mcpbeat Sign in

Virustotal MCP Server

local only

Virustotal runs on your own machine — the client starts it, so there is no endpoint to ping. 374 installs a week from npm. Last commit 8 Sep 2026.

MCP server for querying VirusTotal API with comprehensive security analysis tools.

Installs per day peak 194 · avg 53 · +165% w/w
a month agotoday
374
Installs / week
npm · @burtthecoder/mcp-virustotal
149
Stars
1 open issues
8 Sep 2026
Last commit
0 releases in 90 days
MIT
License
TypeScript

What changed 41

Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 9 August 2026. No other catalogue keeps this.

18 Sep the owner changed
17 Sep the owner changed
16 Sep the owner changed
15 Sep the owner changed
14 Sep the owner changed
13 Sep the owner changed
12 Sep the owner changed
11 Sep the owner changed
10 Sep the owner changed
9 Sep the owner changed
and 31 more, back to 9 August 2026

What the code does

We read the source, 7 d ago · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

Package points at a different repository w0h1v/mcp-virustotal, burtthecoder/mcp-virustotal
пакет @burtthecoder/mcp-virustotal ссылается на burtthecoder/mcp-virustotal

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add virustotal -- npx -y @burtthecoder/mcp-virustotal
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "virustotal": {
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.virustotal]
command = "npx"
args = ["-y", "@burtthecoder/mcp-virustotal"]
.cursor/mcp.json
{
  "mcpServers": {
    "virustotal": {
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "virustotal": {
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "command": "npx"
    }
  }
}

This one needs environment variables set before it will start: VIRUSTOTAL_API_KEY (Your VirusTotal API key). The author declared them in the registry entry; get the values from the project itself.

Alternatives to Virustotal

same job, measured the same way
Vulnicheck
by andrasfe

HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

local only
Securityscorecard MCP
by callmarcus

Community-built, comprehensive MCP server for the SecurityScorecard API (unofficial).

86 installs/wk local only
Vaultguard MCP
by kota1026

VaultGuard MCP Server - Yearn V3 / DeFi vault security and analysis tools for AI coding agents....

25 installs/wk local only
SymbioticSec
by symbioticsec

Symbiotic CLI MCP Server for security scanning and analysis

50 installs/wk local only
I
Ghost MCP Server
by ghostsecurity

Minimal MCP server for Ghost Security API - compatible with all MCP clients

24 installs/wk local only
npm MCP
by alisaitteke

MCP server for npm package management, security analysis, and compatibility checking

32 installs/wk local only
Rqwstr
by kjopstad-it

AI-native HTTP security testing MCP server — 17 tools with raw HTTP/1.1 + HTTP/2 control

local only
CrowdStrike Falcon MCP Server
by crowdstrike

Connects AI agents with CrowdStrike Falcon for security analysis and automation.

10 994 installs/wk local only

Virustotal — questions

Answers built from our own checks of this server.

Why is there no uptime for Virustotal?
Virustotal runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package @burtthecoder/mcp-virustotal was installed 374 times last week.
How do I connect Virustotal?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls @burtthecoder/mcp-virustotal straight from npm; nothing to host, nothing to sign up for.
How many people use Virustotal?
The npm package @burtthecoder/mcp-virustotal was installed 374 times in the last week. Week over week that is +165%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is Virustotal open source?
Yes — it is published under the MIT licence, written in TypeScript, 149 stars on GitHub and 1 open issue. The source link is on this page, so you can read exactly what it does with your data before you connect it.