Virustotal MCP for AI Agents

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with Virustotal MCP or direct API to scan files or URLs, retrieve threat reports, analyze suspicious indicators, and automate security workflows through natural language.

Virustotal logoVirustotal
Api Key

Virustotal is a malware analysis service that checks files and URLs against dozens of antivirus engines. It helps individuals and organizations quickly detect and investigate potential threats.

16 Tools

Try Virustotal now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
Virustotal
Try asking
TOOLS

Supported Tools

Every Virustotal action and event your agent gets out of the box.

Add VirusTotal Comment

Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address).

Add Vote

Tool to add a vote (harmless/malicious) to a VirusTotal resource.

Get Analysis Report

Tool to retrieve the analysis report of a file or URL submission.

Get comments

Tool to retrieve the latest comments on a VirusTotal resource.

Get Domain Relationships

Tool to retrieve relationship objects for a given domain.

Get Domain Report

Tool to retrieve the analysis report of a domain.

Get File Report

Tool to retrieve the analysis report of a file.

Get IP Address Relationships

Tool to retrieve objects related to a specific IP address by relationship type.

Get IP Address Report

Tool to retrieve the analysis report of an IP address.

Get VirusTotal Metadata

Tool to retrieve VirusTotal metadata.

Get URL Report

Tool to retrieve the analysis report of a URL.

Get Votes

Tool to retrieve votes on files, URLs, domains, or IP addresses.

Rescan File

Tool to re-analyze a previously submitted file.

Scan URL

Tool to submit a URL for scanning.

Search VirusTotal

Tool to search for objects in the VirusTotal database.

Upload File

Tool to upload a file for scanning.

SETUP GUIDE

Connect Virustotal MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/openai @ai-sdk/mcp
Install the Composio SDK and Claude Agent SDK
2

Create Tool Router Session

typescript
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: 'your-api-key' });

console.log("Creating Tool Router session...");
const { mcp } = await composio.create('your-user-id');
console.log(`Tool Router session created: ${mcp.url}`);
Initialize the Composio client and create a Tool Router session
3

Connect to AI Agent

typescript
import { openai } from '@ai-sdk/openai';
import { experimental_createMCPClient as createMCPClient } from '@ai-sdk/mcp';
import { generateText, stepCountIs } from 'ai';

const client = await createMCPClient({
  transport: {
    type: 'http',
    url: mcp.url,
    headers: { 'x-api-key': 'your-composio-api-key' }
  }
});

const tools = await client.tools();

const { text } = await generateText({
  model: openai('gpt-4o'),
  tools,
  messages: [{ role: 'user', content: 'Get the analysis report for file hash 44d88612fea8a8f36de82e1278abb02f' }],
  stopWhen: stepCountIs(5)
});

console.log(`Agent: ${text}`);
Use the MCP server with your AI agent
SETUP GUIDE

Connect Virustotal API Tool with your Agent

1

Install Composio

typescript
npm install @composio/openai
Install the Composio SDK
2

Initialize Composio and Create Tool Router Session

typescript
import OpenAI from 'openai';
import { Composio } from '@composio/core';
import { OpenAIResponsesProvider } from '@composio/openai';

const composio = new Composio({
  provider: new OpenAIResponsesProvider(),
});
const openai = new OpenAI({});
const session = await composio.create('your-user-id');
Import and initialize Composio client, then create a Tool Router session
3

Execute Virustotal Tools via Tool Router with Your Agent

typescript
const tools = session.tools;
const response = await openai.responses.create({
  model: 'gpt-4.1',
  tools: tools,
  input: [{
    role: 'user',
    content: 'Scan this suspicious file hash for threats'
  }],
});
const result = await composio.provider.handleToolCalls(
  'your-user-id',
  response.output
);
console.log(result);
Get tools from Tool Router session and execute Virustotal actions with your Agent

Why Use Composio?

AI Native Virustotal Integration

  • Supports both Virustotal MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for submitting, scanning, and querying files, URLs, and reports

Managed Auth

  • Built-in API key management, securely handled by Composio
  • Central place to manage, scope, and revoke Virustotal access
  • Per user and per environment credentials instead of hard-coded keys

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access Virustotal
  • Scoped, least privilege access to Virustotal resources
  • Full audit trail of agent actions to support review and compliance
FAQ

Frequently asked questions

Yes, Virustotal requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Composio is SOC 2 and ISO 27001 compliant with all data encrypted in transit and at rest. Learn more.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

Start with Virustotal.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Virustotal tool your agent needs.Free to start.

Start building