McAfee

Check suspicious emails, texts and links for scams inside an AI chat, backed by McAfee's Scam Detector.

Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.

Paste it into any MCP client. Setup docs

What the McAfee connector does

The McAfee MCP server puts McAfee's Scam Detector inside Claude, ChatGPT and any MCP-compatible agent. Anthropic's directory lists 3 tools that analyse a pasted email, text message or link and explain the risk with guidance on what to do next. No McAfee account, subscription or sign-in is required.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

McAfee tools (3)

  • check_email_for_scam
  • check_text_for_scam
  • check_website_url

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • McAfee's entire web estate was unreachable from our network. The nominated support article, the blog post, llms.txt, llms-full.txt, robots.txt and the sitemap each returned 403 from Akamai to every client we tried, including a browser user agent and a text-extraction service. Everything attributed to McAfee below and above comes from search-engine extracts of its pages, not from pages we read ourselves. That is a materially weaker source than a direct fetch, and it is why we record the documentation as unavailable despite it existing.
  • The support article is a Salesforce Experience Cloud page with no public mirror. We probed mcafee.my.site.com, mcafee.force.com and mcafee.secure.force.com for the same article number; all three resolved and returned 404. Unlike other Salesforce-hosted vendor docs in this catalogue, no alternate hostname serves this content, and the Aura endpoint that would carry the article's JSON is behind the same 403.
  • McAfee publishes no tool list for this server. The three names come from Anthropic's directory. We could not diff them against a vendor enumeration in either direction, and no screenshot, exclusion table or negative enumeration was reachable either.
  • We could not verify the endpoint's behaviour at all. Every path on claudecompanion.gateway.api.mcafee.com, including a nonsense control path, returned the same 403 from an AWS load balancer. We read no tool schemas, no safety annotations and no RFC 9728 metadata, and the "no subscription required" claim is McAfee's, not our observation.
  • No retention or model-training statement for connector submissions could be retrieved. This is the single largest gap on this page, and it is the one place where a directly comparable connector does better: Norton publishes its schedule, McAfee's equivalent is behind the block.
  • The on-device marketing claim does not describe this connector. McAfee promotes Scam Detector as analysing content on-device where possible. A remote MCP server sends content to a network endpoint by definition. Do not carry the app's privacy posture across to the connector.
  • A verdict is an assessment, not a guarantee. Scam detection is probabilistic, and a "safe" result should lower your suspicion rather than end it. We found no McAfee statement about how it handles an inconclusive case on this connector.
  • No rate limits are published. We found no statement from McAfee about request limits, quotas or throttling on this connector, and could not test for them.
  • We found no pricing or metering of any kind. Nothing in the surface spends money or credits, and McAfee states the integration does not require a subscription. No tool in the listing could observe a spend if one existed.
  • Support runs through a dedicated mailbox, not the general queue. The directory lists claudeapp-support@mcafee.com for this connector specifically.

Frequently asked questions

Can the McAfee connector change my security settings or turn off protection?

No. All three tools Anthropic lists begin with check, and none carries a verb that sets, enables, disables, installs or configures anything. McAfee describes the connector as analysis that explains a risk and advises what to do next. There is no McAfee sign-in, so the server has no account or device to apply a setting to.

Does the McAfee connector need a McAfee subscription?

No. McAfee's blog states the Claude and McAfee integration is available to anyone and that you do not have to be a McAfee subscriber, and that it works on the free Claude plan. Anthropic's directory records the endpoint as authless with no OAuth flow, so no consent screen scopes the connector's access.

Can the McAfee connector read my password manager or my identity monitoring records?

No tool in the listing reaches either. McAfee's password manager, identity monitoring and personal data cleanup are separate subscription products bound to a McAfee account, and this connector requires no account at all. With no sign-in there is no identity for the server to attach a vault or a breach record to.

What happens to an email I paste into Claude for McAfee to check?

It leaves Claude and is sent to McAfee's cloud endpoint for analysis. McAfee markets Scam Detector as running on-device wherever possible, but a remote MCP server is a network service by construction, so the connector path is the cloud path. McAfee publishes no retention period for connector submissions that we could reach.

How long does McAfee keep messages submitted through the connector?

McAfee does not say, in anything we could retrieve. Its Scam Detector privacy article sits behind the same edge block as the rest of its support site, so unlike Norton, which publishes a 30-day retention schedule for Genie submissions, McAfee's equivalent commitment is unverified here. Treat a submission as disclosed until McAfee states otherwise.

How many tools does the McAfee MCP server actually have?

Three, according to Anthropic's directory, and there is no second list to check it against. McAfee's blog post describes the connector reviewing texts, emails and URLs but names no tool, and its support article was unreachable from our network. The count is Anthropic's alone and we could not confirm it live.

Why does McAfee tell me to open manage connections and grant permissions?

So the connector can read the content you paste. McAfee's blog directs you to grant McAfee permission to review the texts, emails and URLs you upload to Claude. That is a broader instruction than approving one call, and the per-call confirmation is the only place you see what leaves your chat, so grant narrowly and keep the prompts.

Should I paste a suspicious email into Claude if it contains personal information?

Redact it first. A forwarded email carries its sender, recipients and routing headers, and all of it travels to McAfee's endpoint with the message body. Because McAfee publishes no reachable retention statement for connector submissions, you cannot bound how long that copy persists. Send the smallest excerpt that still shows the suspicious pattern.

Sources

Use it in an agent

Put McAfee to work.

Connect McAfee once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.

Call (650) 285-1019Our AI receptionist answers.