oci ghcr.io/wyre-technology/abnormal-mcp:v1.2.5stdioApache-2.0updated 8d ago
MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.
Was kannst du mit Abnormal Security machen?
abnormal-mcp
MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.
Tools
This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.
Navigation
| Tool | Description |
|---|---|
abnormal_navigate |
Navigate to a domain (threats, messages, remediation, abuse, cases) |
abnormal_back |
Return to domain selection |
Threats domain
| Tool | Description |
|---|---|
abnormal_threats_list |
List detected threat cases (paginated) |
abnormal_threats_get |
Get full details of a specific threat by ID |
Messages domain
| Tool | Description |
|---|---|
abnormal_messages_list |
List messages within a threat case |
abnormal_messages_get |
Get detailed message analysis (headers, URLs, attachments, AI analysis) |
Remediation domain
| Tool | Description |
|---|---|
abnormal_remediation_manage |
Trigger or check remediation actions for a message |
Abuse domain
| Tool | Description |
|---|---|
abnormal_abuse_list |
List phishing emails reported via the Abuse Mailbox |
Cases domain
| Tool | Description |
|---|---|
abnormal_cases_list |
List active security investigation cases |
abnormal_cases_get |
Get details of a specific case |
Interactive Threat Card (MCP Apps)
abnormal_threats_getrenders as an interactive threat card in MCP Apps hosts (Claude Desktop/web): subject, sender, attack classification, remediation status, and the messages in the threat. The card is read-only — remediation stays a deliberate, model-mediated action. Plain-JSON behavior is unchanged in other hosts. Neutral by default, brandable viawindow.__BRAND__injection orMCP_BRAND_*env vars (MCP_BRAND_NAME,MCP_BRAND_LOGO_URL,MCP_BRAND_PRIMARY_COLOR,MCP_BRAND_ACCENT_COLOR,MCP_BRAND_BG,MCP_BRAND_TEXT) — no rebuild needed.
Authentication
Abnormal Security uses Bearer token authentication.
Standalone (env mode)
export ABNORMAL_API_TOKEN=your-api-token
node dist/index.js
Generate your token in the Abnormal portal under Settings > Integrations > API.
Gateway mode
When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.
Running
stdio (for Claude Desktop)
npm install
npm run build
node dist/index.js
HTTP Streamable (for hosted/gateway deployment)
MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.js
Docker
docker compose up
Development
npm install
npm run dev # watch mode
npm test # run tests
npm run typecheck # TypeScript type check
npm run build:ui # rebuild the MCP Apps card bundle (only needed when ui/ changes)
License
Apache-2.0
Installation
Abnormal Security zu deinem Client hinzufügen. Wähl den, den du nutzt.
claude mcp add ghcr-io-wyre-technology-abnormal-mcp-v1- -- docker run -i --rm ghcr.io/wyre-technology/abnormal-mcp:v1.2.5codex mcp add ghcr-io-wyre-technology-abnormal-mcp-v1- -- docker run -i --rm ghcr.io/wyre-technology/abnormal-mcp:v1.2.5amp mcp add ghcr-io-wyre-technology-abnormal-mcp-v1- -- docker run -i --rm ghcr.io/wyre-technology/abnormal-mcp:v1.2.5{
"mcpServers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"ghcr-io-wyre-technology-abnormal-mcp-v1-","command":"docker","args":["run","-i","--rm","ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"type": "local",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"ghcr-io-wyre-technology-abnormal-mcp-v1-": {
"command": {
"path": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
]
}
}
}
}Add to your Zed `settings.json`.
docker run -i --rm ghcr.io/wyre-technology/abnormal-mcp:v1.2.5Run `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
Score
39 / 100
Unvollständig
- Dokumentation22/25
- Pflege25/25
- Vertrauen16/20
- Funktionsumfang0/15
- Installation12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 0 days ago
- Has a release history
- Repository is not archived
- Licensed Apache-2.0
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Versionsverlauf
| Versionen | Veröffentlicht |
|---|---|
| 1.2.5Aktuell | 20. Aug. 2026 |
| 1.2.4 | 20. Aug. 2026 |
| 1.2.3 | 20. Aug. 2026 |
| 1.2.2 | 13. Aug. 2026 |
| 1.2.1 | 7. Aug. 2026 |
| 1.2.0 | 17. Juli 2026 |
| 1.1.8 | 1. Juli 2026 |
| 1.1.7 | 12. Juni 2026 |
| 1.1.6 | 12. Juni 2026 |
| 1.1.5 | 22. Mai 2026 |
| 1.0.0 | 21. Mai 2026 |
| 1.1.4 | 21. Mai 2026 |
| 1.1.3 | 6. Mai 2026 |