Skip to main content
ClaudeWave

MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation

MCP ServersRegistry oficial0 estrellas1 forksTypeScriptApache-2.0Actualizado yesterday
ClaudeWave Trust Score
95/100
Verified
Passed
  • Open-source license (Apache-2.0)
  • Actively maintained (<30d)
  • Clear description
  • Topics declared
  • Documented (README)
Last scanned: 8/27/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/WYRE-AI/abnormal-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "abnormal-mcp": {
      "command": "node",
      "args": ["/path/to/abnormal-mcp/dist/index.js"],
      "env": {
        "ABNORMAL_API_TOKEN": "<abnormal_api_token>"
      }
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/WYRE-AI/abnormal-mcp and follow its README for install instructions.
Detected environment variables
ABNORMAL_API_TOKEN
Casos de uso

Resumen de MCP Servers

# abnormal-mcp

MCP server for [Abnormal Security](https://abnormalsecurity.com/) — AI-powered threat detection, case management, and email remediation.

## Tools

This server uses a decision-tree architecture. Start by calling `abnormal_navigate` to select a domain, then use the domain-specific tools.

### Navigation

| Tool | Description |
|------|-------------|
| `abnormal_navigate` | Navigate to a domain (threats, messages, remediation, abuse, cases) |
| `abnormal_back` | Return to domain selection |

### Threats domain

| Tool | Description |
|------|-------------|
| `abnormal_threats_list` | List detected threat cases (paginated) |
| `abnormal_threats_get` | Get full details of a specific threat by ID |

### Messages domain

| Tool | Description |
|------|-------------|
| `abnormal_messages_list` | List messages within a threat case |
| `abnormal_messages_get` | Get detailed message analysis (headers, URLs, attachments, AI analysis) |

### Remediation domain

| Tool | Description |
|------|-------------|
| `abnormal_remediation_manage` | Trigger or check remediation actions for a message |

### Abuse domain

| Tool | Description |
|------|-------------|
| `abnormal_abuse_list` | List phishing emails reported via the Abuse Mailbox |

### Cases domain

| Tool | Description |
|------|-------------|
| `abnormal_cases_list` | List active security investigation cases |
| `abnormal_cases_get` | Get details of a specific case |

### Interactive Threat Card (MCP Apps)

- `abnormal_threats_get` renders as an interactive threat card in MCP Apps
  hosts (Claude Desktop/web): subject, sender, attack classification,
  remediation status, and the messages in the threat. The card is read-only —
  remediation stays a deliberate, model-mediated action. Plain-JSON behavior
  is unchanged in other hosts. Neutral by default, brandable via
  `window.__BRAND__` injection or `MCP_BRAND_*` env vars (`MCP_BRAND_NAME`,
  `MCP_BRAND_LOGO_URL`, `MCP_BRAND_PRIMARY_COLOR`, `MCP_BRAND_ACCENT_COLOR`,
  `MCP_BRAND_BG`, `MCP_BRAND_TEXT`) — no rebuild needed.

## Authentication

Abnormal Security uses Bearer token authentication.

### Standalone (env mode)

```bash
export ABNORMAL_API_TOKEN=your-api-token
node dist/index.js
```

Generate your token in the Abnormal portal under **Settings > Integrations > API**.

### Gateway mode

When deployed behind the MCP gateway, set `AUTH_MODE=gateway`. The gateway injects the `Authorization: Bearer {token}` header automatically on each request.

## Running

### stdio (for Claude Desktop)

```bash
npm install
npm run build
node dist/index.js
```

### HTTP Streamable (for hosted/gateway deployment)

```bash
MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.js
```

### Docker

```bash
docker compose up
```

## Development

```bash
npm install
npm run dev          # watch mode
npm test             # run tests
npm run typecheck    # TypeScript type check
npm run build:ui     # rebuild the MCP Apps card bundle (only needed when ui/ changes)
```

## License

Apache-2.0
abnormal-securityemail-securitymcp-servermspmsp-mcptypescriptwyre-technology

Lo que la gente pregunta sobre abnormal-mcp

¿Qué es WYRE-AI/abnormal-mcp?

+

WYRE-AI/abnormal-mcp es mcp servers para el ecosistema de Claude AI. MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-08-25.

¿Cómo se instala abnormal-mcp?

+

Puedes instalar abnormal-mcp clonando el repositorio (https://github.com/WYRE-AI/abnormal-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar WYRE-AI/abnormal-mcp?

+

Nuestro agente de seguridad ha analizado WYRE-AI/abnormal-mcp y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene WYRE-AI/abnormal-mcp?

+

WYRE-AI/abnormal-mcp es mantenido por WYRE-AI. La última actividad registrada en GitHub es del 2026-08-25, con 2 issues abiertos.

¿Hay alternativas a abnormal-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega abnormal-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: WYRE-AI/abnormal-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/wyre-ai-abnormal-mcp)](https://claudewave.com/repo/wyre-ai-abnormal-mcp)
<a href="https://claudewave.com/repo/wyre-ai-abnormal-mcp"><img src="https://claudewave.com/api/badge/wyre-ai-abnormal-mcp" alt="Featured on ClaudeWave: WYRE-AI/abnormal-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a abnormal-mcp