Server definition
- Hash
- sha256:9d1de01f9127ea5562c01fe04050c317bca8747be6ea6ce9a7d1b7ecbb5bc534
- What it is
- What a remote MCP server returned when asked what it offers: 5 tools
The blob, as servednamed by its sha256
{
"instructions": "Malware analysis sandbox. Look up a SHA-256 with lookup_hash, read a scan's derived report with get_report, find scans by indicator with search_indicator, and follow a running scan with poll_scan. Tokens granted the submit scope can queue new scans with submit_scan. Reports are derived data only: sample bytes, downloads and artifacts are never served here. A scan that does not exist and one you may not read give the same answer.",
"tools": [
{
"description": "The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never contains the sample's bytes, its decompiled source, a download link or an artifact reference. Every list in the result reports what was returned, counted and truncated. Answers 'not found' for a scan that does not exist and for one this token may not read, identically.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"scan_id": {
"description": "The scan's numeric id.",
"type": "integer"
}
},
"required": [
"scan_id"
],
"type": "object"
},
"name": "get_report",
"outputSchema": null
},
{
"description": "Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searches scans that already exist on this platform. Answers with an empty list when the hash is unknown or not visible to this token, without distinguishing the two.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"sha256": {
"description": "A 64 character hex SHA-256 digest.",
"maxLength": 64,
"minLength": 64,
"type": "string"
}
},
"required": [
"sha256"
],
"type": "object"
},
"name": "lookup_hash",
"outputSchema": {
"properties": {
"scans": {
"description": "A bounded list: items plus what was returned, counted and cut.",
"properties": {
"items": {
"type": "array"
},
"returned": {
"type": "integer"
},
"total": {
"type": "integer"
},
"truncated": {
"type": "boolean"
}
},
"required": [
"items",
"returned",
"total",
"truncated"
],
"type": "object"
},
"sha256": {
"type": "string"
}
},
"required": [
"sha256",
"scans"
],
"type": "object"
}
},
{
"description": "The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_available' means get_report will return a full report. Answers 'not found' for an unknown scan and an unreadable one identically.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"scan_id": {
"description": "The scan's numeric id.",
"type": "integer"
}
},
"required": [
"scan_id"
],
"type": "object"
},
"name": "poll_scan",
"outputSchema": {
"properties": {
"finished_at": {
"type": [
"string",
"null"
]
},
"mime": {
"type": [
"string",
"null"
]
},
"module": {
"type": "string"
},
"report_available": {
"type": "boolean"
},
"scan_id": {
"type": "integer"
},
"score": {
"type": [
"integer",
"null"
]
},
"sha256": {
"type": [
"string",
"null"
]
},
"size": {
"type": [
"integer",
"null"
]
},
"status": {
"type": "string"
},
"submitted_at": {
"type": [
"string",
"null"
]
},
"tags": {
"type": "object"
},
"terminal": {
"type": "boolean"
},
"verdict": {
"type": [
"string",
"null"
]
}
},
"type": "object"
}
},
{
"description": "Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; defanged input such as 'evil[.]com' is refanged first. Only scans this token may read are searched.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"indicator": {
"description": "The exact indicator value. Defanged forms are accepted.",
"maxLength": 512,
"type": "string"
},
"type": {
"description": "Optional indicator type to narrow the search: ip, domain, url, md5, sha1, sha256, imphash, mutex, registry, filepath, email, ja3, ja4, user_agent.",
"type": "string"
}
},
"required": [
"indicator"
],
"type": "object"
},
"name": "search_indicator",
"outputSchema": {
"properties": {
"indicator": {
"type": "string"
},
"matches": {
"description": "A bounded list: items plus what was returned, counted and cut.",
"properties": {
"items": {
"type": "array"
},
"returned": {
"type": "integer"
},
"total": {
"type": "integer"
},
"truncated": {
"type": "boolean"
}
},
"required": [
"items",
"returned",
"total",
"truncated"
],
"type": "object"
}
},
"required": [
"indicator",
"matches"
],
"type": "object"
}
},
{
"description": "Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or a document is not possible over MCP. This spends the account's own credits and is subject to its plan limits. Poll the returned scan_id with poll_scan, then read it with get_report.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"module": {
"description": "hash: look up a SHA-256. url: visit a URL in a browser VM. command: run a command line in a Windows VM. package: install a package in a Linux VM. url and package detonate with internet access and are refused on a plan that does not include it.",
"enum": [
"hash",
"url",
"command",
"package"
],
"type": "string"
},
"private": {
"description": "Keep the scan off the public corpus. Free plans cannot make a scan private and this is ignored for them.",
"type": "boolean"
},
"target": {
"description": "The digest, URL, command line or package specifier, matching the chosen module.",
"maxLength": 2048,
"type": "string"
}
},
"required": [
"module",
"target"
],
"type": "object"
},
"name": "submit_scan",
"outputSchema": {
"properties": {
"finished_at": {
"type": [
"string",
"null"
]
},
"mime": {
"type": [
"string",
"null"
]
},
"module": {
"type": "string"
},
"report_available": {
"type": "boolean"
},
"scan_id": {
"type": "integer"
},
"score": {
"type": [
"integer",
"null"
]
},
"sha256": {
"type": [
"string",
"null"
]
},
"size": {
"type": [
"integer",
"null"
]
},
"status": {
"type": "string"
},
"submitted_at": {
"type": [
"string",
"null"
]
},
"tags": {
"type": "object"
},
"terminal": {
"type": "boolean"
},
"verdict": {
"type": [
"string",
"null"
]
}
},
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:9d1de01f9127ea5562c01fe04050c317bca8747be6ea6ce9a7d1b7ecbb5bc534 | sha256sum