Skip to content
mcp/skillhub

Ismalicious MCP Server

by hexablobcom.ismalicious/mcp-serverv0.5.0

Reputation of IPs, domains, URLs, hashes, emails and phones; CVE lookups; prompt-injection scans

0Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active8d ago

Install Ismalicious MCP server

Install in Claude Code

claude mcp add ismalicious -e ISMALICIOUS_API_KEY='<ismalicious-api-key>' -e ISMALICIOUS_API_SECRET='<ismalicious-api-secret>' -- npx -y @ismalicious/mcp-server

Configuration

VariableRequiredSecretDescription
ISMALICIOUS_API_KEY—yesAPI key from https://ismalicious.com/app/account. Optional: without it the server starts in bootstrap mode and offers bootstrap_key.
ISMALICIOUS_API_SECRET—yesAPI secret paired with the key
ISMALICIOUS_API_BASE——API base URL (defaults to https://ismalicious.com/api; https://api.ismalicious.com reaches the API host directly)
ISMALICIOUS_TIMEOUT_MS——Replaces every tool's timeout, in milliseconds (defaults: gate 15000, check_indicator 25000, CVE 10000, search_indicators 20000, check_indicators 60000, check_password_exposure 10000). ISMALICIOUS_TIMEOUT_<TOOL>_MS, e.g. ISMALICIOUS_TIMEOUT_CHECK_INDICATOR_MS, sets one tool's timeout and wins over it
ISMALICIOUS_WEB_BASE——Base URL for bootstrap_key, a route only https://ismalicious.com/api serves (defaults to ISMALICIOUS_API_BASE, or https://ismalicious.com/api when that is api.ismalicious.com)
ISMALICIOUS_CACHE_TTL_S——Result cache: 0 turns it off; N caps every tool's cache lifetime at N seconds (never raises one)
ISMALICIOUS_PREWARM——0 (or false, off, no) skips the one unauthenticated GET /health sent after initialize to open the connection

Freshness

Active — last maintenance signal 8d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-01 · 8d ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-10-01 · 8d ago · official registry · v0.5.0

FAQ

›How do I install the Ismalicious MCP server in Claude Code?

Run: claude mcp add ismalicious -e ISMALICIOUS_API_KEY='<ismalicious-api-key>' -e ISMALICIOUS_API_SECRET='<ismalicious-api-secret>' -- npx -y @ismalicious/mcp-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Ismalicious require an API key?

Yes. It expects ISMALICIOUS_API_KEY, ISMALICIOUS_API_SECRET, of which 2 are secrets.

›Can I use Ismalicious as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Ismalicious in the official MCP registry?

Yes, as com.ismalicious/mcp-server.

Alternatives to Ismalicious

Other security MCP servers.

View all