npm · @ismalicious/mcp-server
$npx -y @ismalicious/mcp-server@0.5.0 ISMALICIOUS_API_KEY · secret — API key from https://ismalicious.com/app/account. Optional: without it the server starts in bootstrap mode and offers bootstrap_key.
ISMALICIOUS_API_SECRET · secret — API secret paired with the key
ISMALICIOUS_API_BASE — API base URL (defaults to https://ismalicious.com/api; https://api.ismalicious.com reaches the API host directly)
ISMALICIOUS_TIMEOUT_MS — Replaces every tool's timeout, in milliseconds (defaults: gate 15000, check_indicator 25000, CVE 10000, search_indicators 20000, check_indicators 60000, check_password_exposure 10000). ISMALICIOUS_TIMEOUT_<TOOL>_MS, e.g. ISMALICIOUS_TIMEOUT_CHECK_INDICATOR_MS, sets one tool's timeout and wins over it
ISMALICIOUS_WEB_BASE — Base URL for bootstrap_key, a route only https://ismalicious.com/api serves (defaults to ISMALICIOUS_API_BASE, or https://ismalicious.com/api when that is api.ismalicious.com)
ISMALICIOUS_CACHE_TTL_S — Result cache: 0 turns it off; N caps every tool's cache lifetime at N seconds (never raises one)
ISMALICIOUS_PREWARM — 0 (or false, off, no) skips the one unauthenticated GET /health sent after initialize to open the connection