Malwarebytes
by Malwarebytes
Check a link, phone number or email address against Malwarebytes threat intelligence before you click, call or reply. 6 tools, no account, no sign-in. One tool submits a report and is annotated destructive.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Connect Malwarebytes via MCP
https://scamguard.malwarebytes.com/claude/mcpWorks in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.
Malwarebytes Tools & Capabilities (6)
Use this when you need to check if a link or URL is safe, suspicious, or malicious. Provides reputation verdict based on threat intelligence database. Returns one of: - malicious: Confirmed harmful link - suspicious: Potentially dangerous link - safe: Verified safe link - unknown: No threat intelligence available Cross-tool workflow: - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). - If the URL redirects to a different domain, consider scanning the destination URL separately. - If the URL came from an email or text message, consider checking the sender with reputation-check_email or reputation-check_phone. Do not use this for general web searches, content fetching, or webpage analysis.
Use this when you need to check if a phone number is associated with scams or suspicious activity. Provides reputation verdict and additional phone information. Returns one of: - malicious: Confirmed scam or spam phone number - suspicious: Potentially dangerous number - safe: Verified legitimate number - unknown: No threat intelligence available Also provides optional details like carrier, location, and phone type when available. Cross-tool workflow: - If the caller provided links, consider scanning them with reputation-check_link. - If the caller provided email addresses, consider scanning them with reputation-check_email. Do not use this for phone number lookups, caller ID services, or general phone directory searches.
Use this when you need to check if an email address is associated with phishing, scams, or malicious activity. Checks the email domain against threat intelligence database. Returns one of: - malicious: Confirmed phishing or malicious email domain - suspicious: Potentially dangerous email domain - safe: Verified legitimate email domain - unknown: No threat intelligence available Cross-tool workflow: - If the email contains URLs, consider scanning them with reputation-check_link. - If the email contains phone numbers, consider scanning them with reputation-check_phone. - For unknown or suspicious verdicts, consider using reputation-whois to check domain registration details (age, registrar, abuse contact). Do not use this for email validation, mailbox verification, or general email lookup services.
Use this when a user wants to report a suspicious link, email address, or phone number. Submits the indicator to the threat intelligence system for analysis. Only use when explicitly requested by the user. Do not use this to automatically report every checked item.
Use this when you need to look up domain registration information to verify legitimacy or identify suspicious patterns. Provides WHOIS/RDAP data including registrar, registration dates, name servers, and abuse contacts. Particularly useful for identifying newly registered domains (common in phishing and scams). Returns the registrar's abuse contact email when available, which can be used for filing complaints about fraudulent domains. Cross-tool workflow: - Consider using reputation-check_link to check the domain's threat reputation alongside WHOIS registration data. Do not use this for general domain availability checks or bulk domain searches.
Use this when you need to check multiple links, emails, or phone numbers at once. Scans all indicators concurrently and returns a unified result. Each indicator needs: - type: 'url', 'email', or 'phone' - value: the URL, email address, or phone number (E.164 format for phones) Returns a summary with counts per verdict and individual results for each indicator. Prefer this over individual scan tools when 3 or more indicators are present. Maximum 10 indicators per request. Cross-tool workflow: - For unknown URL or email verdicts, consider using reputation-whois on the associated domains for additional registration context and abuse contact information.
Read from the server on 2026-08-16, including each tool's own safety annotations.
Limits
- It is not device protection. No tool scans a machine, removes malware or monitors anything. Six indicator lookups and one report submission are the whole surface.
- One tool writes outward.
reputation-reportis annotated destructive because it submits an indicator to Malwarebytes, which its Scam Guard documentation says may be added to the protection database. There is no tool that withdraws a submission. - "Unknown" is not "safe." Malwarebytes states plainly that an unknown verdict means no information is available and warns readers to remain careful. Four verdicts, and only one of them is reassuring.
