mcpbeat

Malwarebytes MCP Server

vendor.malwarebytes/mcp
answering

Malwarebytes is answering right now. Last checked 6 min ago. It exposes 6 tools.

Uptime history 30 hours of history
30 hours agonow
100.0%
Uptime 24h
91 of 91 checks
6
Tools
read from the server
374 ms
Response time
average over 24h
open, no key
Access
streamable-http

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 6 min ago.

run in your terminal
claude mcp add mcp --transport http https://scamguard.malwarebytes.com/claude/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp": {
      "url": "https://scamguard.malwarebytes.com/claude/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.mcp]
url = "https://scamguard.malwarebytes.com/claude/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "mcp": {
      "url": "https://scamguard.malwarebytes.com/claude/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "mcp": {
      "url": "https://scamguard.malwarebytes.com/claude/mcp"
    }
  }
}

Available tools 6

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

reputation
reputation-check_email
Use this when you need to check if an email address is associated with phishing, scams, or malicious activity. Checks the email domain against threat intelligence database. Returns one of: - malicious: Confirmed phishing or malicious email domain - suspicious: Potentially dangerous email domain - safe: Verified legitimate email domain - unknown: No threat intelligence available Cross-tool workflow: - If the email contains URLs, consider scanning them with reputation-check_link. - If the email contains phone numbers, consider scanning them with reputation-check_phone. - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). Do not use this for email validation, mailbox verification, or general email lookup services.
reputation-check_link
Use this when you need to check if a link or URL is safe, suspicious, or malicious. Provides reputation verdict based on threat intelligence database. Returns one of: - malicious: Confirmed harmful link - suspicious: Potentially dangerous link - safe: Verified safe link - unknown: No threat intelligence available Cross-tool workflow: - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). - If the URL redirects to a different domain, consider scanning the destination URL separately. - If the URL came from an email or text message, consider checking the sender with reputation-check_email or reputation-check_phone. Do not use this for general web searches, content fetching, or webpage analysis.
reputation-check_phone
Use this when you need to check if a phone number is associated with scams or suspicious activity. Provides reputation verdict and additional phone information. Returns one of: - malicious: Confirmed scam or spam phone number - suspicious: Potentially dangerous number - safe: Verified legitimate number - unknown: No threat intelligence available Also provides optional details like carrier, location, and phone type when available. Cross-tool workflow: - If the caller provided links, consider scanning them with reputation-check_link. - If the caller provided email addresses, consider scanning them with reputation-check_email. Do not use this for phone number lookups, caller ID services, or general phone directory searches.
reputation-report
Use this when a user wants to report a suspicious link, email address, or phone number. Submits the indicator to the threat intelligence system for analysis. Only use when explicitly requested by the user. Do not use this to automatically report every checked item.
reputation-scan_all
Use this when you need to check multiple links, emails, or phone numbers at once. Scans all indicators concurrently and returns a unified result. Each indicator needs: - type: 'url', 'email', or 'phone' - value: the URL, email address, or phone number (E.164 format for phones) Returns a summary with counts per verdict and individual results for each indicator. Prefer this over individual scan tools when 3 or more indicators are present. Maximum 10 indicators per request. Cross-tool workflow: - For unknown URL or email verdicts, consider using reputation-whois on the associated domains for additional registration context and abuse contact information.
reputation-whois
Use this when you need to look up domain registration information to verify legitimacy or identify suspicious patterns. Provides WHOIS/RDAP data including registrar, registration dates, name servers, and abuse contacts. Particularly useful for identifying newly registered domains (common in phishing and scams). Returns the registrar's abuse contact email when available, which can be used for filing complaints about fraudulent domains. Cross-tool workflow: - Consider using reputation-check_link to check the domain's threat reputation alongside WHOIS registration data. Do not use this for general domain availability checks or bulk domain searches.

Endpoints

URLTransportStateLatencyChecked
https://scamguard.malwarebytes.com/claude/mcp streamable-http answering 354 ms 6 min ago

Malwarebytes — questions

Answers built from our own checks of this server.

What can Malwarebytes do?
It exposes 6 tools, read directly from the server on our last check. Among them: reputation-check_email, reputation-check_link, reputation-check_phone, reputation-report, reputation-scan_all, reputation-whois. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Malwarebytes working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 374 ms. The bar chart above shows every period we have measured.
How do I connect Malwarebytes?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Malwarebytes need an API key?
No. Malwarebytes completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 6 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Malwarebytes?
It answers our handshake in 374 ms on average, which is faster than 37% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.