# Virustotal

```json
{
  "name": "Virustotal",
  "slug": "virustotal",
  "url": "https://composio.dev/toolkits/virustotal",
  "markdown_url": "https://composio.dev/toolkits/virustotal.md",
  "logo_url": "https://logos.composio.dev/api/virustotal",
  "categories": [
    "data & analytics"
  ],
  "is_composio_managed": false,
  "updated_at": "2026-05-12T10:29:51.341Z"
}
```

![Virustotal logo](https://logos.composio.dev/api/virustotal)

## Description

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with Virustotal MCP or direct API to scan files or URLs, retrieve threat reports, analyze suspicious indicators, and automate security workflows through natural language.

## Summary

Virustotal is a malware analysis service that checks files and URLs against dozens of antivirus engines. It helps individuals and organizations quickly detect and investigate potential threats.

## Categories

- data & analytics

## Toolkit Details

- Tools: 16

## Images

- Logo: https://logos.composio.dev/api/virustotal

## Authentication

- **Api Key**
  - Type: `api_key`
  - Description: Api Key authentication for Virustotal.
  - Setup:
    - Configure Api Key credentials for Virustotal.
    - Use the credentials when creating an auth config in Composio.

## Suggested Prompts

- Scan this file hash for malware
- Get analysis report for suspicious URL
- Retrieve domain reputation details
- Check comments on this IP address

## Supported Tools

| Tool slug | Name | Description |
|---|---|---|
| `VIRUSTOTAL_ADD_COMMENT` | Add VirusTotal Comment | Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use after analyzing a resource to leave contextual feedback. Provide exactly one identifier per call. |
| `VIRUSTOTAL_ADD_VOTE` | Add Vote | Tool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing analysis results to submit your verdict. |
| `VIRUSTOTAL_GET_ANALYSIS` | Get Analysis Report | Tool to retrieve the analysis report of a file or URL submission. Use after obtaining an analysis ID to fetch its detailed report. Analysis results may be incomplete immediately after submission; poll until the report status is 'completed' before treating results as final. |
| `VIRUSTOTAL_GET_COMMENTS` | Get comments | Tool to retrieve the latest comments on a VirusTotal resource. Use when you need to review user-generated comments for a file, URL, domain, or IP after obtaining its identifier. |
| `VIRUSTOTAL_GET_DOMAIN_RELATIONSHIPS` | Get Domain Relationships | Tool to retrieve relationship objects for a given domain. Use when you have a domain and need to explore its related entities. |
| `VIRUSTOTAL_GET_DOMAIN_REPORT` | Get Domain Report | Tool to retrieve the analysis report of a domain. Use when you need detailed insight on a domain's reputation and analysis stats. No malicious signals on obscure or low-traffic domains may indicate limited analysis history rather than safety — treat sparse results as 'unknown', not 'safe'. Covers external OSINT only (reputation, malware, SSL posture); cannot analyze internal/private assets. |
| `VIRUSTOTAL_GET_FILE_REPORT` | Get File Report | Tool to retrieve the analysis report of a file. Use when you have a file's hash and need detailed scan metadata. Recently submitted files may return partial results; retry after a short delay before treating the report as final. |
| `VIRUSTOTAL_GET_IP_ADDRESS_RELATIONSHIPS` | Get IP Address Relationships | Tool to retrieve objects related to a specific IP address by relationship type. Use when you have an IP and need to explore connected files, URLs, or other entities. |
| `VIRUSTOTAL_GET_IP_ADDRESS_REPORT` | Get IP Address Report | Tool to retrieve the analysis report of an IP address. Use when you need detailed insight on an IP's reputation, ASN, country, and analysis stats. Low or zero detections indicate unknown risk, not safety — treat sparse data accordingly. Provides external OSINT only; insufficient as standalone compliance evidence. |
| `VIRUSTOTAL_GET_METADATA` | Get VirusTotal Metadata | Tool to retrieve VirusTotal metadata. Use when you need information about available privileges, relationships between resources (like files, domains, IPs, URLs), and supported antivirus engines. |
| `VIRUSTOTAL_GET_URL_REPORT` | Get URL Report | Tool to retrieve the analysis report of a URL. Use when you have a URL identifier (base64-url without padding) and need detailed scan results, reputation, and metadata. Results may be incomplete immediately after submission; retry with short delays if scan engines are still processing before treating the report as final. |
| `VIRUSTOTAL_GET_VOTES` | Get Votes | Tool to retrieve votes on files, URLs, domains, or IP addresses. Use when you need to view community votes for a given object. |
| `VIRUSTOTAL_RESCAN_FILE` | Rescan File | Tool to re-analyze a previously submitted file. Use when you need updated analysis results after an initial scan. |
| `VIRUSTOTAL_SCAN_URL` | Scan URL | Tool to submit a URL for scanning. Use when you have a URL and need to submit it to VirusTotal to obtain an analysis ID for later retrieval. The returned analysis ID is preliminary — scanning engines may not have finished. Poll VIRUSTOTAL_GET_URL_REPORT with the ID using short delays to retrieve complete results. |
| `VIRUSTOTAL_SEARCH` | Search VirusTotal | Tool to search for objects in the VirusTotal database. Use when locating files, URLs, domains, IPs, or comments matching a query. Supports pagination with limit and cursor. |
| `VIRUSTOTAL_UPLOAD_FILE` | Upload File | Tool to upload a file for scanning. Use when you have binary file content ready to submit for VirusTotal analysis. |

