Abnormal Security MCP Server
by wyre-technologyio.github.wyre-technology/abnormal-mcpv1.2.5
MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
context tax
queued
security
queued
cold start
queued
freshness
Active1d ago
Install Abnormal Security MCP server
Install in Claude Code
claude mcp add abnormal-wyre-technology -e ABNORMAL_API_TOKEN='<abnormal-api-token>' -- docker run -i --rm -e ABNORMAL_API_TOKEN ghcr.io/wyre-technology/abnormal-mcp:v1.2.5Install in Cursor
{
"mcpServers": {
"abnormal-wyre-technology": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"abnormal-wyre-technology": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"abnormal-wyre-technology": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"abnormal-wyre-technology": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
],
"env": {
"ABNORMAL_API_TOKEN": "<abnormal-api-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ABNORMAL_API_TOKEN | yes | yes | Abnormal Security API token (Bearer credential) |
| MCP_TRANSPORT | — | — | Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting. |
| AUTH_MODE | — | — | Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway. |
| LOG_LEVEL | — | — | Log verbosity: debug, info, warn, error |
Freshness
Active — last maintenance signal 1d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-08 · 1d ago · GitHub
Latest release
2026-08-25 · 45d ago · GitHub · v1.2.6
Package published
no data · npm/PyPI
Registry entry updated
2026-08-20 · 50d ago · official registry · v1.2.5
FAQ
›How do I install the Abnormal Security MCP server in Claude Code?
Run: claude mcp add abnormal-wyre-technology -e ABNORMAL_API_TOKEN='<abnormal-api-token>' -- docker run -i --rm -e ABNORMAL_API_TOKEN ghcr.io/wyre-technology/abnormal-mcp:v1.2.5. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Abnormal Security require an API key?
Yes. It expects ABNORMAL_API_TOKEN, of which 1 is a secret.
›Can I use Abnormal Security as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Abnormal Security in the official MCP registry?
Yes, as io.github.wyre-technology/abnormal-mcp.
Alternatives to Abnormal Security
Other email MCP servers.