# io.github.WYRE-AI/avanan-legacy-mcp

MCP server for the legacy Avanan SmartAPI: MSP tenant management plus per-tenant security tools.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 2.3.0
- **Author:** io.github.WYRE-AI
- **License:** Unknown
- **Source:** https://github.com/WYRE-AI/avanan-legacy-mcp

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-25T01:27:15.572Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

33 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `avanan_quarantine_events` — HIGH IMPACT: quarantine the emails behind one or more security events. Reversible with avanan_restore_events. Returns task IDs. Confirm with the user before inv
- `avanan_restore_events` — Restore previously quarantined emails behind one or more security events. Returns task IDs.
- `avanan_quarantine_emails` — HIGH IMPACT: quarantine specific secured entities (emails) by entity ID. Reversible with avanan_restore_emails. Returns task IDs. Confirm with the user before i
- `avanan_restore_emails` — Restore specific quarantined entities (emails) by entity ID. Returns task IDs.
- `avanan_get_task_status` — Check the state of a quarantine/restore task by the task ID an action returned.
- `avanan_test_connection` — Verify the configured Avanan credentials: performs the auth handshake, lists the key's scopes, and probes an MSP endpoint to confirm the key is MSP-scoped. Run 
- `avanan_list_scopes` — List the farm:tenant scopes this key can query. A customer-tenant key has one; an MSP key has one per managed customer, usable as `scopes` / `scope` on the even
- `avanan_query_events` — Query Avanan security events (phishing, malware, DLP, anomaly, shadow IT, malicious URL). Filter by type, state, severity, SaaS, date range, or description text
- `avanan_get_event` — Get full details of one security event by its Avanan event ID.
- `avanan_list_exceptions` — List whitelist or blacklist exception entries.
- `avanan_get_exception` — Get one whitelist or blacklist entry by its entity ID.
- `avanan_add_exception` — Add a whitelist or blacklist entry. Provide at least one match field (senderEmail, senderDomain, senderName, recipient, subject, attachmentMd5, linkDomains, sen
- `avanan_update_exception` — Update an existing whitelist or blacklist entry by its entity ID.
- `avanan_delete_exception` — DESTRUCTIVE and irreversible: delete a whitelist or blacklist entry by its entity ID. Confirm with the user before invoking.
- `avanan_list_licenses` — List all available license packages (id, codeName, displayName). Use the codeName when assigning a license to a tenant.
- `avanan_list_addons` — List all available license add-ons (id, name). Add-on IDs are used when assigning a license to a tenant.
- `avanan_assign_license` — Assign a license (and optional add-ons) to an existing customer tenant.
- `avanan_list_msp_partners` — List all associated child MSP partners under the current MSP. Returns id and name for each child MSP.
- `avanan_create_msp_partner` — Create a new child MSP partner under the current MSP (msppartners-extended endpoint, July 2026 guide).
- `avanan_delete_msp_partner` — Delete a child MSP partner by ID. WARNING: all tenants associated with this MSP are also deleted.
- `avanan_search_emails` — Search secured entities (emails and SaaS objects) by platform and date range, with optional attribute filters (fromEmail, subject, recipients, isQuarantined, at
- `avanan_get_email` — Get full details of one secured entity (email, file, message) by its Avanan entity ID.
- `avanan_list_tenants` — List all customer tenants associated with the current MSP. Each tenant entry includes domain, deployment mode, user counts, status, license package and add-ons.
- `avanan_get_tenant` — Get details of a single customer tenant by ID, including license, PoC/paid dates, user count, and expiration.
- `avanan_create_tenant` — Create a new customer tenant under the current MSP.
- `avanan_delete_tenant` — Delete a customer tenant by ID. WARNING: this deletes the tenant and all its data.
- `avanan_get_monthly_usage` — Get monthly usage details across all customer tenants for a given year/month. Returns per-day, per-tenant rows with user count, daily price, and cost.
- `avanan_get_daily_usage` — Get daily usage details across all customer tenants for a specific year/month/day.
- `avanan_list_msp_users` — List all MSP users.
- `avanan_get_msp_user` — Get a single MSP user by ID.
- `avanan_create_msp_user` — Create a new MSP user.
- `avanan_update_msp_user` — Update an MSP user by ID. All fields are required per the SmartAPI spec.
- `avanan_delete_msp_user` — Delete an MSP user by ID.

## Install

This entry has no npm package and no hosted endpoint, so there is nothing for an MCP client to launch or connect to. It is indexed as source only.

## Blast radius

Extensive to critical — no package coordinates and no declared endpoint — Forge cannot tell where this would run or whose authority it would borrow. Known so far: deletes data; holds an oauth grant.
- Floor 52, ceiling 64 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Favanan-legacy-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Favanan-legacy-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.WYRE-AI%2Favanan-legacy-mcp
- HTML page: https://forgeregistry.com/registry/io.github.WYRE-AI%2Favanan-legacy-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
