Server data from the Official MCP Registry
MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
This is a well-structured MCP server with proper authentication, secure credential handling, and appropriate permissions for its intended purpose. The code follows security best practices with Bearer token authentication, environment variable-based credential management, and dual transport support (stdio and HTTP). Minor code quality issues around input validation and error handling do not significantly impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (2 critical, 0 high severity).
7 files analyzed · 10 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Set these up before or after installing:
Environment variable: ABNORMAL_API_TOKEN
Environment variable: MCP_TRANSPORT
Environment variable: AUTH_MODE
Environment variable: LOG_LEVEL
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-wyre-technology-abnormal-mcp": {
"env": {
"AUTH_MODE": "your-auth-mode-here",
"LOG_LEVEL": "your-log-level-here",
"MCP_TRANSPORT": "your-mcp-transport-here",
"ABNORMAL_API_TOKEN": "your-abnormal-api-token-here"
},
"args": [
"-y",
"@wyre-technology/abnormal-mcp"
],
"command": "npx"
}
}
}From the project's GitHub README.
MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.
This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.
| Tool | Description |
|---|---|
abnormal_navigate | Navigate to a domain (threats, messages, remediation, abuse, cases) |
abnormal_back | Return to domain selection |
| Tool | Description |
|---|---|
abnormal_threats_list | List detected threat cases (paginated) |
abnormal_threats_get | Get full details of a specific threat by ID |
| Tool | Description |
|---|---|
abnormal_messages_list | List messages within a threat case |
abnormal_messages_get | Get detailed message analysis (headers, URLs, attachments, AI analysis) |
| Tool | Description |
|---|---|
abnormal_remediation_manage | Trigger or check remediation actions for a message |
| Tool | Description |
|---|---|
abnormal_abuse_list | List phishing emails reported via the Abuse Mailbox |
| Tool | Description |
|---|---|
abnormal_cases_list | List active security investigation cases |
abnormal_cases_get | Get details of a specific case |
Abnormal Security uses Bearer token authentication.
export ABNORMAL_API_TOKEN=your-api-token
node dist/index.js
Generate your token in the Abnormal portal under Settings > Integrations > API.
When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.
npm install
npm run build
node dist/index.js
MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.js
docker compose up
npm install
npm run dev # watch mode
npm test # run tests
npm run typecheck # TypeScript type check
Apache-2.0
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.