- An email check tests the domain.
reputation-check_emailchecks the sender's domain, so a clean verdict does not vouch for the individual address. - Ten indicators per call.
reputation-scan_allcaps a single request at 10, per its own tool description. - Phone numbers need E.164 format.
reputation-check_phonerequires the international form, such as a leading+and country code. - No published rate limits or error codes. Malwarebytes' connector article has no troubleshooting or rate-limit section; it directs problems to Malwarebytes Support and connector questions to Claude Support.
- We did not exercise any tool. Our check was a read-only
tools/listhandshake. We deliberately did not callreputation-report, because doing so would have submitted a real indicator to a live threat intelligence system.
Frequently asked questions
Why is reputation-report annotated destructive when it only files a report?
Because it writes to Malwarebytes rather than to you. The tool submits an indicator to the threat intelligence team, and Malwarebytes says a submitted item can be added to its protection database. The submission cannot be recalled from the conversation, so the vendor flags an outbound, irreversible write even though nothing on your side changes.
Does the Malwarebytes connector scan my computer for malware?
No. All six tools take a URL, phone number, email address or domain as text and return a verdict from threat intelligence. Malwarebytes describes the connector as checking items you share in the conversation. Nothing reads your files, monitors your device or removes anything, so it does not replace antivirus software.
Do you need a Malwarebytes subscription to use the MCP server?
No. Malwarebytes states that no subscription or account is needed and that it works for both paid and free Claude users. Its April 2026 announcement calls the connector free with no Malwarebytes account required. We confirmed the endpoint completes an anonymous handshake on 2026-08-16.
What do the malicious, suspicious, safe and unknown verdicts mean?
They rank confidence, not severity. Malwarebytes defines malicious as a confirmed threat, suspicious as risky context without a confirmed threat, and safe as known and legitimate. Unknown means the database holds no information — and Malwarebytes warns explicitly that unknown does not mean safe, which is the verdict most likely to be misread.
What data does Malwarebytes receive from my conversation?
Only the indicators you share. Malwarebytes states that just the specific items sent — links, phone numbers or email addresses — reach its threat intelligence service, and that conversation messages and personal information are not stored. For a report it says only the indicator and its type are submitted, with no conversation content included.
Sources
- Malwarebytes connector documentation, "Using Malwarebytes in Claude" (retrieved 2026-08-16 via the Zendesk public Help Center API, HTTP 200; the rendered HTML page returns a Cloudflare 403 to automated clients, so the article JSON at
/api/v2/help_center/en-us/articles/47985341083675.jsonwas used.robots.txton this host does not disallow/hc/en-us/articles/. Setup steps, six features, four verdict definitions, data handling and example prompts) · retrieved 2026-08-16 - Malwarebytes, "Detecting threats with Scam Guard on Desktop Security" (retrieved 2026-08-16, same API route; states a submitted item may be added to the protection database — the evidence behind the destructive annotation) · retrieved 2026-08-16
- Malwarebytes, "How Scam Guard uses your chat information" (retrieved 2026-08-16, same API route; submission and retention detail) · retrieved 2026-08-16
- Malwarebytes press release, "Malwarebytes Brings Real-time Scam Detection and Threat Intelligence to AI Conversations with Claude Connector" (retrieved 2026-08-16, HTTP 200, zero redirects; free, no account, indicator-only reporting) · retrieved 2026-08-16
- Live
tools/listhandshake againsthttps://scamguard.malwarebytes.com/claude/mcp— 6 tools with descriptions, input schemas and safety annotations, anonymous connection accepted (2026-08-16) · retrieved 2026-08-16 - Anthropic Connectors Directory entry (from the 2026-08-16 directory snapshot; partner tier, productivity category, endpoint, six tool names) · retrieved 2026-08-16
- Malwarebytes support — · Privacy (HTTP 200, zero redirects, 2026-08-16) · retrieved 2026-08-16
Use in Agentman
Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.
Open in Agentman StudioServer Info
- Category
- Productivity
- Developer
- Malwarebytes
- Tools
- 6
- Domain
- scamguard.malwarebytes.com
Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.