Abnormal Security MCP

The full Abnormal Security REST API in your terminal and your agents - with a local threat store, ranked SOC triage, blocking remediation, and one-shot client reporting.

People who work with Abnormal and want it reachable from Claude, Cursor, VS Code, or another MCP client. The project is written in Go.

One of 67 MCP servers published from servosity/msp-skills. Stars and repository activity are shared across all of them. See all 67 →

VERIFIED ACTIVE

LAST COMMIT 2026-09-16 · VERIFIED 2026-09-18

NOASSERTION · Go servers · how we verify → /methodology

01 · Install Abnormal Security MCP

before you install - you'll need

Set ABNORMAL_API_TOKEN before connecting.

Claude Desktop

Settings → Extensions → Install, then select the https://github.com/Servosity/msp-skills/releases/download/abnormal-v0.1.3/abnormal-mcp.mcpb .mcpb bundle

02 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as Claude Desktop extension (.mcpb bundle)

license no standard license detected - usage rights unclear; check the repo before commercial use

registry namespace io.github.Servosity is GitHub-verified and matches the repo owner

03 · What Abnormal Security MCP can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

datagate-v0.1.0 · 2026-09-14

Added · Initial DataGate connector: read-only (list/get/search) coverage of customers, · customer users, agreements, service items, assignments, rate cards, sites, · product templates, kit templates, invoices…

riverside-fm-v0.1.0 · 2026-09-14

Added · Initial msp-skills release: Riverside CLI + MCP server for exporting your own · Riverside.com account. · bulk export - archive a whole studio's transcripts, assets, and HLS manifests · to disk with a resume…

acronis-v0.1.4 · 2026-09-11

Fixed · Resolve the API client's tenant subtree for default sync and search; sync agents, · per-tenant usages, and offering items as well as the existing resources. · Follow Acronis nested cursors, including short…

04 · Who maintains Abnormal Security MCP

Abnormal Security MCP is maintained by servosity. We track 67 MCP servers from servosity - 67 actively maintained, 40 combined GitHub stars, oldest repo from May 2026. Full record: all servers from servosity.

  1. Acronis MCP The first real CLI for the Acronis Cyber Protect Cloud platform - every tenant, agent, and usage ★ 40
  2. Action1 MCP Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations. ★ 40
  3. Afi MCP The first CLI for Afi SaaS backup - full public-API coverage plus the fleet-wide coverage ★ 40
  4. AppDirect MCP AppDirect marketplace operations with an offline mirror and cross-company billing reconciliation. ★ 40
  5. Atera MCP Every Atera RMM + PSA endpoint, plus a local SQLite mirror that answers fleet-health, SLA, and ★ 40
  6. Autotask MCP Every Autotask entity at the command line, plus a local SQLite mirror that answers ticket-aging ★ 40

05 · Facts

category
email - actively maintained as of 2026-09-18.
registry
io.github.Servosity/abnormal-mcp (active, first published 2026-06-07 · 4 versions)
packages
mcpb:https://github.com/Servosity/msp-skills/releases/download/abnormal-v0.1.3/abnormal-mcp.mcpb

06 · Abnormal Security MCP FAQ

What is Abnormal Security MCP?

The full Abnormal Security REST API in your terminal and your agents - with a local threat store, ranked SOC triage, blocking remediation, and one-shot client reporting.

Is Abnormal Security MCP still maintained?

Yes - as of 2026-09-18, its last commit was 2026-09-16. We re-verify nightly.

07 · Alternatives to Abnormal Security MCP