McAfee MCP server icon

McAfee

by McAfee

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity3 tools

Check suspicious emails, texts and links for scams from inside an AI chat, backed by McAfee's Scam Detector. Anthropic lists 3 tools; McAfee publishes no tool list. No McAfee subscription required, and no tool changes any protection setting.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect McAfee via MCP

https://claudecompanion.gateway.api.mcafee.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

McAfee Tools & Capabilities (3)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • McAfee's entire web estate was unreachable from our network. The nominated support article, the blog post, llms.txt, llms-full.txt, robots.txt and the sitemap each returned 403 from Akamai to every client we tried, including a browser user agent and a text-extraction service. Everything attributed to McAfee below and above comes from search-engine extracts of its pages, not from pages we read ourselves. That is a materially weaker source than a direct fetch, and it is why we record the documentation as unavailable despite it existing.
  • The support article is a Salesforce Experience Cloud page with no public mirror. We probed mcafee.my.site.com, mcafee.force.com and mcafee.secure.force.com for the same article number; all three resolved and returned 404. Unlike other Salesforce-hosted vendor docs in this catalogue, no alternate hostname serves this content, and the Aura endpoint that would carry the article's JSON is behind the same 403.
  • McAfee publishes no tool list for this server. The three names come from Anthropic's directory. We could not diff them against a vendor enumeration in either direction, and no screenshot, exclusion table or negative enumeration was reachable either.
  • We could not verify the endpoint's behaviour at all. Every path on claudecompanion.gateway.api.mcafee.com, including a nonsense control path, returned the same 403 from an AWS load balancer. We read no tool schemas, no safety annotations and no RFC 9728 metadata, and the "no subscription required" claim is McAfee's, not our observation.
  • No retention or model-training statement for connector submissions could be retrieved. This is the single largest gap on this page, and it is the one place where a directly comparable connector does better: Norton publishes its schedule, McAfee's equivalent is behind the block.
  • The on-device marketing claim does not describe this connector. McAfee promotes Scam Detector as analysing content on-device where possible. A remote MCP server sends content to a network endpoint by definition. Do not carry the app's privacy posture across to the connector.
  • A verdict is an assessment, not a guarantee. Scam detection is probabilistic, and a "safe" result should lower your suspicion rather than end it. We found no McAfee statement about how it handles an inconclusive case on this connector.
  • No rate limits are published. We found no statement from McAfee about request limits, quotas or throttling on this connector, and could not test for them.
  • We found no pricing or metering of any kind. Nothing in the surface spends money or credits, and McAfee states the integration does not require a subscription. No tool in the listing could observe a spend if one existed.
  • Support runs through a dedicated mailbox, not the general queue. The directory lists claudeapp-support@mcafee.com for this connector specifically.

Frequently asked questions

No. All three tools Anthropic lists begin with check, and none carries a verb that sets, enables, disables, installs or configures anything. McAfee describes the connector as analysis that explains a risk and advises what to do next. There is no McAfee sign-in, so the server has no account or device to apply a setting to.

No. McAfee's blog states the Claude and McAfee integration is available to anyone and that you do not have to be a McAfee subscriber, and that it works on the free Claude plan. Anthropic's directory records the endpoint as authless with no OAuth flow, so no consent screen scopes the connector's access.

No tool in the listing reaches either. McAfee's password manager, identity monitoring and personal data cleanup are separate subscription products bound to a McAfee account, and this connector requires no account at all. With no sign-in there is no identity for the server to attach a vault or a breach record to.

It leaves Claude and is sent to McAfee's cloud endpoint for analysis. McAfee markets Scam Detector as running on-device wherever possible, but a remote MCP server is a network service by construction, so the connector path is the cloud path. McAfee publishes no retention period for connector submissions that we could reach.

McAfee does not say, in anything we could retrieve. Its Scam Detector privacy article sits behind the same edge block as the rest of its support site, so unlike Norton, which publishes a 30-day retention schedule for Genie submissions, McAfee's equivalent commitment is unverified here. Treat a submission as disclosed until McAfee states otherwise.

Three, according to Anthropic's directory, and there is no second list to check it against. McAfee's blog post describes the connector reviewing texts, emails and URLs but names no tool, and its support article was unreachable from our network. The count is Anthropic's alone and we could not confirm it live.

So the connector can read the content you paste. McAfee's blog directs you to grant McAfee permission to review the texts, emails and URLs you upload to Claude. That is a broader instruction than approving one call, and the per-call confirmation is the only place you see what leaves your chat, so grant narrowly and keep the prompts.

Redact it first. A forwarded email carries its sender, recipients and routing headers, and all of it travels to McAfee's endpoint with the message body. Because McAfee publishes no reachable retention statement for connector submissions, you cannot bound how long that copy persists. Send the smallest excerpt that still shows the suspicious pattern.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
McAfee
Tools
3
Domain
claudecompanion.gateway.api.mcafee.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.