How to connect Virustotal MCP with VS Code

How to connect Virustotal MCP with VS Code VS Code is the most popular code editor out there. With its recent AI makeover, it can do more than just help you write code. You can connect your applications to it and let LLMs automate many of the mundane tasks in your workflow. In this guide, I will explain how to connect Virustotal with VS Code in the most secure and robust way possible via Composio.

Virustotal logoVirustotal
Api Key

Virustotal is a malware analysis service that checks files and URLs against dozens of antivirus engines. It helps individuals and organizations quickly detect and investigate potential threats.

16 Tools

How to connect Virustotal MCP with VS Code

VS Code is the most popular code editor out there. With its recent AI makeover, it can do more than just help you write code. You can connect your applications to it and let LLMs automate many of the mundane tasks in your workflow.

In this guide, I will explain how to connect Virustotal with VS Code in the most secure and robust way possible via Composio.

Also integrate Virustotal with

Why use Composio?

Composio provides:

  • Access to 1,000+ managed apps from a single MCP endpoint. This makes it convenient for agents to run cross-app workflows.
  • Programmatic tool calling. Allows LLMs to write its code in a remote workbench to handle complex tool chaining. Reduces to-and-fro with LLMs for frequent tool calling.
  • Large tool response handling outside the LLM context. This minimizes context bloat from large tool responses.
  • Dynamic just-in-time access to thousands of tools across hundreds of apps. Composio loads the tools your agent needs, so LLMs are not overwhelmed by tools they do not need.

Integrate Virustotal MCP with VS Code

1. Install with one click

Click the button below to add Composio to VS Code. You will be prompted to authorize. This requires VS Code 1.99+ with GitHub Copilot.

+Install in VS Code

2. Or add manually

Open or create .vscode/mcp.json in your project root and add the following configuration:

bash
{
  "servers": {
    "composio": {
      "type": "http",
      "url": "https://connect.composio.dev/mcp"
    }
  }
}

3. Authorize

Click the install button to authorize VS Code to connect to Composio. VS Code will detect OAuth and prompt you to sign in.

VS Code MCP server install screen for Composio

A browser window will open to authorize.

Composio authorization browser window

4. Authenticate Virustotal and start working

Back in VS Code chat, ask the agent to connect to Virustotal or give it any Virustotal-related task.

For example, ask it to:

  • "Scan this file hash for malware"
  • "Get analysis report for suspicious URL"
  • "Retrieve domain reputation details"

It will prompt you to authenticate and authorize access to Virustotal.

That is it. Composio tools are now available in VS Code, and your Virustotal account is ready to use.

Way Forward

Now that Virustotal is connected, extend your setup by connecting the other apps you already use every day, so your agent can run true cross-app workflows end to end.

  • Connect Calendar to turn threads into scheduled meetings automatically.
  • Connect Slack or Teams to post summaries, approvals, and alerts where your team works.
  • Connect Notion, Linear, Jira, or Asana to convert requests into tickets, tasks, and docs.
  • Connect Drive, Dropbox, or OneDrive to fetch, file, and share attachments without manual steps.
  • Connect HubSpot or Salesforce to log customer context, update records, and draft follow-ups.

Start with one workflow you do repeatedly, then keep adding apps as you find new handoffs. With everything behind a single MCP endpoint, your agent can coordinate multiple tools safely and reliably in one conversation.

TOOLS

Supported Tools

Every Virustotal action and event your agent gets out of the box.

Add VirusTotal Comment

Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address).

Add Vote

Tool to add a vote (harmless/malicious) to a VirusTotal resource.

Get Analysis Report

Tool to retrieve the analysis report of a file or URL submission.

Get comments

Tool to retrieve the latest comments on a VirusTotal resource.

Get Domain Relationships

Tool to retrieve relationship objects for a given domain.

Get Domain Report

Tool to retrieve the analysis report of a domain.

Get File Report

Tool to retrieve the analysis report of a file.

Get IP Address Relationships

Tool to retrieve objects related to a specific IP address by relationship type.

Get IP Address Report

Tool to retrieve the analysis report of an IP address.

Get VirusTotal Metadata

Tool to retrieve VirusTotal metadata.

Get URL Report

Tool to retrieve the analysis report of a URL.

Get Votes

Tool to retrieve votes on files, URLs, domains, or IP addresses.

Rescan File

Tool to re-analyze a previously submitted file.

Scan URL

Tool to submit a URL for scanning.

Search VirusTotal

Tool to search for objects in the VirusTotal database.

Upload File

Tool to upload a file for scanning.

FAQ

Frequently asked questions

With a standalone Virustotal MCP server, the agents and LLMs can only access a fixed set of Virustotal tools tied to that server. However, with the Composio Tool Router, agents can dynamically load tools from Virustotal and many other apps based on the task at hand, all through a single MCP endpoint.

Yes, you can. VS Code fully supports MCP integration. You get structured tool calling, message history handling, and model orchestration while Tool Router takes care of discovering and serving the right Virustotal tools.

Yes, absolutely. You can configure which Virustotal scopes and actions are allowed when connecting your account to Composio. You can also bring your own OAuth credentials or API configuration so you keep full control over what the agent can do.

All sensitive data such as tokens, keys, and configuration is fully encrypted at rest and in transit. Composio is SOC 2 Type 2 compliant and follows strict security practices so your Virustotal data and credentials are handled as safely as possible.

Start with Virustotal.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Virustotal tool your agent needs.Free to start.

Start building