Back to Discover

abnormal-mcp

connector

wyre-technology

MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.

View on GitHub
0 starsSynced Aug 7, 2026

Install to Claude Code

/plugin marketplace add wyre-technology/abnormal-mcp

README

abnormal-mcp

MCP server for Abnormal Security — AI-powered threat detection, case management, and email remediation.

Tools

This server uses a decision-tree architecture. Start by calling abnormal_navigate to select a domain, then use the domain-specific tools.

Navigation

ToolDescription
abnormal_navigateNavigate to a domain (threats, messages, remediation, abuse, cases)
abnormal_backReturn to domain selection

Threats domain

ToolDescription
abnormal_threats_listList detected threat cases (paginated)
abnormal_threats_getGet full details of a specific threat by ID

Messages domain

ToolDescription
abnormal_messages_listList messages within a threat case
abnormal_messages_getGet detailed message analysis (headers, URLs, attachments, AI analysis)

Remediation domain

ToolDescription
abnormal_remediation_manageTrigger or check remediation actions for a message

Abuse domain

ToolDescription
abnormal_abuse_listList phishing emails reported via the Abuse Mailbox

Cases domain

ToolDescription
abnormal_cases_listList active security investigation cases
abnormal_cases_getGet details of a specific case

Interactive Threat Card (MCP Apps)

  • abnormal_threats_get renders as an interactive threat card in MCP Apps hosts (Claude Desktop/web): subject, sender, attack classification, remediation status, and the messages in the threat. The card is read-only — remediation stays a deliberate, model-mediated action. Plain-JSON behavior is unchanged in other hosts. Neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild needed.

Authentication

Abnormal Security uses Bearer token authentication.

Standalone (env mode)

export ABNORMAL_API_TOKEN=your-api-token
node dist/index.js

Generate your token in the Abnormal portal under Settings > Integrations > API.

Gateway mode

When deployed behind the MCP gateway, set AUTH_MODE=gateway. The gateway injects the Authorization: Bearer {token} header automatically on each request.

Running

stdio (for Claude Desktop)

npm install
npm run build
node dist/index.js

HTTP Streamable (for hosted/gateway deployment)

MCP_TRANSPORT=http AUTH_MODE=gateway node dist/index.js

Docker

docker compose up

Development

npm install
npm run dev          # watch mode
npm test             # run tests
npm run typecheck    # TypeScript type check
npm run build:ui     # rebuild the MCP Apps card bundle (only needed when ui/ changes)

License

Apache-2.0

Rendered live from wyre-technology/abnormal-mcp's GitHub README — not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
oci packageInstall via oci (stdio transport)mcp-serverghcr.io/wyre-technology/abnormal-mcp:v1.2.1

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.