Skip to content

Add IsMalicious threat-intelligence MCP catalogue entry #721

Description

@hexablob

Problem

OpenHands has no IsMalicious integration configuration in its current curated catalogue. Users manually configure the stdio command and matching API key/secret, and the catalogue cannot present those required secret fields.

Proposed change

Add integrations/catalog/ismalicious.json with npx -y @ismalicious/mcp-server@0.3.0, two required password fields, and the public setup documentation. Regenerate integrations/catalog-index.js using the existing build command. Version 0.3.0 was published on September 25 and clears the seven-day dependency rule; newer versions are deliberately not required.

This exposes optional IOC reputation, CVE and Gate tools. It does not install mandatory middleware or guarantee inspection of every agent input/result. An IsMalicious account and plan quotas apply.

Verified implementation

  • npm run build:integrations succeeded.
  • uv run pytest -q tests/test_catalog_schema.py tests/test_integration_catalog_in_sync.py: 106 passed.
  • Released OpenHands SDK 1.51.0 loaded the entry, launched the published npm 0.3.0 package through the catalogue's exact npx command, discovered seven tools, and invoked scan_before_use over stdio.
  • A loopback HTTP fixture verified the exact request content and both allow/block output preservation. No production credentials, LLM call or Cloud claim is involved.

The focused implementation and reproduction script are ready. Please triage the catalogue addition for ready-for-dev. A draft PR can then follow the repository template; its HUMAN section must be completed by the human author before review.

AI assistance was used for preparation and testing.


OpenHands AI triage

The following comments and acceptance criteria were added by the OpenHands AI agent.

Triage

This is a single-file curated-catalogue addition under integrations/catalog/, which AGENTS.md and integrations/README.md designate as the hand-authored source of truth; integrations/catalog-index.js is generated by npm run build:integrations. It matches the repository's established pattern for API-key stdio MCP servers (for example brave-search, firecrawl, kagi, mongodb): one catalog JSON with a kind: "stdio" connection option and required password envFields.

Verified against upstream: @ismalicious/mcp-server@0.3.0 exists on npm (published 2026-09-25, which is more than seven days before 2026-10-03 and therefore clears the recency guard in skills/code-review/references/supply-chain-security.md). Its bin is ismalicious-mcp, it launches via npx -y @ismalicious/mcp-server@0.3.0, it reads exactly ISMALICIOUS_API_KEY and ISMALICIOUS_API_SECRET (plus optional ISMALICIOUS_API_BASE / ISMALICIOUS_TIMEOUT_MS), and it advertises the package's eight tools, including the seven named in the request. Because 0.3.0 differs from npm latest (0.6.0), pinning the exact version is what keeps the catalogue entry reproducible; pinning is uncommon in sibling entries and should be stated explicitly.

Non-goals: no SDK, agent-server, or Agent Canvas changes; no mandatory middleware or interception of every agent input/result; no production credentials, LLM calls, or Cloud claims; no upstream package changes.

Acceptance Criteria

  • integrations/catalog/ismalicious.json exists and validates against integrations/catalog.schema.json, with id matching the filename.
  • npm run build:integrations regenerates integrations/catalog-index.js with a static import of ./catalog/ismalicious.json, and re-running it on an unchanged tree produces no diff.
  • uv run pytest -q tests/test_catalog_schema.py tests/test_integration_catalog_in_sync.py passes, including test_js_reads_the_same_catalog_as_python.
  • The entry has exactly one provider: "mcp" / kind: "stdio" connection option with command npx, args ["-y", "@ismalicious/mcp-server@0.3.0"], and a consistent serverName.
  • The transport declares exactly two required password envFields, ISMALICIOUS_API_KEY and ISMALICIOUS_API_SECRET (exact names), each with non-empty helperText as the schema requires for password fields.
  • docsUrl is an https:// URL to IsMalicious setup documentation that actually documents ISMALICIOUS_API_KEY and ISMALICIOUS_API_SECRET, and the URL resolves.
  • name, description, categories (using a category value already present in the taxonomy), keywords, and serializable logo metadata (logoUrl / iconBg / iconColor) are present and accurate.
  • Connecting through the catalogue's exact command and env keys launches the published npm package and discovers its advertised tools (including scan_before_use, check_indicator, get_cve, recent_cves, check_indicators, and bootstrap_key), with scan_before_use invocable over stdio.
  • scan_before_use preserves both an observed allow and an observed block verdict, and provider failures surface as the documented error body with isError: true; no production credential is committed, logged, or printed.
  • The change touches only integrations/catalog/ismalicious.json and the generated integrations/catalog-index.js.
  • User-facing copy states that an IsMalicious account and plan quotas apply, and that the entry exposes optional IOC/CVE/Gate tools rather than guaranteeing inspection of every agent input/result.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:lowready-for-devScoped for contribution; managed by repository readiness checks.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions