proofpoint-mcp
Health Warn
- License — License: Apache-2.0
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Fail
- exec() — Shell command execution in scripts/lint-destructive-warnings.mjs
- process.env — Environment variable access in src/__tests__/client-url.test.ts
- process.env — Environment variable access in src/__tests__/gateway-credentials.test.ts
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
MCP server for Proofpoint TAP and Essentials APIs — threat intelligence, email tracing, and MSP org management
Proofpoint MCP Server
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.
Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
Installation
npm install @wyre-ai/proofpoint-mcp
Configuration
Set the following environment variables:
| Variable | Required | Description |
|---|---|---|
PROOFPOINT_SERVICE_PRINCIPAL |
Yes | Your Proofpoint TAP service principal |
PROOFPOINT_SERVICE_SECRET |
Yes | Your Proofpoint TAP service secret |
PROOFPOINT_BASE_URL |
No | Custom base URL (default: tap-api-v2.proofpoint.com) |
MCP_TRANSPORT |
No | Transport mode: stdio (default) or http |
Usage
Running with Claude Desktop
Add to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"proofpoint-mcp": {
"command": "npx",
"args": ["@wyre-ai/proofpoint-mcp"],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "your-proofpoint-service-principal"
"PROOFPOINT_SERVICE_SECRET": "your-proofpoint-service-secret"
}
}
}
}
Running with Claude Code (CLI)
claude mcp add proofpoint-mcp \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-- npx -y @wyre-ai/proofpoint-mcp
Docker
docker build -t proofpoint-mcp .
docker run \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-p 8080:8080 proofpoint-mcp
Features
Interactive Threat Card (MCP Apps)
proofpoint_threat_get_by_id renders as an interactive, read-only card in
MCP Apps hosts (Claude Desktop/web) showing the threat name, status,
category, severity, and resolved actor / malware-family / campaign names;
plain-JSON behavior is unchanged in other hosts. The card is neutral by
default and brandable via window.__BRAND__ injection or MCP_BRAND_* env
vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR,MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild
needed.
Available Domains
Dlp
Data loss prevention policies
Events
Security event stream and SIEM export
Forensics
Forensic analysis of threats
People
Very Attacked People (VAP) reporting
Policy
Email policy management
Quarantine
Email quarantine management
Reports
Security reports and summaries
Smart Search
Advanced email search
Tap
Targeted Attack Protection events and campaigns
Threat Intel
Threat intelligence and indicators of compromise
Url Defense
URL rewriting and click defense
Development
# Clone the repository
git clone https://github.com/WYRE-AI/proofpoint-mcp.git
cd proofpoint-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
Contributing
Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.
License
Licensed under the Apache License, Version 2.0. See LICENSE for details.
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found