Skip to content

Tools

Agents reach analysis tools in three ways, and each is configuration rather than code:

  • A static provider — the reverse-engineering tool the static analyst attaches: Ghidra, radare2, capa and YARA, an MCP server of your own, or nothing (core.static.provider).
  • A sandbox provider — where samples are detonated, or which uploaded report stands in (core.sandbox.provider).
  • Tool servers (MCP) — the built-in sidecars, VirusTotal's own server, and any server an operator adds, each with the tools it exposes and the agents that may call it (core.mcp.servers).

Every call an agent makes, whichever way it went, is written to the evidence ledger with a citable id.

  • Ghidra


    The decompiler, as an MCP server in its own container. A team that needs it waits for it.

    Ghidra

  • radare2


    r2mcp over stdio, degrading cleanly when it is not installed.

    radare2

  • capa and YARA


    Deterministic capability and rule matches, as a provider, as tools and in the triage pack.

    capa and YARA

  • Sandboxes


    CAPEv2, Hatching Triage, an uploaded report, any REST sandbox, or the mock.

    Sandboxes

  • VirusTotal


    VirusTotal's own MCP server, registered with an agent token.

    VirusTotal

  • Analysis and knowledge sidecars


    The built-in tool servers: file analysis, ATT&CK knowledge, capture views and reputation.

    Sidecars

  • Generic MCP servers


    Any MCP server, attached to the agents you choose, with the tools you tick.

    Generic MCP servers

Static providers at a glance

core.static.provider What it attaches When it is missing
ghidra (the shipped value) The Ghidra MCP server's tools; core.static.ghidra.enabled is off by default Does not degrade: a job whose team needs it is refused at submit
r2 r2mcp's tools Degrades: the run goes on and names what was missing
capa_yara No tools: two deterministic passes whose results are written to the ledger Degrades
generic_mcp The tools of the core.mcp.servers entry named by core.static.generic.server Degrades
none Nothing —

A job can choose its own provider with static_provider, a team can force one on every member, and an agent definition can name its own. Which agents open a provider, and what happens when one fails, is in Providers.

Every tool says what it cannot do

Each built-in sidecar answers capabilities: which of its tools need an optional library, a binary or a setting, and which of those are present on its host. The console's server card names the unavailable tools before a run, a tool marked unavailable is kept out of the list the model is given, and a tool that cannot answer returns an error with a code and a remedy rather than raising. See Built-in tool servers.

The measurement baseline

The measurement team withholds every tool server and forces the static provider to none, so the same sample can be run with and without tools. See Teams and profiles.