PluginBench
MCP Server
Active
MIT

Cyberbro MCP Server MCP Server

io.github.stanfrbd/mcp-cyberbro

Extract and analyze indicators of compromise (IoCs) with Cyberbro threat intelligence.

What is the Cyberbro MCP Server MCP server?

The Cyberbro MCP Server integrates Cyberbro's IOC extraction and reputation analysis into MCP-capable assistants. It enables analysis of observables (IPs, domains, URLs, hashes) across multiple threat intelligence engines for security investigations and OSINT workflows.

This server connects Claude, Cursor, and other MCP clients to Cyberbro for automated threat analysis. You can submit indicators of compromise, check their reputation across multiple engines (GitHub, Google, VirusTotal, etc.), and retrieve detailed analysis results—useful for security research, incident response, and OSINT investigations.

How to install Cyberbro MCP Server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • CYBERBRO_URL
    required

    Base URL of Cyberbro (for example http://localhost:5000)

  • API_PREFIX

    Cyberbro API prefix (default: api)

  • SSL_VERIFY

    Enable/disable SSL verification for Cyberbro API calls (true/false)

  • MCP_TRANSPORT

    Transport override: stdio, sse or streamable-http

  • MCP_HOST

    Host for HTTP transports

  • MCP_PORT

    Port for HTTP transports

  • MCP_MOUNT_PATH

    Mount path for SSE transport

  • MCP_SSE_PATH

    SSE endpoint path

  • MCP_STREAMABLE_HTTP_PATH

    Streamable HTTP endpoint path

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-cyberbro": {
      "command": "uvx",
      "args": [
        "mcp-cyberbro"
      ],
      "env": {
        "CYBERBRO_URL": "<YOUR_CYBERBRO_URL>",
        "API_PREFIX": "<YOUR_API_PREFIX>",
        "SSL_VERIFY": "<YOUR_SSL_VERIFY>",
        "MCP_TRANSPORT": "<YOUR_MCP_TRANSPORT>",
        "MCP_HOST": "<YOUR_MCP_HOST>",
        "MCP_PORT": "<YOUR_MCP_PORT>",
        "MCP_MOUNT_PATH": "<YOUR_MCP_MOUNT_PATH>",
        "MCP_SSE_PATH": "<YOUR_MCP_SSE_PATH>",
        "MCP_STREAMABLE_HTTP_PATH": "<YOUR_MCP_STREAMABLE_HTTP_PATH>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • analyze_observable — Submit an observable (IP, domain, URL, hash, etc.) for analysis via Cyberbro engines.
  • is_analysis_complete — Check if a submitted analysis has completed processing.
  • get_analysis_results — Retrieve detailed analysis results for a submitted observable.
  • get_engines — List available threat intelligence engines for analysis.
  • get_web_url — Get the web URL for viewing analysis results in Cyberbro's interface.

Use cases

  • Check IP and domain reputation across multiple threat intelligence engines during incident response.
  • Analyze suspicious file hashes and URLs to determine if they are malicious.
  • Conduct OSINT investigations by submitting indicators and pivoting on results.
  • Automate threat indicator extraction and enrichment in security workflows.
  • Generate threat analysis reports with multi-engine consensus on observable reputation.

Cyberbro MCP Server MCP server FAQ

What is the Cyberbro MCP Server?

It's an MCP server that integrates Cyberbro's threat intelligence platform, allowing you to analyze indicators of compromise (IPs, domains, URLs, hashes) across multiple engines directly from Claude, Cursor, or other MCP clients.

Is it free to use?

The server itself is open-source (MIT license), but it requires a running Cyberbro instance (self-hosted or external) specified via the CYBERBRO_URL environment variable.

How do I install it in Cursor or Claude?

Install via `pip install mcp-cyberbro` or use `uvx mcp-cyberbro`, then add it to your MCP client config (e.g., Claude Desktop, Cursor, or VSCode) with the CYBERBRO_URL pointing to your Cyberbro instance.

What authentication is required?

No API key or authentication is required for the MCP server itself; you only need network access to your Cyberbro instance via the CYBERBRO_URL.

What threat intelligence engines does it support?

It supports any engines available in your Cyberbro instance; examples mentioned include GitHub, Google, and VirusTotal. Use the get_engines tool to list available engines.

Can I run it in Docker?

Yes, a Docker image is available at ghcr.io/stanfrbd/mcp-cyberbro:latest. It runs in streamable-http mode by default on port 8000, or you can build a custom image for stdio transport.

README (reference)

Source of truth, from the repository.

<!-- mcp-server: cyberbro | tools: 5 | resources: 0 | transport: stdio,sse,streamable-http | auth: none | framework: fastmcp --> <!-- mcp-name: io.github.stanfrbd/mcp-cyberbro -->

MseeP.ai Security Assessment Badge

<h1 align="center">Cyberbro MCP Server</h1> <p align="center"> <img src="https://github.com/user-attachments/assets/5e5a4406-99c1-47f1-a726-de176baa824c" width="90" /><br /> <b><i>Extract IoCs from messy text and analyze them with Cyberbro.</i></b> <br /> <b>🌐 <a href="https://demo.cyberbro.net/">demo.cyberbro.net</a></b><br /> </p>

mcp-cyberbro-demo

Model Context Protocol server for Cyberbro.

