Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Proofpoint

OCI · GHCR.IO/WYRE-TECHNOLOGY/PROOFPOINT-MCP:V1.1.4 · SCANNED AUG 22

MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

+5 this week 46 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security0
  • Malware scan not yet available for this package.Unverified
  • Known CVEs could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.Unverified
  • Install-script risk not yet assessed.Unverified
  • Dependency health could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.Unverified
Provenance & Transparency45
Schema Quality & AI Usability87
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 3401 tokens (~82/item across 41 items; 40 tools + 1 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management30
  • Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
  • Supports UI / widget rendering.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

oci · ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4

# add to Claude Code
claude mcp add wyre-technology-proofpoint-mcp -- docker run --rm -i ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4
# add to Codex CLI
codex mcp add wyre-technology-proofpoint-mcp -- docker run --rm -i ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "wyre-technology-proofpoint-mcp": {
      "type": "local",
      "command": [
        "docker",
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
      ],
      "enabled": true
    }
  }
}
# ~/.hermes/config.yaml
mcp_servers:
  wyre-technology-proofpoint-mcp:
    command: "docker"
    args: ["run", "--rm", "-i", "ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"]
// mcp.json
{
  "mcpServers": {
    "wyre-technology-proofpoint-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 22 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Aug 26 +4
    • Stability: unverified → 0.23 functional
  • 13 Aug 26 41

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 22 Aug 2026 · Analysed oci/ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem oci
Reason No attestation published
MCP tools · 40 exposed · ~3,382 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
proofpoint_dlp_get_incident ~48

Get detailed information about a specific DLP incident, including matched rules, sensitive data types, and message metadata.

NameTypeReqDescription
incident_idstringyesThe DLP incident ID

No output schema declared.

No examples provided.

proofpoint_dlp_list_encrypted ~118

List messages that were encrypted by Proofpoint Email Encryption. Shows encrypted message status and recipient access.

NameTypeReqDescription
endDatestringEnd date in ISO 8601 format
pagenumberPage number (default: 1)
per_pagenumberResults per page (default: 50)
recipientstringFilter by recipient email address
senderstringFilter by sender email address
startDatestringStart date in ISO 8601 format

No output schema declared.

No examples provided.

proofpoint_dlp_list_incidents ~119

List DLP incidents. Returns messages that triggered DLP rules, including policy violations and sensitive data detections.

NameTypeReqDescription
endDatestringEnd date in ISO 8601 format
pagenumberPage number (default: 1)
per_pagenumberResults per page (default: 50)
severitystringFilter by severity level
startDatestringStart date in ISO 8601 format
statusstringFilter by incident status

No output schema declared.

No examples provided.

proofpoint_events_get_details ~42

Get detailed information about a specific detection event, including full threat analysis and message metadata.

NameTypeReqDescription
event_idstringyesThe event ID to look up

No output schema declared.

No examples provided.

proofpoint_events_get_stats ~91

Get detection event statistics. Returns counts of spam, phishing, malware, and impostor detections over a time period.

NameTypeReqDescription
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceSecondsnumberNumber of seconds ago (max 3600)
sinceTimestringISO 8601 date/time to get stats since

No output schema declared.

No examples provided.

proofpoint_events_list ~119

List spam, phishing, and malware detection events. Returns events where Proofpoint detected and acted on threats.

NameTypeReqDescription
dispositionstringFilter by disposition (what happened to the message)
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceSecondsnumberNumber of seconds ago to fetch events from (max 3600)
sinceTimestringISO 8601 date/time to fetch events since
threatTypestringFilter by threat type

No output schema declared.

No examples provided.

proofpoint_forensics_get_campaign ~47

Get forensic evidence for all threats in a campaign. Returns aggregated behavioral analysis across all associated threats.

NameTypeReqDescription
campaign_idstringyesThe campaign ID to get forensics for

No output schema declared.

No examples provided.

proofpoint_forensics_get_threat ~73

Get forensic evidence for a specific threat. Returns behavioral analysis, network activity, file modifications, and other forensic indicators.

NameTypeReqDescription
includeCampaignForensicsbooleanInclude forensics for the entire campaign (default: false)
threat_idstringyesThe threat ID to get forensics for

No output schema declared.

No examples provided.

proofpoint_forensics_pull_messages ~71

Auto-pull (search & destroy) messages from mailboxes. This is a destructive operation that removes delivered messages from user mailboxes.

NameTypeReqDescription
message_idsarrayyesArray of message IDs to pull from mailboxes
reasonstringReason for pulling messages (for audit trail)

No output schema declared.

No examples provided.

proofpoint_forensics_search_messages ~129

Search for messages across mailboxes for threat response. Used for search & destroy / auto-pull operations to find and remediate delivered threats.

NameTypeReqDescription
endDatestringEnd date in ISO 8601 format
message_idstringInternet message ID to search for
senderstringSender email address to search for
startDatestringStart date in ISO 8601 format
subjectstringSubject line to search for (partial match)
threat_idstringThreat ID associated with messages to find

No output schema declared.

