You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OpenHands has no IsMalicious integration configuration in its current curated catalogue. Users manually configure the stdio command and matching API key/secret, and the catalogue cannot present those required secret fields.
Proposed change
Add integrations/catalog/ismalicious.json with npx -y @ismalicious/mcp-server@0.3.0, two required password fields, and the public setup documentation. Regenerate integrations/catalog-index.js using the existing build command. Version 0.3.0 was published on September 25 and clears the seven-day dependency rule; newer versions are deliberately not required.
This exposes optional IOC reputation, CVE and Gate tools. It does not install mandatory middleware or guarantee inspection of every agent input/result. An IsMalicious account and plan quotas apply.
Verified implementation
npm run build:integrations succeeded.
uv run pytest -q tests/test_catalog_schema.py tests/test_integration_catalog_in_sync.py: 106 passed.
Released OpenHands SDK 1.51.0 loaded the entry, launched the published npm 0.3.0 package through the catalogue's exact npx command, discovered seven tools, and invoked scan_before_use over stdio.
A loopback HTTP fixture verified the exact request content and both allow/block output preservation. No production credentials, LLM call or Cloud claim is involved.
The focused implementation and reproduction script are ready. Please triage the catalogue addition for ready-for-dev. A draft PR can then follow the repository template; its HUMAN section must be completed by the human author before review.
AI assistance was used for preparation and testing.
OpenHands AI triage
The following comments and acceptance criteria were added by the OpenHands AI agent.
Triage
This is a single-file curated-catalogue addition under integrations/catalog/, which AGENTS.md and integrations/README.md designate as the hand-authored source of truth; integrations/catalog-index.js is generated by npm run build:integrations. It matches the repository's established pattern for API-key stdio MCP servers (for example brave-search, firecrawl, kagi, mongodb): one catalog JSON with a kind: "stdio" connection option and required passwordenvFields.
Verified against upstream: @ismalicious/mcp-server@0.3.0 exists on npm (published 2026-09-25, which is more than seven days before 2026-10-03 and therefore clears the recency guard in skills/code-review/references/supply-chain-security.md). Its bin is ismalicious-mcp, it launches via npx -y @ismalicious/mcp-server@0.3.0, it reads exactly ISMALICIOUS_API_KEY and ISMALICIOUS_API_SECRET (plus optional ISMALICIOUS_API_BASE / ISMALICIOUS_TIMEOUT_MS), and it advertises the package's eight tools, including the seven named in the request. Because 0.3.0 differs from npm latest (0.6.0), pinning the exact version is what keeps the catalogue entry reproducible; pinning is uncommon in sibling entries and should be stated explicitly.
Non-goals: no SDK, agent-server, or Agent Canvas changes; no mandatory middleware or interception of every agent input/result; no production credentials, LLM calls, or Cloud claims; no upstream package changes.
Acceptance Criteria
integrations/catalog/ismalicious.json exists and validates against integrations/catalog.schema.json, with id matching the filename.
npm run build:integrations regenerates integrations/catalog-index.js with a static import of ./catalog/ismalicious.json, and re-running it on an unchanged tree produces no diff.
uv run pytest -q tests/test_catalog_schema.py tests/test_integration_catalog_in_sync.py passes, including test_js_reads_the_same_catalog_as_python.
The entry has exactly one provider: "mcp" / kind: "stdio" connection option with commandnpx, args["-y", "@ismalicious/mcp-server@0.3.0"], and a consistent serverName.
The transport declares exactly two required passwordenvFields, ISMALICIOUS_API_KEY and ISMALICIOUS_API_SECRET (exact names), each with non-empty helperText as the schema requires for password fields.
docsUrl is an https:// URL to IsMalicious setup documentation that actually documents ISMALICIOUS_API_KEY and ISMALICIOUS_API_SECRET, and the URL resolves.
name, description, categories (using a category value already present in the taxonomy), keywords, and serializable logo metadata (logoUrl / iconBg / iconColor) are present and accurate.
Connecting through the catalogue's exact command and env keys launches the published npm package and discovers its advertised tools (including scan_before_use, check_indicator, get_cve, recent_cves, check_indicators, and bootstrap_key), with scan_before_use invocable over stdio.
scan_before_use preserves both an observed allow and an observed block verdict, and provider failures surface as the documented error body with isError: true; no production credential is committed, logged, or printed.
