io.github.WYRE-AI/avanan-legacy-mcp

MCPcommunity
v2.3.0io.github.WYRE-AIUnknownUpdated 16d agoGitHub

MCP server for the legacy Avanan SmartAPI: MSP tenant management plus per-tenant security tools.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
16d agoLast update
Needs 1 credential before it runs
  • AVANAN_CLIENT_SECRETOAuth apprequired

    MSP API Client Secret used to sign every request (x-av-sig); never sent on the wire

  • CONDUIT_S2S_SECRETAPI keyoptional

    Conduit gateway S2S subkey; when set, /mcp requires a valid X-Gateway-S2S header (HTTP transport only)

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorio.github.WYRE-AI
LicenseUnknown
Version2.3.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: run `forge publish` from the repo to claim ownership
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface33 tools · 4 privileged
Security scan✓ CleanvHEAD · 1d agoHow well does this scan work?
EvalsNone
IndexedAug 27, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

33 tools · 4 privileged
Statically extracted from the published packagevHEAD · 1d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

avanan_quarantine_eventsHIGH IMPACT: quarantine the emails behind one or more security events. Reversible with avanan_restore_events. Returns task IDs. Confirm with the user before invoking.

HIGH IMPACT: quarantine the emails behind one or more security events. Reversible with avanan_restore_events. Returns task IDs. Confirm with the user before invoking.

No input schema was published for this tool.

avanan_restore_eventsRestore previously quarantined emails behind one or more security events. Returns task IDs.

Restore previously quarantined emails behind one or more security events. Returns task IDs.

No input schema was published for this tool.

avanan_quarantine_emailsHIGH IMPACT: quarantine specific secured entities (emails) by entity ID. Reversible with avanan_restore_emails. Returns task IDs. Confirm with the user before invoking.

HIGH IMPACT: quarantine specific secured entities (emails) by entity ID. Reversible with avanan_restore_emails. Returns task IDs. Confirm with the user before invoking.

No input schema was published for this tool.

avanan_restore_emailsRestore specific quarantined entities (emails) by entity ID. Returns task IDs.

Restore specific quarantined entities (emails) by entity ID. Returns task IDs.

No input schema was published for this tool.

avanan_get_task_statusCheck the state of a quarantine/restore task by the task ID an action returned.

Check the state of a quarantine/restore task by the task ID an action returned.

No input schema was published for this tool.

avanan_test_connectionVerify the configured Avanan credentials: performs the auth handshake, lists the key's scopes, and probes an MSP endpoint to confirm the key is MSP-scoped. Run this first when MSP tools return 403.

Verify the configured Avanan credentials: performs the auth handshake, lists the key's scopes, and probes an MSP endpoint to confirm the key is MSP-scoped. Run this first when MSP tools return 403.

No input schema was published for this tool.

avanan_list_scopesList the farm:tenant scopes this key can query. A customer-tenant key has one; an MSP key has one per managed customer, usable as `scopes` / `scope` on the event, search and action tools.

List the farm:tenant scopes this key can query. A customer-tenant key has one; an MSP key has one per managed customer, usable as `scopes` / `scope` on the event, search and action tools.

No input schema was published for this tool.

avanan_query_eventsQuery Avanan security events (phishing, malware, DLP, anomaly, shadow IT, malicious URL). Filter by type, state, severity, SaaS, date range, or description text. Returns each event's available remediation actions.

Query Avanan security events (phishing, malware, DLP, anomaly, shadow IT, malicious URL). Filter by type, state, severity, SaaS, date range, or description text. Returns each event's available remediation actions.

No input schema was published for this tool.

avanan_get_eventGet full details of one security event by its Avanan event ID.

Get full details of one security event by its Avanan event ID.

No input schema was published for this tool.

avanan_list_exceptionsList whitelist or blacklist exception entries.

List whitelist or blacklist exception entries.

No input schema was published for this tool.

avanan_get_exceptionGet one whitelist or blacklist entry by its entity ID.

Get one whitelist or blacklist entry by its entity ID.

No input schema was published for this tool.

avanan_add_exceptionAdd a whitelist or blacklist entry. Provide at least one match field (senderEmail, senderDomain, senderName, recipient, subject, attachmentMd5, linkDomains, senderIp).

Add a whitelist or blacklist entry. Provide at least one match field (senderEmail, senderDomain, senderName, recipient, subject, attachmentMd5, linkDomains, senderIp).

No input schema was published for this tool.

avanan_update_exceptionUpdate an existing whitelist or blacklist entry by its entity ID.

