Atlas / MCP servers / eversinc33 / Vibe Malware Triage

Vibe Malware TriageSAFE

mcp/eversinc33/vibe-malware-triage

Vibe Malware Triage - MCP server for static PE analysis.

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
11 7r · 4w · 0d
Transport
sse · stdio
License
—
Stars
78
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

OUTDATED: Build a proper agent graph instead

MCP server to enable an LLM to do basic static triage of a PE.

A minimal prompt idea could be:

You are a malware analyst tasked to analyse the sample at  with your MCP tools. Create a markdown report that summarizes your findings. 

Of course supplying more info will usually yield a better result.

Installation

Install dependencies:

pip install pefile yara-python die-python mcp[cli]

Then adjust triage.py and change _EXE_PATH and YARA_RULE_PATH accordingly.

Claude Desktop Integration

You can install this server in Claude Desktop and interact with it right away by running:

mcp install .\triage.py

Different transport protocol

By default, without using arguments, the server will use stdio transport:

.\triage.py

To use SSE transport:

.\triage.py --transport http://127.0.0.1:8744

TODO

  • VT/AnyRun/Sandbox integration
  • Hash lookup
  • Streamable HTTP transport
Read from source at commit 8fa0a15e4c67OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add TriageMCP -- uvx TriageMCP
claude-desktop
{
  "mcpServers": {
    "TriageMCP": {
      "command": "uvx",
      "args": [
        "TriageMCP"
      ]
    }
  }
}
03

Exposed tools (11)

7 read · 4 write · 0 destructive.

ToolRiskDescription
get_EATread
get_IATread
get_hashesread
get_pe_metadataread
get_sectionsread
list_directoryread
run_capa-scanwrite
run_detect-it-easywrite
run_flosswrite
run_yara-scanwrite
upx_unpackread
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
triage.py:380
parser.add_argument("--transport", type=str, default="stdio", help="MCP transport protocol to use (stdio or http://127.0.0.1:8744)")
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
triage.py:87
"md5": hashlib.md5(),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:41
.\triage.py --transport http://127.0.0.1:8744

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 8fa0a15e4c67full audit observations/trust-audit/mcp-server/eversinc33__vibe-malware-triage.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078fa0a15e4c67SAFEB88first audit
06

Questions

What is the Vibe Malware Triage MCP server?

Vibe Malware Triage - MCP server for static PE analysis.

What tools does Vibe Malware Triage expose?

11 in total: 7 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vibe Malware Triage safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Vibe Malware Triage need?

No credential environment variables were found in its source, so it appears to need none.

How does Vibe Malware Triage run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as TriageMCP.

How current is this page?

The grade is for one exact copy of the source (8fa0a15e4c67), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement