Ismalicious MCP Server
by hexablobcom.ismalicious/mcp-serverv0.5.0
Reputation of IPs, domains, URLs, hashes, emails and phones; CVE lookups; prompt-injection scans
context tax
queued
security
queued
cold start
queued
freshness
Active8d ago
Install Ismalicious MCP server
Install in Claude Code
claude mcp add ismalicious -e ISMALICIOUS_API_KEY='<ismalicious-api-key>' -e ISMALICIOUS_API_SECRET='<ismalicious-api-secret>' -- npx -y @ismalicious/mcp-serverInstall in Cursor
{
"mcpServers": {
"ismalicious": {
"command": "npx",
"args": [
"-y",
"@ismalicious/mcp-server"
],
"env": {
"ISMALICIOUS_API_KEY": "<ismalicious-api-key>",
"ISMALICIOUS_API_SECRET": "<ismalicious-api-secret>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"ismalicious": {
"command": "npx",
"args": [
"-y",
"@ismalicious/mcp-server"
],
"env": {
"ISMALICIOUS_API_KEY": "<ismalicious-api-key>",
"ISMALICIOUS_API_SECRET": "<ismalicious-api-secret>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"ismalicious": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@ismalicious/mcp-server"
],
"env": {
"ISMALICIOUS_API_KEY": "<ismalicious-api-key>",
"ISMALICIOUS_API_SECRET": "<ismalicious-api-secret>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"ismalicious": {
"command": "npx",
"args": [
"-y",
"@ismalicious/mcp-server"
],
"env": {
"ISMALICIOUS_API_KEY": "<ismalicious-api-key>",
"ISMALICIOUS_API_SECRET": "<ismalicious-api-secret>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ISMALICIOUS_API_KEY | — | yes | API key from https://ismalicious.com/app/account. Optional: without it the server starts in bootstrap mode and offers bootstrap_key. |
| ISMALICIOUS_API_SECRET | — | yes | API secret paired with the key |
| ISMALICIOUS_API_BASE | — | — | API base URL (defaults to https://ismalicious.com/api; https://api.ismalicious.com reaches the API host directly) |
| ISMALICIOUS_TIMEOUT_MS | — | — | Replaces every tool's timeout, in milliseconds (defaults: gate 15000, check_indicator 25000, CVE 10000, search_indicators 20000, check_indicators 60000, check_password_exposure 10000). ISMALICIOUS_TIMEOUT_<TOOL>_MS, e.g. ISMALICIOUS_TIMEOUT_CHECK_INDICATOR_MS, sets one tool's timeout and wins over it |
| ISMALICIOUS_WEB_BASE | — | — | Base URL for bootstrap_key, a route only https://ismalicious.com/api serves (defaults to ISMALICIOUS_API_BASE, or https://ismalicious.com/api when that is api.ismalicious.com) |
| ISMALICIOUS_CACHE_TTL_S | — | — | Result cache: 0 turns it off; N caps every tool's cache lifetime at N seconds (never raises one) |
| ISMALICIOUS_PREWARM | — | — | 0 (or false, off, no) skips the one unauthenticated GET /health sent after initialize to open the connection |
Freshness
Active — last maintenance signal 8d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-01 · 8d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-10-01 · 8d ago · official registry · v0.5.0
FAQ
›How do I install the Ismalicious MCP server in Claude Code?
Run: claude mcp add ismalicious -e ISMALICIOUS_API_KEY='<ismalicious-api-key>' -e ISMALICIOUS_API_SECRET='<ismalicious-api-secret>' -- npx -y @ismalicious/mcp-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Ismalicious require an API key?
Yes. It expects ISMALICIOUS_API_KEY, ISMALICIOUS_API_SECRET, of which 2 are secrets.
›Can I use Ismalicious as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Ismalicious in the official MCP registry?
Yes, as com.ismalicious/mcp-server.
Alternatives to Ismalicious
Other security MCP servers.