Update an existing whitelist or blacklist entry by its entity ID.

No input schema was published for this tool.

avanan_delete_exceptionprivilegedDESTRUCTIVE and irreversible: delete a whitelist or blacklist entry by its entity ID. Confirm with the user before invoking.

DESTRUCTIVE and irreversible: delete a whitelist or blacklist entry by its entity ID. Confirm with the user before invoking.

No input schema was published for this tool.

avanan_list_licensesList all available license packages (id, codeName, displayName). Use the codeName when assigning a license to a tenant.

List all available license packages (id, codeName, displayName). Use the codeName when assigning a license to a tenant.

No input schema was published for this tool.

avanan_list_addonsList all available license add-ons (id, name). Add-on IDs are used when assigning a license to a tenant.

List all available license add-ons (id, name). Add-on IDs are used when assigning a license to a tenant.

No input schema was published for this tool.

avanan_assign_licenseAssign a license (and optional add-ons) to an existing customer tenant.

Assign a license (and optional add-ons) to an existing customer tenant.

No input schema was published for this tool.

avanan_list_msp_partnersList all associated child MSP partners under the current MSP. Returns id and name for each child MSP.

List all associated child MSP partners under the current MSP. Returns id and name for each child MSP.

No input schema was published for this tool.

avanan_create_msp_partnerCreate a new child MSP partner under the current MSP (msppartners-extended endpoint, July 2026 guide).

Create a new child MSP partner under the current MSP (msppartners-extended endpoint, July 2026 guide).

No input schema was published for this tool.

avanan_delete_msp_partnerprivilegedDelete a child MSP partner by ID. WARNING: all tenants associated with this MSP are also deleted.

Delete a child MSP partner by ID. WARNING: all tenants associated with this MSP are also deleted.

No input schema was published for this tool.

avanan_search_emailsSearch secured entities (emails and SaaS objects) by platform and date range, with optional attribute filters (fromEmail, subject, recipients, isQuarantined, attachmentMd5, ...).

Search secured entities (emails and SaaS objects) by platform and date range, with optional attribute filters (fromEmail, subject, recipients, isQuarantined, attachmentMd5, ...).

No input schema was published for this tool.

avanan_get_emailGet full details of one secured entity (email, file, message) by its Avanan entity ID.

Get full details of one secured entity (email, file, message) by its Avanan entity ID.

No input schema was published for this tool.

avanan_list_tenantsList all customer tenants associated with the current MSP. Each tenant entry includes domain, deployment mode, user counts, status, license package and add-ons.

List all customer tenants associated with the current MSP. Each tenant entry includes domain, deployment mode, user counts, status, license package and add-ons.

No input schema was published for this tool.

avanan_get_tenantGet details of a single customer tenant by ID, including license, PoC/paid dates, user count, and expiration.

Get details of a single customer tenant by ID, including license, PoC/paid dates, user count, and expiration.

No input schema was published for this tool.

avanan_create_tenantCreate a new customer tenant under the current MSP.

Create a new customer tenant under the current MSP.

No input schema was published for this tool.

avanan_delete_tenantprivilegedDelete a customer tenant by ID. WARNING: this deletes the tenant and all its data.

Delete a customer tenant by ID. WARNING: this deletes the tenant and all its data.

No input schema was published for this tool.

avanan_get_monthly_usageGet monthly usage details across all customer tenants for a given year/month. Returns per-day, per-tenant rows with user count, daily price, and cost.

Get monthly usage details across all customer tenants for a given year/month. Returns per-day, per-tenant rows with user count, daily price, and cost.

No input schema was published for this tool.

avanan_get_daily_usageGet daily usage details across all customer tenants for a specific year/month/day.

Get daily usage details across all customer tenants for a specific year/month/day.

No input schema was published for this tool.

avanan_list_msp_usersList all MSP users.

List all MSP users.

No input schema was published for this tool.

avanan_get_msp_userGet a single MSP user by ID.

Get a single MSP user by ID.

No input schema was published for this tool.

avanan_create_msp_userCreate a new MSP user.

Create a new MSP user.

No input schema was published for this tool.

avanan_update_msp_userUpdate an MSP user by ID. All fields are required per the SmartAPI spec.

Update an MSP user by ID. All fields are required per the SmartAPI spec.

No input schema was published for this tool.

avanan_delete_msp_userprivilegedDelete an MSP user by ID.

Delete an MSP user by ID.

No input schema was published for this tool.

33 of 33 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

MCP server for the legacy Avanan SmartAPI: MSP tenant management plus per-tenant security tools.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.