Enterprise DNA Enterprise DNA
M MCP Servers Developer low

nagameTW/mcp-server-malcolm

by Various

MCP server for Malcolm: full read surface plus opt-in, audited write tools

MCP

nagameTW/mcp-server-malcolm

Added 3 Sept 2026

#ai-agent #arkime #claude #malcolm #mcp #model-context-protocol #netbox #network-security

Overview

An MCP server that exposes Malcolm's full read surface to AI tools and assistants. It includes opt-in write tools that are audited, meaning write operations are disabled unless explicitly enabled and logged.

Best for

Best for
Developers prototyping MCP-based assistants that need read and audited write access to Malcolm.

Use cases

  • Connect an AI assistant to query Malcolm data through MCP
  • Enable audited write operations for controlled automation
  • Build custom tooling that reads Malcolm's full data surface

How to use

Install

uvx --from /path/to/mcp-server-malcolm mcp-server-malcolm

Tools exposed

  • MALCOLM_URL
  • MALCOLM_USERNAME
  • MALCOLM_PASSWORD
  • MALCOLM_SSL_VERIFY
  • MALCOLM_TIMEOUT
  • MALCOLM_MAX_CONCURRENCY
  • MALCOLM_MAX_REQUESTS_PER_MINUTE
  • search_dsl
  • list_indices
  • index_mapping
  • cluster_health
  • malcolm_search
  • malcolm_aggregate
  • malcolm_alerts
  • malcolm_field_search
  • malcolm_field_values
  • malcolm_field_profile
  • arkime_field_search
  • malcolm_service_status
  • malcolm_data_coverage

Tested with

Claude Desktop, Claude Code, Cursor

Notes

An MCP server that exposes Malcolm’s full read surface to AI tools and assistants. It includes opt-in write tools that are audited, meaning write operations are disabled unless explicitly enabled and logged.

3 stars on GitHub. Last updated 2026-09-01. Licensed MIT.

Use cases

  • Connect an AI assistant to query Malcolm data through MCP
  • Enable audited write operations for controlled automation
  • Build custom tooling that reads Malcolm’s full data surface

Pros

  • Full read coverage of Malcolm’s data
  • Write tools are opt-in and audited for safer automation
  • Simple Python implementation fits standard MCP workflows

Cons

  • Very early stage with only 3 GitHub stars
  • Writes require explicit opt-in configuration
  • Limited community adoption and proven production use

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Full read coverage of Malcolm's data
  • Write tools are opt-in and audited for safer automation
  • Simple Python implementation fits standard MCP workflows

Cons

  • Very early stage with only 3 GitHub stars
  • Writes require explicit opt-in configuration
  • Limited community adoption and proven production use

Pairs with

Other entries in the index that connect to this one. Click through to see the chain.

Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks