oci ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4stdioApache-2.0updated 8d ago
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
Was kannst du mit Proofpoint machen?
Proofpoint MCP Server
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.
Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
Installation
npm install @wyre-ai/proofpoint-mcp
Configuration
Set the following environment variables:
| Variable | Required | Description |
|---|---|---|
PROOFPOINT_SERVICE_PRINCIPAL |
Yes | Your Proofpoint TAP service principal |
PROOFPOINT_SERVICE_SECRET |
Yes | Your Proofpoint TAP service secret |
PROOFPOINT_BASE_URL |
No | Custom base URL (default: tap-api-v2.proofpoint.com) |
MCP_TRANSPORT |
No | Transport mode: stdio (default) or http |
Usage
Running with Claude Desktop
Add to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"proofpoint-mcp": {
"command": "npx",
"args": ["@wyre-ai/proofpoint-mcp"],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "your-proofpoint-service-principal"
"PROOFPOINT_SERVICE_SECRET": "your-proofpoint-service-secret"
}
}
}
}
Running with Claude Code (CLI)
claude mcp add proofpoint-mcp \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-- npx -y @wyre-ai/proofpoint-mcp
Docker
docker build -t proofpoint-mcp .
docker run \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-p 8080:8080 proofpoint-mcp
Features
Interactive Threat Card (MCP Apps)
proofpoint_threat_get_by_id renders as an interactive, read-only card in
MCP Apps hosts (Claude Desktop/web) showing the threat name, status,
category, severity, and resolved actor / malware-family / campaign names;
plain-JSON behavior is unchanged in other hosts. The card is neutral by
default and brandable via window.__BRAND__ injection or MCP_BRAND_* env
vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR,
MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild
needed.
Available Domains
Dlp
Data loss prevention policies
Events
Security event stream and SIEM export
Forensics
Forensic analysis of threats
People
Very Attacked People (VAP) reporting
Policy
Email policy management
Quarantine
Email quarantine management
Reports
Security reports and summaries
Smart Search
Advanced email search
Tap
Targeted Attack Protection events and campaigns
Threat Intel
Threat intelligence and indicators of compromise
Url Defense
URL rewriting and click defense
Development
# Clone the repository
git clone https://github.com/WYRE-AI/proofpoint-mcp.git
cd proofpoint-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
Contributing
Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.
License
Licensed under the Apache License, Version 2.0. See LICENSE for details.
Installation
Proofpoint zu deinem Client hinzufügen. Wähl den, den du nutzt.
claude mcp add ghcr-io-wyre-technology-proofpoint-mcp-v -- docker run -i --rm ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4codex mcp add ghcr-io-wyre-technology-proofpoint-mcp-v -- docker run -i --rm ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4amp mcp add ghcr-io-wyre-technology-proofpoint-mcp-v -- docker run -i --rm ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4{
"mcpServers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"ghcr-io-wyre-technology-proofpoint-mcp-v","command":"docker","args":["run","-i","--rm","ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"type": "local",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"ghcr-io-wyre-technology-proofpoint-mcp-v": {
"command": {
"path": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
]
}
}
}
}Add to your Zed `settings.json`.
docker run -i --rm ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4Run `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
Score
39 / 100
Unvollständig
- Dokumentation22/25
- Pflege25/25
- Vertrauen16/20
- Funktionsumfang0/15
- Installation12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 0 days ago
- Has a release history
- Repository is not archived
- Licensed Apache-2.0
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Versionsverlauf
| Versionen | Veröffentlicht |
|---|---|
| 1.1.4Aktuell | 13. Aug. 2026 |
| 1.1.3 | 7. Aug. 2026 |
| 1.1.2 | 21. Juli 2026 |
| 1.1.1 | 21. Juli 2026 |
| 1.1.0 | 17. Juli 2026 |
| 1.0.5 | 1. Juli 2026 |
| 1.0.4 | 30. Mai 2026 |