MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
PROOFPOINT_SERVICE_SECRETAPI keyrequiredProofpoint TAP service secret
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
proofpoint_dlp_list_incidentsList DLP incidents. Returns messages that triggered DLP rules, including policy violations and sensitive data detections.List DLP incidents. Returns messages that triggered DLP rules, including policy violations and sensitive data detections.
No input schema was published for this tool.
proofpoint_dlp_get_incidentGet detailed information about a specific DLP incident, including matched rules, sensitive data types, and message metadata.Get detailed information about a specific DLP incident, including matched rules, sensitive data types, and message metadata.
No input schema was published for this tool.
proofpoint_dlp_list_encryptedList messages that were encrypted by Proofpoint Email Encryption. Shows encrypted message status and recipient access.List messages that were encrypted by Proofpoint Email Encryption. Shows encrypted message status and recipient access.
No input schema was published for this tool.
proofpoint_events_listList spam, phishing, and malware detection events. Returns events where Proofpoint detected and acted on threats.List spam, phishing, and malware detection events. Returns events where Proofpoint detected and acted on threats.
No input schema was published for this tool.
proofpoint_events_get_detailsGet detailed information about a specific detection event, including full threat analysis and message metadata.Get detailed information about a specific detection event, including full threat analysis and message metadata.
No input schema was published for this tool.
proofpoint_events_get_statsGet detection event statistics. Returns counts of spam, phishing, malware, and impostor detections over a time period.Get detection event statistics. Returns counts of spam, phishing, malware, and impostor detections over a time period.
No input schema was published for this tool.
proofpoint_forensics_get_threatGet forensic evidence for a specific threat. Returns behavioral analysis, network activity, file modifications, and other forensic indicators.Get forensic evidence for a specific threat. Returns behavioral analysis, network activity, file modifications, and other forensic indicators.
No input schema was published for this tool.
proofpoint_forensics_get_campaignGet forensic evidence for all threats in a campaign. Returns aggregated behavioral analysis across all associated threats.Get forensic evidence for all threats in a campaign. Returns aggregated behavioral analysis across all associated threats.
No input schema was published for this tool.
proofpoint_forensics_search_messagesSearch for messages across mailboxes for threat response. Used for search & destroy / auto-pull operations to find and remediate delivered threats.Search for messages across mailboxes for threat response. Used for search & destroy / auto-pull operations to find and remediate delivered threats.
No input schema was published for this tool.
proofpoint_forensics_pull_messagesAuto-pull (search & destroy) messages from mailboxes. This is a destructive operation that removes delivered messages from user mailboxes.Auto-pull (search & destroy) messages from mailboxes. This is a destructive operation that removes delivered messages from user mailboxes.
No input schema was published for this tool.
proofpoint_people_get_vapGet the Very Attacked People (VAP) report. Returns users who received the most attacks, ranked by attack index. Useful for identifying high-risk users.Get the Very Attacked People (VAP) report. Returns users who received the most attacks, ranked by attack index. Useful for identifying high-risk users.
No input schema was published for this tool.
proofpoint_people_get_top_clickersGet top clickers report. Returns users who clicked on the most threat URLs, indicating users who may need additional security training.Get top clickers report. Returns users who clicked on the most threat URLs, indicating users who may need additional security training.
No input schema was published for this tool.
proofpoint_people_get_user_riskGet the risk score and attack details for a specific user by email address.Get the risk score and attack details for a specific user by email address.
No input schema was published for this tool.
proofpoint_policy_listList all email security policies. Returns policy names, types, and enabled status.List all email security policies. Returns policy names, types, and enabled status.
No input schema was published for this tool.
proofpoint_policy_getGet detailed information about a specific policy including rules, conditions, and actions.Get detailed information about a specific policy including rules, conditions, and actions.
No input schema was published for this tool.
proofpoint_policy_list_routesList email routing rules/routes. Shows how mail is routed based on policy configuration.List email routing rules/routes. Shows how mail is routed based on policy configuration.
No input schema was published for this tool.
proofpoint_quarantine_listList quarantined messages. Returns messages held in quarantine with sender, recipient, subject, and reason.List quarantined messages. Returns messages held in quarantine with sender, recipient, subject, and reason.
No input schema was published for this tool.
proofpoint_quarantine_searchSearch quarantine by keyword across sender, recipient, and subject fields.Search quarantine by keyword across sender, recipient, and subject fields.
No input schema was published for this tool.
proofpoint_quarantine_release⚠ HIGH-IMPACT. Release a quarantined message, delivering it to the intended recipient.⚠ HIGH-IMPACT. Release a quarantined message, delivering it to the intended recipient.
No input schema was published for this tool.
proofpoint_quarantine_deleteprivileged⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a quarantined message.⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a quarantined message.
No input schema was published for this tool.
proofpoint_reports_org_summaryGet organization security summary. Returns high-level metrics: total messages processed, threats blocked, quarantined, and delivered.Get organization security summary. Returns high-level metrics: total messages processed, threats blocked, quarantined, and delivered.
