All integrations
Catalogue metadata onlysecurity & identity toolsv20260615_00

VIRUSTOTAL

Virustotal

VirusTotal is a free online service that analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content using multiple antivirus engines and website scanners.

Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.

Pakkawork boundary

Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.

No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Attributed source

16

Action summaries

Display-only definitions

0

Trigger types

Not installed instances

1

Auth modes

Field names, never values

No

Execution

No runtime adapter

Authentication map

What setup is declared?

Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
API_KEY

API_KEY

virustotal_api_key

Provider setup

Developer setup

No fields declared in this snapshot.

User connection

  • VirusTotal API Keygeneric_api_key · stringRequired

Capability index

Actions and trigger definitions

Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.

Showing 1–16 of 16 actions

Add VirusTotal Comment

VIRUSTOTAL_ADD_COMMENT

Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use after analyzing a resource to leave contextual feedback. Provide exactly one identifier per call.

Untrusted display-only summary

Add Vote

VIRUSTOTAL_ADD_VOTE

Tool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing analysis results to submit your verdict.

Untrusted display-only summary

Get Analysis Report

VIRUSTOTAL_GET_ANALYSIS

Tool to retrieve the analysis report of a file or URL submission. Use after obtaining an analysis ID to fetch its detailed report. Analysis results may be incomplete immediately after submission; poll until the report status is 'completed' before treating results as final.

Untrusted display-only summary

Get comments

VIRUSTOTAL_GET_COMMENTS

Tool to retrieve the latest comments on a VirusTotal resource. Use when you need to review user-generated comments for a file, URL, domain, or IP after obtaining its identifier.

Untrusted display-only summary

Get Domain Relationships

VIRUSTOTAL_GET_DOMAIN_RELATIONSHIPS

Tool to retrieve relationship objects for a given domain. Use when you have a domain and need to explore its related entities.

Untrusted display-only summary

Get Domain Report

VIRUSTOTAL_GET_DOMAIN_REPORT

Tool to retrieve the analysis report of a domain. Use when you need detailed insight on a domain's reputation and analysis stats. No malicious signals on obscure or low-traffic domains may indicate limited analysis history rather than safety — treat sparse results as 'unknown', not 'safe'. Covers external OSINT only (…

Untrusted display-only summary

Get File Report

VIRUSTOTAL_GET_FILE_REPORT

Tool to retrieve the analysis report of a file. Use when you have a file's hash and need detailed scan metadata. Recently submitted files may return partial results; retry after a short delay before treating the report as final.

Untrusted display-only summary

Get IP Address Relationships

VIRUSTOTAL_GET_IP_ADDRESS_RELATIONSHIPS

Tool to retrieve objects related to a specific IP address by relationship type. Use when you have an IP and need to explore connected files, URLs, or other entities.

Untrusted display-only summary

Get IP Address Report

VIRUSTOTAL_GET_IP_ADDRESS_REPORT

Tool to retrieve the analysis report of an IP address. Use when you need detailed insight on an IP's reputation, ASN, country, and analysis stats. Low or zero detections indicate unknown risk, not safety — treat sparse data accordingly. Provides external OSINT only; insufficient as standalone compliance evidence.

Untrusted display-only summary

Get VirusTotal Metadata

VIRUSTOTAL_GET_METADATA

Tool to retrieve VirusTotal metadata. Use when you need information about available privileges, relationships between resources (like files, domains, IPs, URLs), and supported antivirus engines.

Untrusted display-only summary

Get URL Report

VIRUSTOTAL_GET_URL_REPORT

Tool to retrieve the analysis report of a URL. Use when you have a URL identifier (base64-url without padding) and need detailed scan results, reputation, and metadata. Results may be incomplete immediately after submission; retry with short delays if scan engines are still processing before treating the report as fin…

Untrusted display-only summary

Get Votes

VIRUSTOTAL_GET_VOTES

Tool to retrieve votes on files, URLs, domains, or IP addresses. Use when you need to view community votes for a given object.

Untrusted display-only summary

Rescan File

VIRUSTOTAL_RESCAN_FILE

Tool to re-analyze a previously submitted file. Use when you need updated analysis results after an initial scan.

Untrusted display-only summary

Scan URL

VIRUSTOTAL_SCAN_URL

Tool to submit a URL for scanning. Use when you have a URL and need to submit it to VirusTotal to obtain an analysis ID for later retrieval. The returned analysis ID is preliminary — scanning engines may not have finished. Poll VIRUSTOTAL_GET_URL_REPORT with the ID using short delays to retrieve complete results.

Untrusted display-only summary

Search VirusTotal

VIRUSTOTAL_SEARCH

Tool to search for objects in the VirusTotal database. Use when locating files, URLs, domains, IPs, or comments matching a query. Supports pagination with limit and cursor.

Untrusted display-only summary

Upload File

VIRUSTOTAL_UPLOAD_FILE

Tool to upload a file for scanning. Use when you have binary file content ready to submit for VirusTotal analysis.

Untrusted display-only summary

Provenance

Versioned facts, explicit trust.

The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.

Repository
https://github.com/provider-directoryHQ/provider-directory
Commit
85e33f6a81dfe987f6fc3637d48d45052cea8ca5
Generated
2026-09-12
Trust policy
untrusted_display_only

Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.