# io.github.WYRE-AI/proofpoint-mcp

MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.1.5
- **Author:** io.github.WYRE-AI
- **License:** Unknown
- **Source:** https://github.com/WYRE-AI/proofpoint-mcp

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-25T01:27:16.655Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `proofpoint_dlp_list_incidents` — List DLP incidents. Returns messages that triggered DLP rules, including policy violations and sensitive data detections.
- `proofpoint_dlp_get_incident` — Get detailed information about a specific DLP incident, including matched rules, sensitive data types, and message metadata.
- `proofpoint_dlp_list_encrypted` — List messages that were encrypted by Proofpoint Email Encryption. Shows encrypted message status and recipient access.
- `proofpoint_events_list` — List spam, phishing, and malware detection events. Returns events where Proofpoint detected and acted on threats.
- `proofpoint_events_get_details` — Get detailed information about a specific detection event, including full threat analysis and message metadata.
- `proofpoint_events_get_stats` — Get detection event statistics. Returns counts of spam, phishing, malware, and impostor detections over a time period.
- `proofpoint_forensics_get_threat` — Get forensic evidence for a specific threat. Returns behavioral analysis, network activity, file modifications, and other forensic indicators.
- `proofpoint_forensics_get_campaign` — Get forensic evidence for all threats in a campaign. Returns aggregated behavioral analysis across all associated threats.
- `proofpoint_forensics_search_messages` — Search for messages across mailboxes for threat response. Used for search & destroy / auto-pull operations to find and remediate delivered threats.
- `proofpoint_forensics_pull_messages` — Auto-pull (search & destroy) messages from mailboxes. This is a destructive operation that removes delivered messages from user mailboxes.
- `proofpoint_people_get_vap` — Get the Very Attacked People (VAP) report. Returns users who received the most attacks, ranked by attack index. Useful for identifying high-risk users.
- `proofpoint_people_get_top_clickers` — Get top clickers report. Returns users who clicked on the most threat URLs, indicating users who may need additional security training.
- `proofpoint_people_get_user_risk` — Get the risk score and attack details for a specific user by email address.
- `proofpoint_policy_list` — List all email security policies. Returns policy names, types, and enabled status.
- `proofpoint_policy_get` — Get detailed information about a specific policy including rules, conditions, and actions.
- `proofpoint_policy_list_routes` — List email routing rules/routes. Shows how mail is routed based on policy configuration.
- `proofpoint_quarantine_list` — List quarantined messages. Returns messages held in quarantine with sender, recipient, subject, and reason.
- `proofpoint_quarantine_search` — Search quarantine by keyword across sender, recipient, and subject fields.
- `proofpoint_quarantine_release` — ⚠ HIGH-IMPACT. Release a quarantined message, delivering it to the intended recipient.
- `proofpoint_quarantine_delete` — ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently delete a quarantined message.
- `proofpoint_reports_org_summary` — Get organization security summary. Returns high-level metrics: total messages processed, threats blocked, quarantined, and delivered.
- `proofpoint_reports_threat_summary` — Get threat summary report. Breakdown of threats by type (spam, phishing, malware, impostor) with counts and trends.
- `proofpoint_reports_mail_flow` — Get mail flow report. Shows email volume over time with breakdown by disposition (delivered, blocked, quarantined).
- `proofpoint_reports_executive_summary` — Get executive summary report. High-level security posture overview suitable for management reporting. Includes threat trends, top targeted users, and effectiven
- `proofpoint_smart_search_trace` — Trace messages through the Proofpoint mail flow. Search by sender, recipient, subject, or message ID to track delivery status and processing history.
- `proofpoint_smart_search_get_message` — Get detailed information about a specific message including headers, processing log, and delivery details.
- `proofpoint_smart_search_get_headers` — Get the full email headers for a specific message.
- `proofpoint_tap_get_all_threats` — Get all threats (messages and clicks) from the TAP SIEM API for a given time window. Returns both delivered/blocked messages and permitted/blocked clicks.
- `proofpoint_tap_get_messages_delivered` — Get messages delivered containing threats. These are messages that reached the recipient's mailbox despite containing identified threats.
- `proofpoint_tap_get_messages_blocked` — Get messages blocked that contained threats. These are messages quarantined or rejected before reaching the recipient.
- `proofpoint_tap_get_clicks_permitted` — Get permitted clicks on threat URLs. These are clicks that were allowed through to the destination.
- `proofpoint_tap_get_clicks_blocked` — Get blocked clicks on threat URLs. These are clicks that were prevented from reaching the malicious destination.
- `proofpoint_threat_get_campaign` — Get details of a specific threat campaign by campaign ID. Returns campaign actors, malware families, techniques, and associated messages.
- `proofpoint_threat_get_by_id` — Get detailed information about a specific threat by its threat ID. Returns threat type, classification, and associated indicators.
- `proofpoint_threat_list_families` — List known threat families tracked by Proofpoint. Returns malware family names, descriptions, and associated campaigns.
- `proofpoint_threat_get_iocs` — Get indicators of compromise (IOCs) for a specific campaign or time range. Returns URLs, IPs, domains, file hashes associated with threats.
- `proofpoint_url_decode` — Decode one or more Proofpoint URL Defense rewritten URLs back to the original URLs. Proofpoint rewrites URLs in emails for click-time protection; this tool reve
- `proofpoint_url_analyze` — Analyze a URL for threats. Returns threat classification, risk score, and associated campaigns.
- `proofpoint_navigate` — Discover available Proofpoint tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/
- `proofpoint_status` — Show credentials status and available domains

## Install

This entry has no npm package and no hosted endpoint, so there is nothing for an MCP client to launch or connect to. It is indexed as source only.

## Blast radius

Extensive blast radius — deletes data; holds an api key.
- Floor 42, ceiling 54 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Fproofpoint-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.WYRE-AI%2Fproofpoint-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.WYRE-AI%2Fproofpoint-mcp
- HTML page: https://forgeregistry.com/registry/io.github.WYRE-AI%2Fproofpoint-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
