Skip to content
mcp/skillhub

Abnormal MCP Server

by gregdogio.github.GregDog/mcp-server-abnormalv1.1.0

Abnormal Security MCP: threats, search, remediation, ATO cases, vendor/BEC, and evidence download.

0Dockerstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active10d ago

Install Abnormal MCP server

Install in Claude Code

claude mcp add abnormal -e ABNORMAL_API_TOKEN='<abnormal-api-token>' -- docker run -i --rm -e ABNORMAL_API_TOKEN ghcr.io/gregdog/mcp-server-abnormal:v1.1.0 serve

Configuration

VariableRequiredSecretDescription
ABNORMAL_API_TOKENyesyesAbnormal REST API bearer token
ABNORMAL_BASE_URL——Abnormal API base URL
ABNORMAL_ALLOW_RESPONSE——Enable response MCP tools (remediation)
ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD——Enable evidence download MCP tools (EML and attachments)
ABNORMAL_MAX_EVIDENCE_BYTES——Max bytes per evidence download from Abnormal

Freshness

Active — last maintenance signal 10d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-29 · 10d ago · GitHub

  2. Latest release

    2026-09-17 · 22d ago · GitHub · v1.1.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-17 · 22d ago · official registry · v1.1.0

FAQ

›How do I install the Abnormal MCP server in Claude Code?

Run: claude mcp add abnormal -e ABNORMAL_API_TOKEN='<abnormal-api-token>' -- docker run -i --rm -e ABNORMAL_API_TOKEN ghcr.io/gregdog/mcp-server-abnormal:v1.1.0 serve. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Abnormal require an API key?

Yes. It expects ABNORMAL_API_TOKEN, of which 1 is a secret.

›Can I use Abnormal as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Abnormal in the official MCP registry?

Yes, as io.github.GregDog/mcp-server-abnormal.

Alternatives to Abnormal

Other security MCP servers.

View all