Qu1cksc0pe
A malware analysis tool with an MCP server: the agent calls file, document and archive analysis, indicator extraction and signature checks
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Analyzes potentially malicious files
- Can call external services such as VirusTotal with a key
Install
Manual install
pip install "mcp>=2.0.0"Dependency for the MCP server; the tool itself is installed from the cloned repository.
This is third-party code. Review the repository files before installing.
What it does
Qu1cksc0pe is a toolkit for static and dynamic analysis of suspicious files across platforms. A separate MCP server exposes part of its features to the agent as tools: analyze a file, document or archive, detect the packer and language, extract indicators, check resources and signatures, look up a hash and query VirusTotal. Each tool validates the input file locally and returns a JSON report along with the output. Interactive modes such as dynamic watching are intentionally not exposed over MCP.
Who it is for. For security professionals doing authorized analysis of suspicious files.
Good fit when
- You need to quickly analyze a suspicious file or document
- You need to extract indicators of compromise
- You need to check hash databases and VirusTotal
Not a fit when
- You are not authorized to analyze these files
- You need to handle live malware outside an isolated environment rather than defensive analysis
Example request
Analyze this file with Qu1cksc0pe: detect the packer, extract indicators and check the hashLimitations
Analyze malicious files in an isolated environment. The MCP tools reject files of 50MB and larger and do not include interactive modes. VirusTotal lookups and model-assisted analysis need their own keys.
How to disable. Remove the qu1cksc0pe server from your MCP config and delete the cloned repository.
MCP
- Transport
- stdio, http
- Authentication
- not required
| Environment variables | |
|---|---|
| SC0PE_MCP_TRANSPORT | Server transport: streamable-http, stdio or sse |
Security check
- Analyzes potentially malicious files
- Can call external services such as VirusTotal with a key
README in short
The README describes Qu1cksc0pe as a malware analysis toolkit and its MCP server. By default the server uses streamable-http transport and listens on a local port, with a stdio mode; for Claude Code the repository includes an .mcp.json. It lists the tools exposed to the agent and notes that files of 50MB and larger are rejected and interactive modes are not exposed. VirusTotal and model provider keys are set separately.
FAQ
Which tools are available to the agent?
Analyze a file, document and archive, detect packer and language, extract indicators, check resources and signatures, look up a hash and query VirusTotal.
What if python3 is the wrong one?
Set the full path to the interpreter that has the dependencies installed in the config.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents