# Abnormal MCP Server (io.github.GregDog/mcp-server-abnormal@1.0.1)

> Source: <https://mcpindex.ai/server/io-github-gregdog-mcp-server-abnormal>
> Published: 2026-09-10 13:50:55+00:00

[← Index](/leaderboard)

# Abnormal MCP Server

Abnormal Security MCP: threats, search, remediation, ATO cases, vendor/BEC, and evidence download.

The current version, v1.0.1, was published to the official MCP registry on 2026-09-10. It is distributed as the Docker image ghcr.io/gregdog/mcp-server-abnormal:v1.0.1, filed under Search by this index, and declares 5 environment variables. Removals and unreachable sources are measured across every server this index tracks, contract drift across the servers that answer in consecutive snapshots; [the index's current counts](/stats) put this record in context.

## Using Abnormal MCP Server in Claude, Cursor, Gemini CLI, Cline, or Zed?

MCP tool contracts can change remotely with no version bump. The mcpindex gate pins each contract and **HOLDs the call** when it drifts-before your agent acts. Zero credentials. This is not the package install for this server itself (use **Install this server** for that).

Rewrites your MCP host config so each server launches behind the gate. Inspect first: curl -fsSL https://mcpindex.ai/install.sh | less

```
uv tool install mcpindex-gate && mcpindex-config-wire
```

[method](/methodology)

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: [the eval, four-state verdict, honest limits](/methodology).

Own this server? [Screen its description →](/screen)

## That verdict was true at screening time (snapshot 2026-09-10).

Contracts can change after screening, with no version bump. The gate pins Abnormal MCP Server’s tool contracts on first sight and holds any silent change before your agent acts - the check that keeps being true on Tuesday.

[See your first HOLD in 2 minutes →](/guides/install-the-gate-first-hold)

Related: [how to trust an MCP server](/guides/how-to-trust-an-mcp-server) · [screen before install](/guides/screen-mcp-server-before-install) · [silent contract drift](/guides/mcp-silent-contract-drift)

`ABNORMAL_API_TOKEN`
Abnormal REST API bearer token

`ABNORMAL_BASE_URL`
Abnormal API base URL

`ABNORMAL_ALLOW_RESPONSE`
Enable response MCP tools (remediation)

`ABNORMAL_ALLOW_EVIDENCE_DOWNLOAD`
Enable evidence download MCP tools (EML and attachments)

`ABNORMAL_MAX_EVIDENCE_BYTES`
Max bytes per evidence download from Abnormal

[methodology](/methodology)

[YTDL RMCPai.dinglebear/rytdl](/server/ai-dinglebear-rytdl)

yt-dlp search, download, metadata, delivery, and Plex workflows over MCP and CLI.

[Fodda Topic & Trend Researchai.fodda/topic-research](/server/ai-fodda-topic-research)

Trend, stats & insight search across PSFK expert graphs with citable sources.

[AniList MCP Serverio.github.Grinv/anilist-mcp-server](/server/io-github-grinv-anilist-mcp-server)

MCP server for the AniList GraphQL API — anime/manga search, details, and personal list management.