This project is packaged as a standard Python distribution and can be launched with:

  • uvx mcp-cyberbro
  • pip install mcp-cyberbro then mcp-cyberbro

Why this server

  • Analyze observables (IP, domain, URL, hash, etc.) via Cyberbro engines.
  • Integrate threat-analysis actions directly in MCP-capable assistants.
  • Run with stdio, sse, or streamable-http transports.
  • Compatible with any MCP client that supports one of these transports.

Installation

Use with uvx (standalone)

uvx mcp-cyberbro --cyberbro_url http://localhost:5000

Use with pip

pip install mcp-cyberbro
mcp-cyberbro --cyberbro_url http://localhost:5000

Local development

pip install -e .
mcp-cyberbro --cyberbro_url http://localhost:5000

Docker

Default container command starts in streamable-http mode on port 8000.

docker run --rm -p 8000:8000 \
  -e CYBERBRO_URL=http://host.docker.internal:5000 \
  ghcr.io/stanfrbd/mcp-cyberbro:latest

To run in stdio mode, a custom Dockerfile is required:

FROM ghcr.io/stanfrbd/mcp-cyberbro:latest
CMD ["mcp-cyberbro", "--transport", "stdio"]

Build and use it:

docker build -t mcp-cyberbro-stdio .
docker run -i --rm -e CYBERBRO_URL=http://host.docker.internal:5000 mcp-cyberbro-stdio

Configuration

Copy .env.example and set at least:

  • CYBERBRO_URL (required)

Supported environment variables:

  • CYBERBRO_URL
  • API_PREFIX (default: api)
  • SSL_VERIFY (true/false)
  • MCP_TRANSPORT (stdio, sse, streamable-http)
  • MCP_HOST
  • MCP_PORT
  • MCP_MOUNT_PATH
  • MCP_SSE_PATH
  • MCP_STREAMABLE_HTTP_PATH

CLI flags are also available and override env values.

MCP Client Integration

You can use this server with Claude Desktop, Claude Code, Cursor, OpenAI-compatible MCP clients, or any other MCP client.

Example config using uvx:

{
  "mcpServers": {
    "cyberbro": {
      "command": "uvx",
      "args": ["mcp-cyberbro"],
      "env": {
        "CYBERBRO_URL": "http://localhost:5000"
      }
    }
  }
}

To use Docker with stdio transport (required by some MCP clients), build a custom image as shown in the Docker section above, then reference it:

{
  "mcpServers": {
    "cyberbro": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-e", "CYBERBRO_URL", "mcp-cyberbro-stdio"],
      "env": {
        "CYBERBRO_URL": "http://localhost:5000"
      }
    }
  }
}

Usage in VSCode - Example

Create .vscode/mcp.json

{
	"servers": {
		"mcp-cyberbro": {
			"type": "stdio",
			"command": "uvx",
			"args": [
				"mcp-cyberbro"
			],
			"env": {
				"CYBERBRO_URL": "http://127.0.0.1:5000"
			}
		}
	}
}

MCP Registry Metadata

server.json is included for MCP Registry publication and points to PyPI package mcp-cyberbro.

Release Pipelines

Release-created workflows:

  • .github/workflows/publish-test-pypi.yml
  • .github/workflows/publish-pypi.yml
  • .github/workflows/publish-mcp-plugin.yml

Available Tools

  • analyze_observable
  • is_analysis_complete
  • get_analysis_results
  • get_engines
  • get_web_url

Example Prompts

Here are practical prompt examples you can use with any MCP-capable assistant connected to Cyberbro.

Getting Indicator Details

  • Cyberbro: Check indicators for target.com
  • Can you check this IP reputation with Cyberbro? 192.168.1.1. Use github, google and virustotal engines.
  • I want to analyze the domain example.com. What can Cyberbro tell me about it? Use max 3 engines.
  • Analyze these observables with Cyberbro: suspicious-domain.com, 8.8.8.8, and 44d88612fea8a8f36de82e1278abb02f. Use all available engines.

Observable Analysis

  • I found this (hash|domain|url|ip|extension). Can you submit it for analysis to Cyberbro and analyze the results?

OSINT Investigation

  • Create an OSINT report for the domain example.com using Cyberbro. Use all available engines and pivot on the results for more information. Use a maximum of 10 analysis requests.

Acknowledgements

License

MIT

Related MCP servers

Add inline, range-anchored comments to Google Docs - the one comment op the Google APIs can't do.

3
JavaScript
MIT
View repository →

Astrology decision support: accurate Swiss Ephemeris charts with calibrated classical verdicts.

Karea task manager - 12 tools covering 69 actions, for Claude Code, Cursor, and other MCP clients.

1
JavaScript
MIT
View repository →
STStarfetch logo

Starfetch

Active

Query public astronomy catalogs through metadata-first TAP and ADQL tools.

0
TypeScript
MIT
View repository →

Search the Federal Register, read & diff CFR sections, query Regulations.gov. Any LLM supported.

Vet a package (CVEs, license, maintenance) before your AI agent uses it, plus capability discovery.

8
TypeScript
View repository →