{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_5tva7kkn7b6r","handle":"malwagon","url":"https://wellknown.network/agents/malwagon","links":{"self":"https://wellknown.network/agents/malwagon/record.json","html":"https://wellknown.network/agents/malwagon","markdown":"https://wellknown.network/agents/malwagon/record.md","api":"https://wellknown.network/api/v1/agents/malwagon","status":"https://wellknown.network/api/v1/agents/malwagon/status","claim":"https://wellknown.network/agents/malwagon/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/malwagon/claim.json","badge":"https://wellknown.network/agents/malwagon/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/malwagon/history","tools":"https://wellknown.network/api/v1/agents/malwagon/tools"},"ard":{"identifier":"urn:air:malwagon.com:server:malwagon","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Malwagon","summary":"Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.","description":"Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.","publisher":{"name":"com.malwagon","url":null},"homepage":"https://malwagon.com","repository":null,"version":"1.1.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://malwagon.com/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-09-09T19:43:54.926394Z","publishedAt":"2026-09-09T19:43:54.926394Z","registryName":"com.malwagon/malwagon"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"analytics.reporting","name":"Reporting & Dashboards","confidence":0.885,"provenance":"derived"},{"slug":"dev.terminal","name":"Terminal & Shell","confidence":0.525,"provenance":"derived"},{"slug":"content.writing","name":"Writing & Editing","confidence":0.51,"provenance":"derived"},{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":0.51,"provenance":"derived"}],"categories":["analytics","content","dev"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 3h ago.","lastOkAt":"2026-10-10T18:26:21.956Z","lastProbedAt":"2026-10-10T18:26:21.956Z","statusComputedAt":"2026-10-10T18:28:54.462Z","reliability30d":{"probes":110,"successRate":0.9909,"p50Ms":199,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":107,"ok":106,"authBoundaryOk":0,"serviceOk":106,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-10T18:26:21.956Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":306,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T04:32:10.465Z","kind":"mcp_initialize","ok":false,"httpStatus":530,"latencyMs":10,"error":"http 530","detail":null},{"at":"2026-10-09T21:27:23.319Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":201,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T15:32:48.184Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":167,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T08:27:35.998Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":208,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T01:24:47.731Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":144,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T18:26:50.095Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":179,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T11:24:04.375Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":194,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T05:20:59.808Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":147,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-07T22:23:57.086Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":145,"error":null,"detail":{"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"toolCount":5,"toolsHash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","serverName":"Malwagon","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"lookup_hash","description":"Find analyses of a known SHA-256 digest. Returns the caller's own scans of those bytes plus any publicly shared scan of them. Sends nothing anywhere: this searc"},{"name":"get_report","description":"The derived analysis report for one scan: verdict, capabilities, behaviour summary, observed operations and defanged indicators. Derived data only - it never co"},{"name":"search_indicator","description":"Find scans where an indicator was observed: an IP, a domain, a URL, a mutex, a registry key, a hash or a JA3/JA4 fingerprint. The indicator is matched exactly; "},{"name":"poll_scan","description":"The current status of one scan, for polling after submit_scan. Cheap enough to call in a loop. 'terminal' means the scan will not change again; 'report_availabl"},{"name":"submit_scan","description":"Queue a new analysis of a target that can be named as text: a SHA-256 to look up, a URL to visit, a command to run, or a package to install. Uploading a file or"}],"package":null,"toolSurface":{"id":"ts_3zrx8ts58zpn","endpointId":"ep_47wgm2nkbudb","hash":"17493f246d2b2b9d49dba707f5ee6c723ce57b84100acfd850098e2488468bfc","toolCount":5,"serverName":"Malwagon","serverVersion":"1.0.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-09-12T14:26:10.644Z","lastSeenAt":"2026-10-10T18:26:21.955Z","observations":101,"toolNames":["lookup_hash","get_report","search_indicator","poll_scan","submit_scan"],"distinctSurfaces":1},"endpointFacts":[{"id":"ep_47wgm2nkbudb","url":"https://malwagon.com/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-10T18:26:21.960Z","auth":{"observedAt":"2026-10-10T18:26:22.079Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-10-10T18:26:22.097Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"malwagon.com","issuer":{"commonName":"WE1","organization":"Google Trust Services"},"validFrom":"2026-08-29T17:15:20.000Z","validTo":"2026-11-27T18:14:02.000Z","daysToExpiry":47,"sanCount":2,"fingerprint256":"1C:88:1C:F7:7B:C3:5F:23:D0:28:6E:26:BB:38:08:C5:7C:F3:1C:DC:54:A6:F2:41:7E:8F:DC:F5:A6:DD:CA:1D"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"com.malwagon/malwagon","url":"https://registry.modelcontextprotocol.io/v0/servers/com.malwagon%2Fmalwagon","firstSeenAt":"2026-09-07T16:22:29.776Z","fetchedAt":"2026-10-09T08:21:12.996Z","normalizedAt":"2026-10-09T08:21:12.996Z"}]},"firstSeenAt":"2026-09-07T16:22:29.776Z","updatedAt":"2026-10-10T18:29:32.857Z"}