Vibe Malware TriageSAFE
Vibe Malware Triage - MCP server for static PE analysis.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
OUTDATED: Build a proper agent graph instead
MCP server to enable an LLM to do basic static triage of a PE.
A minimal prompt idea could be:
You are a malware analyst tasked to analyse the sample at with your MCP tools. Create a markdown report that summarizes your findings.
Of course supplying more info will usually yield a better result.
Installation
Install dependencies:
pip install pefile yara-python die-python mcp[cli]
Then adjust triage.py and change _EXE_PATH and YARA_RULE_PATH accordingly.
Claude Desktop Integration
You can install this server in Claude Desktop and interact with it right away by running:
mcp install .\triage.py
Different transport protocol
By default, without using arguments, the server will use stdio transport:
.\triage.py
To use SSE transport:
.\triage.py --transport http://127.0.0.1:8744
TODO
- VT/AnyRun/Sandbox integration
- Hash lookup
- Streamable HTTP transport
8fa0a15e4c67OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add TriageMCP -- uvx TriageMCP
{
"mcpServers": {
"TriageMCP": {
"command": "uvx",
"args": [
"TriageMCP"
]
}
}
}Exposed tools (11)
7 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_EAT | read | |
get_IAT | read | |
get_hashes | read | |
get_pe_metadata | read | |
get_sections | read | |
list_directory | read | |
run_capa-scan | write | |
run_detect-it-easy | write | |
run_floss | write | |
run_yara-scan | write | |
upx_unpack | read |
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
parser.add_argument("--transport", type=str, default="stdio", help="MCP transport protocol to use (stdio or http://127.0.0.1:8744)")"md5": hashlib.md5(),
.\triage.py --transport http://127.0.0.1:8744
Gates applied: no_behavioural_pass, no_license.
8fa0a15e4c67full audit observations/trust-audit/mcp-server/eversinc33__vibe-malware-triage.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8fa0a15e4c67 | SAFE | B | 88 | first audit |
Questions
What is the Vibe Malware Triage MCP server?
Vibe Malware Triage - MCP server for static PE analysis.
What tools does Vibe Malware Triage expose?
11 in total: 7 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Vibe Malware Triage safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Vibe Malware Triage need?
No credential environment variables were found in its source, so it appears to need none.
How does Vibe Malware Triage run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as TriageMCP.
How current is this page?
The grade is for one exact copy of the source (8fa0a15e4c67), read on 2026-10-07. The repository is watched and re-audited when it changes.