Mallory MCP Server (deprecated)
⚠️ This package is deprecated and no longer maintained.
The local
mallorymcpstdio server has been replaced by Mallory's hosted Remote MCP service. The remote service is fully managed, always up to date, and requires no local install.➡️ Migrate to the Remote MCP service: https://docs.mallory.ai/use/agent/mcp
What changed
mallorymcp was a local MCP server you ran via uvx/pip that proxied the
Mallory API to your AI client over stdio. It is no longer published with new
features and will receive no further updates.
All functionality now lives in the Mallory Remote MCP service, a hosted endpoint you connect your AI client to directly. It exposes the same threat intelligence capabilities (vulnerabilities, threat actors, malware, exploits, organizations, attack patterns, breaches, products, advisories, stories, mentions, search, and sources) without any local package to install or keep up to date.
How to migrate
Follow the setup guide for your AI client (Cursor, Claude Desktop, Claude Code, and others) here:
https://docs.mallory.ai/use/agent/mcp
Once you've connected the Remote MCP service, you can remove the local server from your MCP client config and uninstall this package:
pip uninstall mallorymcp
License
Apache 2.0.
Release files for mallorymcp 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mallorymcp-0.4.0.tar.gz | 6.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mallorymcp-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.3 kB
Release files / mallorymcp-0.4.0.tar.gz
| Download URL | mallorymcp-0.4.0.tar.gz |
|---|---|
| Size | 6.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
112eecaeca3d1ff702f598063887c5be2937149660f6a69754876dc96f68a1a3
|
|
BLAKE2b-256 checksum How to use checksums |
54047fbb8f5bb45b5668e5953ed83e5ef47a0d4742df62d8c56a0d4545a33f25
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.
Transparency logRelease files / mallorymcp-0.4.0-py3-none-any.whl
| Download URL | mallorymcp-0.4.0-py3-none-any.whl |
|---|---|
| Size | 7.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0a636a7338405010fa81f4e8030d7311337fde7c838e06f5a9b50dd23b98e6a9
|
|
BLAKE2b-256 checksum How to use checksums |
61d0a8d87ae0f76f4523aa8042ecc11215be2313f266509b5f31550662f4e01f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.
Transparency log