No input schema was published for this tool.
proofpoint_reports_threat_summaryGet threat summary report. Breakdown of threats by type (spam, phishing, malware, impostor) with counts and trends.Get threat summary report. Breakdown of threats by type (spam, phishing, malware, impostor) with counts and trends.
No input schema was published for this tool.
proofpoint_reports_mail_flowGet mail flow report. Shows email volume over time with breakdown by disposition (delivered, blocked, quarantined).Get mail flow report. Shows email volume over time with breakdown by disposition (delivered, blocked, quarantined).
No input schema was published for this tool.
proofpoint_reports_executive_summaryGet executive summary report. High-level security posture overview suitable for management reporting. Includes threat trends, top targeted users, and effectiveness metrics.Get executive summary report. High-level security posture overview suitable for management reporting. Includes threat trends, top targeted users, and effectiveness metrics.
No input schema was published for this tool.
proofpoint_smart_search_traceTrace messages through the Proofpoint mail flow. Search by sender, recipient, subject, or message ID to track delivery status and processing history.Trace messages through the Proofpoint mail flow. Search by sender, recipient, subject, or message ID to track delivery status and processing history.
No input schema was published for this tool.
proofpoint_smart_search_get_messageGet detailed information about a specific message including headers, processing log, and delivery details.Get detailed information about a specific message including headers, processing log, and delivery details.
No input schema was published for this tool.
proofpoint_smart_search_get_headersGet the full email headers for a specific message.Get the full email headers for a specific message.
No input schema was published for this tool.
proofpoint_tap_get_all_threatsGet all threats (messages and clicks) from the TAP SIEM API for a given time window. Returns both delivered/blocked messages and permitted/blocked clicks.Get all threats (messages and clicks) from the TAP SIEM API for a given time window. Returns both delivered/blocked messages and permitted/blocked clicks.
No input schema was published for this tool.
proofpoint_tap_get_messages_deliveredGet messages delivered containing threats. These are messages that reached the recipient's mailbox despite containing identified threats.Get messages delivered containing threats. These are messages that reached the recipient's mailbox despite containing identified threats.
No input schema was published for this tool.
proofpoint_tap_get_messages_blockedGet messages blocked that contained threats. These are messages quarantined or rejected before reaching the recipient.Get messages blocked that contained threats. These are messages quarantined or rejected before reaching the recipient.
No input schema was published for this tool.
proofpoint_tap_get_clicks_permittedGet permitted clicks on threat URLs. These are clicks that were allowed through to the destination.Get permitted clicks on threat URLs. These are clicks that were allowed through to the destination.
No input schema was published for this tool.
proofpoint_tap_get_clicks_blockedGet blocked clicks on threat URLs. These are clicks that were prevented from reaching the malicious destination.Get blocked clicks on threat URLs. These are clicks that were prevented from reaching the malicious destination.
No input schema was published for this tool.
proofpoint_threat_get_campaignGet details of a specific threat campaign by campaign ID. Returns campaign actors, malware families, techniques, and associated messages.Get details of a specific threat campaign by campaign ID. Returns campaign actors, malware families, techniques, and associated messages.
No input schema was published for this tool.
proofpoint_threat_get_by_idGet detailed information about a specific threat by its threat ID. Returns threat type, classification, and associated indicators.Get detailed information about a specific threat by its threat ID. Returns threat type, classification, and associated indicators.
No input schema was published for this tool.
proofpoint_threat_list_familiesList known threat families tracked by Proofpoint. Returns malware family names, descriptions, and associated campaigns.List known threat families tracked by Proofpoint. Returns malware family names, descriptions, and associated campaigns.
No input schema was published for this tool.
proofpoint_threat_get_iocsGet indicators of compromise (IOCs) for a specific campaign or time range. Returns URLs, IPs, domains, file hashes associated with threats.Get indicators of compromise (IOCs) for a specific campaign or time range. Returns URLs, IPs, domains, file hashes associated with threats.
No input schema was published for this tool.
proofpoint_url_decodeDecode one or more Proofpoint URL Defense rewritten URLs back to the original URLs. Proofpoint rewrites URLs in emails for click-time protection; this tool reverses that encoding.Decode one or more Proofpoint URL Defense rewritten URLs back to the original URLs. Proofpoint rewrites URLs in emails for click-time protection; this tool reverses that encoding.
No input schema was published for this tool.
proofpoint_url_analyzeAnalyze a URL for threats. Returns threat classification, risk score, and associated campaigns.Analyze a URL for threats. Returns threat classification, risk score, and associated campaigns.
No input schema was published for this tool.
proofpoint_navigateDiscover available Proofpoint tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/discovery aid, not a prerequisite.Discover available Proofpoint tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/discovery aid, not a prerequisite.
No input schema was published for this tool.
proofpoint_statusShow credentials status and available domainsShow credentials status and available domains
No input schema was published for this tool.
40 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.