NO_AUTH
MALWAREBYTES_MCP_NO_AUTH
Developer setup
No fields declared in this snapshot.
User connection
No fields declared in this snapshot.
MALWAREBYTES_MCP
Verify links, emails, phone numbers, and domains against Malwarebytes threat intelligence.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
6
Action summaries
Display-only definitions
0
Trigger types
Not installed instances
1
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
NO_AUTH
No fields declared in this snapshot.
No fields declared in this snapshot.
Capability index
Showing 1–6 of 6 actions
MALWAREBYTES_MCP_REPUTATION_CHECK_EMAIL
Use this when you need to check if an email address is associated with phishing, scams, or malicious activity. Checks the email domain against threat intelligence database. Returns one of: - malicious: Confirmed phishing or malicious email domain - suspicious: Potentially dangerous email domain - safe: Verified legiti…
Untrusted display-only summary
MALWAREBYTES_MCP_REPUTATION_CHECK_LINK
Use this when you need to check if a link or URL is safe, suspicious, or malicious. Provides reputation verdict based on threat intelligence database. Returns one of: - malicious: Confirmed harmful link - suspicious: Potentially dangerous link - safe: Verified safe link - unknown: No threat intelligence available Cros…
Untrusted display-only summary
MALWAREBYTES_MCP_REPUTATION_CHECK_PHONE
Use this when you need to check if a phone number is associated with scams or suspicious activity. Provides reputation verdict and additional phone information. Returns one of: - malicious: Confirmed scam or spam phone number - suspicious: Potentially dangerous number - safe: Verified legitimate number - unknown: No t…
Untrusted display-only summary
MALWAREBYTES_MCP_REPUTATION_REPORT
Use this when a user wants to report a suspicious link, email address, or phone number. Submits the indicator to the threat intelligence system for analysis. Only use when explicitly requested by the user. Do not use this to automatically report every checked item.
Untrusted display-only summary
MALWAREBYTES_MCP_REPUTATION_SCAN_ALL
Use this when you need to check multiple links, emails, or phone numbers at once. Scans all indicators concurrently and returns a unified result. Each indicator needs: - type: 'url', 'email', or 'phone' - value: the URL, email address, or phone number (E.164 format for phones) Returns a summary with counts per verdict…
Untrusted display-only summary
MALWAREBYTES_MCP_REPUTATION_WHOIS
Use this when you need to look up domain registration information to verify legitimacy or identify suspicious patterns. Provides WHOIS/RDAP data including registrar, registration dates, name servers, and abuse contacts. Particularly useful for identifying newly registered domains (common in phishing and scams). Return…
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.