The change touches only integrations/catalog/ismalicious.json and the generated integrations/catalog-index.js.
User-facing copy states that an IsMalicious account and plan quotas apply, and that the entry exposes optional IOC/CVE/Gate tools rather than guaranteeing inspection of every agent input/result.
Problem
OpenHands has no IsMalicious integration configuration in its current curated catalogue. Users manually configure the stdio command and matching API key/secret, and the catalogue cannot present those required secret fields.
Proposed change
Add
integrations/catalog/ismalicious.jsonwithnpx -y @ismalicious/mcp-server@0.3.0, two required password fields, and the public setup documentation. Regenerateintegrations/catalog-index.jsusing the existing build command. Version 0.3.0 was published on September 25 and clears the seven-day dependency rule; newer versions are deliberately not required.This exposes optional IOC reputation, CVE and Gate tools. It does not install mandatory middleware or guarantee inspection of every agent input/result. An IsMalicious account and plan quotas apply.
Verified implementation
npm run build:integrationssucceeded.uv run pytest -q tests/test_catalog_schema.py tests/test_integration_catalog_in_sync.py: 106 passed.scan_before_useover stdio.The focused implementation and reproduction script are ready. Please triage the catalogue addition for
ready-for-dev. A draft PR can then follow the repository template; its HUMAN section must be completed by the human author before review.AI assistance was used for preparation and testing.
OpenHands AI triage
The following comments and acceptance criteria were added by the OpenHands AI agent.
Triage
This is a single-file curated-catalogue addition under
integrations/catalog/, whichAGENTS.mdandintegrations/README.mddesignate as the hand-authored source of truth;integrations/catalog-index.jsis generated bynpm run build:integrations. It matches the repository's established pattern for API-key stdio MCP servers (for examplebrave-search,firecrawl,kagi,mongodb): one catalog JSON with akind: "stdio"connection option and requiredpasswordenvFields.Verified against upstream:
@ismalicious/mcp-server@0.3.0exists on npm (published 2026-09-25, which is more than seven days before 2026-10-03 and therefore clears the recency guard inskills/code-review/references/supply-chain-security.md). Itsbinisismalicious-mcp, it launches vianpx -y @ismalicious/mcp-server@0.3.0, it reads exactlyISMALICIOUS_API_KEYandISMALICIOUS_API_SECRET(plus optionalISMALICIOUS_API_BASE/ISMALICIOUS_TIMEOUT_MS), and it advertises the package's eight tools, including the seven named in the request. Because0.3.0differs from npmlatest(0.6.0), pinning the exact version is what keeps the catalogue entry reproducible; pinning is uncommon in sibling entries and should be stated explicitly.Non-goals: no SDK, agent-server, or Agent Canvas changes; no mandatory middleware or interception of every agent input/result; no production credentials, LLM calls, or Cloud claims; no upstream package changes.
Acceptance Criteria
integrations/catalog/ismalicious.jsonexists and validates againstintegrations/catalog.schema.json, withidmatching the filename.npm run build:integrationsregeneratesintegrations/catalog-index.jswith a static import of./catalog/ismalicious.json, and re-running it on an unchanged tree produces no diff.uv run pytest -q tests/test_catalog_schema.py tests/test_integration_catalog_in_sync.pypasses, includingtest_js_reads_the_same_catalog_as_python.provider: "mcp"/kind: "stdio"connection option withcommandnpx,args["-y", "@ismalicious/mcp-server@0.3.0"], and a consistentserverName.passwordenvFields,ISMALICIOUS_API_KEYandISMALICIOUS_API_SECRET(exact names), each with non-emptyhelperTextas the schema requires for password fields.docsUrlis anhttps://URL to IsMalicious setup documentation that actually documentsISMALICIOUS_API_KEYandISMALICIOUS_API_SECRET, and the URL resolves.name,description,categories(using a category value already present in the taxonomy),keywords, and serializable logo metadata (logoUrl/iconBg/iconColor) are present and accurate.scan_before_use,check_indicator,get_cve,recent_cves,check_indicators, andbootstrap_key), withscan_before_useinvocable over stdio.scan_before_usepreserves both an observed allow and an observed block verdict, and provider failures surface as the documented error body withisError: true; no production credential is committed, logged, or printed.integrations/catalog/ismalicious.jsonand the generatedintegrations/catalog-index.js.