## Supported Triggers

None listed.

## Installation and MCP Setup

### Path 1: SDK Installation

#### Path 1, Step 1: Install Composio

Install the Composio SDK
```python
pip install composio_openai
```

```typescript
npm install @composio/openai
```

#### Path 1, Step 2: Initialize Composio and Create Tool Router Session

Import and initialize Composio client, then create a Tool Router session
```python
from openai import OpenAI
from composio import Composio
from composio_openai import OpenAIResponsesProvider

composio = Composio(provider=OpenAIResponsesProvider())
openai = OpenAI()
session = composio.create(user_id='your-user-id')
```

```typescript
import OpenAI from 'openai';
import { Composio } from '@composio/core';
import { OpenAIResponsesProvider } from '@composio/openai';

const composio = new Composio({
  provider: new OpenAIResponsesProvider(),
});
const openai = new OpenAI({});
const session = await composio.create('your-user-id');
```

#### Path 1, Step 3: Execute Virustotal Tools via Tool Router with Your Agent

Get tools from Tool Router session and execute Virustotal actions with your Agent
```python
tools = session.tools
response = openai.responses.create(
  model='gpt-4.1',
  tools=tools,
  input=[{
    'role': 'user',
    'content': 'Scan this suspicious file hash for threats'
  }]
)
result = composio.provider.handle_tool_calls(
  response=response,
  user_id='your-user-id'
)
print(result)
```

```typescript
const tools = session.tools;
const response = await openai.responses.create({
  model: 'gpt-4.1',
  tools: tools,
  input: [{
    role: 'user',
    content: 'Scan this suspicious file hash for threats'
  }],
});
const result = await composio.provider.handleToolCalls(
  'your-user-id',
  response.output
);
console.log(result);
```

### Path 2: MCP Server Setup

#### Path 2, Step 1: Install Composio

Install the Composio SDK and Claude Agent SDK
```python
pip install composio claude-agent-sdk
```

```typescript
npm install @composio/core ai @ai-sdk/openai @ai-sdk/mcp
```

#### Path 2, Step 2: Create Tool Router Session

Initialize the Composio client and create a Tool Router session
```python
from composio import Composio
from claude_agent_sdk import ClaudeSDKClient, ClaudeAgentOptions

composio = Composio(api_key='your-composio-api-key')
session = composio.create(user_id='your-user-id')
url = session.mcp.url
```

```typescript
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: 'your-api-key' });

console.log("Creating Tool Router session...");
const { mcp } = await composio.create('your-user-id');
console.log(`Tool Router session created: ${mcp.url}`);
```