No examples provided.

proofpoint_navigate ~259

Discover available Proofpoint tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/discovery aid, not a prerequisite.

NameTypeReqDescription
domainstringyesThe domain to explore: - tap: Targeted Attack Protection (TAP) - SIEM API for threats, clicks, messages, and attack intelligence - quarantine: Quarantine management - list, release, delete, and searc…

No output schema declared.

No examples provided.

proofpoint_people_get_top_clickers ~94

Get top clickers report. Returns users who clicked on the most threat URLs, indicating users who may need additional security training.

NameTypeReqDescription
pagenumberPage number (default: 1)
sizenumberResults per page (default: 1000)
windownumberTime window in days: 14, 30, or 90 (default: 30)

No output schema declared.

No examples provided.

proofpoint_people_get_user_risk ~57

Get the risk score and attack details for a specific user by email address.

NameTypeReqDescription
emailstringyesUser email address to look up
windownumberTime window in days (default: 30)

No output schema declared.

No examples provided.

proofpoint_people_get_vap ~100

Get the Very Attacked People (VAP) report. Returns users who received the most attacks, ranked by attack index. Useful for identifying high-risk users.

NameTypeReqDescription
pagenumberPage number (default: 1)
sizenumberResults per page (default: 1000)
windownumberTime window in days: 14, 30, or 90 (default: 30)

No output schema declared.

No examples provided.

proofpoint_policy_get ~38

Get detailed information about a specific policy including rules, conditions, and actions.

NameTypeReqDescription
policy_idstringyesThe policy ID to retrieve

No output schema declared.

No examples provided.

proofpoint_policy_list ~37

List all email security policies. Returns policy names, types, and enabled status.

NameTypeReqDescription
typestringFilter by policy direction

No output schema declared.

No examples provided.

proofpoint_policy_list_routes ~57

List email routing rules/routes. Shows how mail is routed based on policy configuration.

NameTypeReqDescription
pagenumberPage number (default: 1)
per_pagenumberResults per page (default: 50)

No output schema declared.

No examples provided.

proofpoint_quarantine_delete ~66

⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a quarantined message. This action cannot be undone and will remove the message from quarantine storage. Confirm with the user before invoking.

NameTypeReqDescription
message_idstringyesThe quarantined message ID to delete

No output schema declared.

No examples provided.

proofpoint_quarantine_list ~147

List quarantined messages. Returns messages held in quarantine with sender, recipient, subject, and reason.

NameTypeReqDescription
endDatestringEnd date in ISO 8601 format
folderstringFilter by quarantine folder/reason
pagenumberPage number for pagination (default: 1)
per_pagenumberNumber of results per page (default: 50)
recipientstringFilter by recipient email address
senderstringFilter by sender email address
startDatestringStart date in ISO 8601 format
subjectstringFilter by subject (partial match)

No output schema declared.

No examples provided.

proofpoint_quarantine_release ~70

⚠ HIGH-IMPACT. Release a quarantined message, delivering it to the intended recipient. Irreversible delivery but message itself is preserved. Can deliver malicious mail to user. Confirm with the user before invoking.

NameTypeReqDescription
message_idstringyesThe quarantined message ID to release

No output schema declared.

No examples provided.

proofpoint_quarantine_search ~104

Search quarantine by keyword across sender, recipient, and subject fields.

NameTypeReqDescription
endDatestringEnd date in ISO 8601 format
pagenumberPage number (default: 1)
per_pagenumberResults per page (default: 50)
querystringyesSearch keyword to find in sender, recipient, or subject
startDatestringStart date in ISO 8601 format

No output schema declared.

No examples provided.

proofpoint_reports_executive_summary ~56

Get executive summary report. High-level security posture overview suitable for management reporting. Includes threat trends, top targeted users, and effectiveness metrics.

NameTypeReqDescription
windownumberTime window in days (default: 30)

No output schema declared.

No examples provided.

proofpoint_reports_mail_flow ~66

Get mail flow report. Shows email volume over time with breakdown by disposition (delivered, blocked, quarantined).

NameTypeReqDescription
granularitystringData point granularity (default: daily)
windownumberTime window in days (default: 7)

No output schema declared.

No examples provided.

proofpoint_reports_org_summary ~50

Get organization security summary. Returns high-level metrics: total messages processed, threats blocked, quarantined, and delivered.

NameTypeReqDescription
windownumberTime window in days (default: 30)

No output schema declared.

No examples provided.

proofpoint_reports_threat_summary ~71

Get threat summary report. Breakdown of threats by type (spam, phishing, malware, impostor) with counts and trends.

NameTypeReqDescription
threatTypestringFocus on a specific threat type (default: all)
windownumberTime window in days (default: 30)

No output schema declared.

No examples provided.

proofpoint_smart_search_get_headers ~37

Get the full email headers for a specific message.

NameTypeReqDescription
message_idstringyesThe Proofpoint internal message ID

No output schema declared.

