Developer · Local MCP server
Abnormal Security
MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.wyre-technology/abnormal-mcp- Version
- 1.2.5
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- OCI image (Docker)
- Published
- 2026-08-20
- Updated
- 2026-08-20
- Publisher
- wyre-technology (GitHub) · 53 servers with pages here
- Listed under
- Email MCP servers
- Website
- github.com/wyre-technology/abnormal-mcp
- Repository
- github.com/wyre-technology/abnormal-mcp
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| OCI image (Docker) | ghcr.io/wyre-technology/abnormal-mcp:v1.2.5 | — | stdio |
How to connect Abnormal Security
Abnormal Security runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/wyre-technology/abnormal-mcp:v1.2.5. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e ABNORMAL_API_TOKEN -e MCP_TRANSPORT -e AUTH_MODE -e LOG_LEVEL ghcr.io/wyre-technology/abnormal-mcp:v1.2.5. It reads these environment variables: ABNORMAL_API_TOKEN (required, secret), MCP_TRANSPORT, AUTH_MODE and LOG_LEVEL; set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"abnormal-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ABNORMAL_API_TOKEN",
"-e",
"MCP_TRANSPORT",
"-e",
"AUTH_MODE",
"-e",
"LOG_LEVEL",
"ghcr.io/wyre-technology/abnormal-mcp:v1.2.5"
],
"env": {
"ABNORMAL_API_TOKEN": "<secret>",
"MCP_TRANSPORT": "<value>",
"AUTH_MODE": "<value>",
"LOG_LEVEL": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from wyre-technology (GitHub)
| Server | Runs |
|---|---|
| Action1Action1 MCP server — endpoint inventory, patch visibility, and policy automation via REST API. | Local · stdio |
| Alternative PaymentsMCP server for Alternative Payments — customers, invoices, payment requests, payouts, webhooks. | Local · stdio |
| AutotaskMCP server for Kaseya Autotask PSA — companies, tickets, projects, time entries, and more. | Local · stdio |
| AuvikMCP server for the Auvik network monitoring API — devices, alerts, statistics, billing. | Local · stdio |
| AvananMCP server for Check Point Harmony Email & Collaboration (Avanan) email security. | Local · stdio |
| Avanan MSP (Legacy SmartAPI)MCP server for the Avanan MSP SmartAPI — manage child MSPs, users, tenants, licenses, and usage. | Local · stdio |
| Axcient x360RecoverMCP server for Axcient x360Recover — BCDR clients, devices, jobs, vaults, and appliances. | Local · stdio |
| BlumiraMCP server for Blumira SIEM — query findings, evidence, and detection data via the Blumira API. | Local · stdio |
| CIPPMCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies). | Local · stdio |
| Cisco MerakiMCP server for the Cisco Meraki Dashboard: networks, devices, wireless, switch, appliance. | Local · stdio |
| ConnectWise AutomateMCP server for ConnectWise Automate RMM — computers, clients, alerts, and scripts. | Local · stdio |
| ConnectWise CPQMCP server for ConnectWise CPQ (Sell) — quotes, line items, customers, terms, and templates. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| AblyMCP server for Ably — channel history, presence, occupancy, stats, publish, and app management. | Remote · HTTP |
| ABMeterRun A/B experiments through your AI assistant. SDKs for Ruby, Python, JS, Node, React Native, Go. | Remote · HTTP |
| Abnormal MCP ServerAbnormal Security MCP: threats, search, remediation, ATO cases, vendor/BEC, and evidence download. | Local · stdio |
| Abnormal SecurityMCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation. | Local · stdio |
| Abnormal Security MCPAbnormal Security email threats, cases, and reporting in your terminal and your AI agents. | Local · stdio |
| AbscissaSafety-aware MCP server for Linear issues, projects, cycles, and dependencies. | Local · stdio |
| Abstraxn Agent LayerAbstraxn: public Web3 MCP server for read-only chain data and pay-per-call relays. | Remote · HTTP |
| Abuseipdb MCPMCP server for AbuseIPDB: IP abuse reports, reputation. Free key. | Local · stdio |