Rust SDK for VirusTotal API v3 with Model Context Protocol (MCP) server implementation providing threat intelligence tools to Language Models
VirusTotal MCP server demonstrates solid tool definition quality with consistent verb-based naming (vti_search, get_file_report, get_url_report, get_ip_report, get_domain_report), clear descriptions of 80-140 characters, and proper input schemas with typed parameters. All tools are READ_ONLY threat intelligence lookups with appropriate risk classification. Input parameters include descriptions explaining what each indicator type is. However, output schemas are not documented in the visible code, tool responses are not formally declared. Parameter validation rules are mentioned in descriptions but could be more explicit (e.g., hash format validation, IP version specification). Error handling strategy is not evident from the tool definitions. No tool annotations (readOnlyHint/destructiveHint/idempotentHint) are declared despite all tools being read-only. Missing pagination/limit parameters for tools that might return large result sets (vti_search, get_domain_report could return many related domains/IPs).
Get detailed domain analysis report from VirusTotal.
Get detailed file analysis report from VirusTotal using a file hash (MD5, SHA1, SHA256, or SHA512).
Get detailed IP address analysis report from VirusTotal.
Get detailed URL analysis report from VirusTotal for a specific URL.
Search VirusTotal for threat intelligence on any indicator (hash, IP, domain, or URL). Automatically detects indicator type and returns comprehensive threat analysis.
Output schemas not documented. Tools return VirusTotal API responses but LLMs cannot infer what fields are present, types, or structure. This prevents downstream tool chaining and forces LLMs to guess field names.
No tool annotations (readOnlyHint, idempotentHint) declared. All five tools are read-only and idempotent, declaring these annotations helps agents understand safety and retryability without reading descriptions.
No pagination or limit parameters visible. vti_search and get_domain_report may return many related IoCs (IPs, domains, subdomains). Without pagination, large result sets risk exceeding context windows. Should include limit (default 20-50) and optional cursor/offset.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 76 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 48 | - | v1 |
Parameter validation rules not explicit in schema. get_file_report accepts 'hash' without specifying accepted formats (MD5, SHA1, SHA256, SHA512). get_ip_report accepts 'ip' without declaring IPv4 vs IPv6 validation. Descriptions mention types but JSON Schema should enforce via pattern or enum.
Error handling strategy not evident in tool definitions. No recovery guidance shown (e.g., 'If indicator not found, try a different hash format'). Error responses should guide LLM on next steps.