No examples provided.

proofpoint_smart_search_get_message ~44

Get detailed information about a specific message including headers, processing log, and delivery details.

NameTypeReqDescription
message_idstringyesThe Proofpoint internal message ID

No output schema declared.

No examples provided.

proofpoint_smart_search_trace ~173

Trace messages through the Proofpoint mail flow. Search by sender, recipient, subject, or message ID to track delivery status and processing history.

NameTypeReqDescription
endDatestringEnd date in ISO 8601 format
message_idstringInternet Message-ID header to search for
pagenumberPage number (default: 1)
per_pagenumberResults per page (default: 50)
recipientstringRecipient email address to search for
senderstringSender email address to search for
startDatestringStart date in ISO 8601 format
statusstringFilter by delivery status (default: all)
subjectstringSubject line to search for (partial match)

No output schema declared.

No examples provided.

proofpoint_status ~16

Show credentials status and available domains

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

proofpoint_tap_get_all_threats ~173

Get all threats (messages and clicks) from the TAP SIEM API for a given time window. Returns both delivered/blocked messages and permitted/blocked clicks.

NameTypeReqDescription
formatstringResponse format (default: json)
intervalstringPredefined time interval: "PT30M" (30 min) or "PT1H" (1 hour). Mutually exclusive with sinceSeconds/sinceTime.
sinceSecondsnumberNumber of seconds ago to fetch threats from (max 3600). Mutually exclusive with sinceTime/interval.
sinceTimestringISO 8601 date/time to fetch threats since. Mutually exclusive with sinceSeconds/interval.
threatStatusstringFilter by threat status (default: active)

No output schema declared.

No examples provided.

proofpoint_tap_get_clicks_blocked ~101

Get blocked clicks on threat URLs. These are clicks that were prevented from reaching the malicious destination.

NameTypeReqDescription
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceSecondsnumberNumber of seconds ago (max 3600)
sinceTimestringISO 8601 date/time to fetch since
threatStatusstringFilter by threat status

No output schema declared.

No examples provided.

proofpoint_tap_get_clicks_permitted ~100

Get permitted clicks on threat URLs. These are clicks that were allowed through to the destination.

NameTypeReqDescription
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceSecondsnumberNumber of seconds ago (max 3600)
sinceTimestringISO 8601 date/time to fetch since
threatStatusstringFilter by threat status

No output schema declared.

No examples provided.

proofpoint_tap_get_messages_blocked ~100

Get messages blocked that contained threats. These are messages quarantined or rejected before reaching the recipient.

NameTypeReqDescription
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceSecondsnumberNumber of seconds ago (max 3600)
sinceTimestringISO 8601 date/time to fetch since
threatStatusstringFilter by threat status

No output schema declared.

No examples provided.

proofpoint_tap_get_messages_delivered ~101

Get messages delivered containing threats. These are messages that reached the recipient's mailbox despite containing identified threats.

NameTypeReqDescription
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceSecondsnumberNumber of seconds ago (max 3600)
sinceTimestringISO 8601 date/time to fetch since
threatStatusstringFilter by threat status

No output schema declared.

No examples provided.

proofpoint_threat_get_by_id ~55

Get detailed information about a specific threat by its threat ID. Returns threat type, classification, and associated indicators.

NameTypeReqDescription
threat_idstringyesThe threat ID (SHA256 hash or Proofpoint threat ID)

No output schema declared.

No examples provided.

proofpoint_threat_get_campaign ~50

Get details of a specific threat campaign by campaign ID. Returns campaign actors, malware families, techniques, and associated messages.

NameTypeReqDescription
campaign_idstringyesThe campaign ID to look up

No output schema declared.

No examples provided.

proofpoint_threat_get_iocs ~110

Get indicators of compromise (IOCs) for a specific campaign or time range. Returns URLs, IPs, domains, file hashes associated with threats.

NameTypeReqDescription
campaign_idstringCampaign ID to get IOCs for
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceTimestringISO 8601 date/time to fetch IOCs since
threat_typestringFilter by threat type

No output schema declared.

No examples provided.

proofpoint_threat_list_families ~74

List known threat families tracked by Proofpoint. Returns malware family names, descriptions, and associated campaigns.

NameTypeReqDescription
intervalstringPredefined interval: "PT30M" or "PT1H"
sinceTimestringISO 8601 date/time to list families active since

No output schema declared.

No examples provided.

proofpoint_url_analyze ~40

Analyze a URL for threats. Returns threat classification, risk score, and associated campaigns.

NameTypeReqDescription
urlstringyesURL to analyze for threats

No output schema declared.

No examples provided.

proofpoint_url_decode ~79

Decode one or more Proofpoint URL Defense rewritten URLs back to the original URLs. Proofpoint rewrites URLs in emails for click-time protection; this tool reverses that encoding.

NameTypeReqDescription
urlsarrayyesArray of Proofpoint-encoded URLs to decode (e.g., https://urldefense.proofpoint.com/v2/url?...)

No output schema declared.

No examples provided.