

Gateway mode

When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.

Running

stdio (for Claude Desktop)

npm install
npm run build
node dist/index.js

HTTP Streamable (for hosted/gateway deployment)

MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.js

Docker

docker compose up

Development

npm install
npm run dev          # watch mode
npm test             # run tests
npm run typecheck    # TypeScript type check
npm run build:ui     # rebuild the MCP Apps card bundle (only needed when ui/ changes)

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!

Abnormal MCP Server - MCP server for Abnormal Security — AI-powered email threat | MCP Marketplace