#### Path 2, Step 3: Connect to AI Agent

Use the MCP server with your AI agent
```python
import asyncio

options = ClaudeAgentOptions(
    permission_mode='bypassPermissions',
    mcp_servers={
        'tool_router': {
            'type': 'http',
            'url': url,
            'headers': {
                'x-api-key': 'your-composio-api-key'
            }
        }
    },
    system_prompt='You are a helpful assistant with access to Virustotal tools.',
    max_turns=10
)

async def main():
    async with ClaudeSDKClient(options=options) as client:
        await client.query('Get the analysis report for file hash 44d88612fea8a8f36de82e1278abb02f')
        async for message in client.receive_response():
            if hasattr(message, 'content'):
                for block in message.content:
                    if hasattr(block, 'text'):
                        print(block.text)

asyncio.run(main())
```

```typescript
import { openai } from '@ai-sdk/openai';
import { experimental_createMCPClient as createMCPClient } from '@ai-sdk/mcp';
import { generateText, stepCountIs } from 'ai';

const client = await createMCPClient({
  transport: {
    type: 'http',
    url: mcp.url,
    headers: { 'x-api-key': 'your-composio-api-key' }
  }
});

const tools = await client.tools();

const { text } = await generateText({
  model: openai('gpt-4o'),
  tools,
  messages: [{ role: 'user', content: 'Get the analysis report for file hash 44d88612fea8a8f36de82e1278abb02f' }],
  stopWhen: stepCountIs(5)
});

console.log(`Agent: ${text}`);
```

## Why Use Composio?

### 1. AI Native Virustotal Integration

- Supports both Virustotal MCP and direct API based integrations
- Structured, LLM-friendly schemas for reliable tool execution
- Rich coverage for submitting, scanning, and querying files, URLs, and reports

### 2. Managed Auth

- Built-in API key management, securely handled by Composio
- Central place to manage, scope, and revoke Virustotal access
- Per user and per environment credentials instead of hard-coded keys

### 3. Agent Optimized Design

- Tools are tuned using real error and success rates to improve reliability over time
- Comprehensive execution logs so you always know what ran, when, and on whose behalf

### 4. Enterprise Grade Security

- Fine-grained RBAC so you control which agents and users can access Virustotal
- Scoped, least privilege access to Virustotal resources
- Full audit trail of agent actions to support review and compliance

## Use Virustotal with any AI Agent Framework

Choose a framework you want to connect Virustotal with:

- [ChatGPT](https://composio.dev/toolkits/virustotal/framework/chatgpt)
- [OpenAI Agents SDK](https://composio.dev/toolkits/virustotal/framework/open-ai-agents-sdk)
- [Claude Agent SDK](https://composio.dev/toolkits/virustotal/framework/claude-agents-sdk)
- [Claude Code](https://composio.dev/toolkits/virustotal/framework/claude-code)
- [Claude Cowork](https://composio.dev/toolkits/virustotal/framework/claude-cowork)
- [Codex](https://composio.dev/toolkits/virustotal/framework/codex)
- [Cursor](https://composio.dev/toolkits/virustotal/framework/cursor)
- [VS Code](https://composio.dev/toolkits/virustotal/framework/vscode)
- [OpenCode](https://composio.dev/toolkits/virustotal/framework/opencode)
- [OpenClaw](https://composio.dev/toolkits/virustotal/framework/openclaw)
- [Hermes](https://composio.dev/toolkits/virustotal/framework/hermes-agent)
- [Google ADK](https://composio.dev/toolkits/virustotal/framework/google-adk)
- [LangChain](https://composio.dev/toolkits/virustotal/framework/langchain)
- [Vercel AI SDK](https://composio.dev/toolkits/virustotal/framework/ai-sdk)
- [Mastra AI](https://composio.dev/toolkits/virustotal/framework/mastra-ai)
- [LlamaIndex](https://composio.dev/toolkits/virustotal/framework/llama-index)
- [CrewAI](https://composio.dev/toolkits/virustotal/framework/crew-ai)
- [Pydantic AI](https://composio.dev/toolkits/virustotal/framework/pydantic-ai)
- [AutoGen](https://composio.dev/toolkits/virustotal/framework/autogen)

## Related Toolkits

- [Excel](https://composio.dev/toolkits/excel) - Microsoft Excel is a robust spreadsheet application for organizing, analyzing, and visualizing data. It's the go-to tool for calculations, reporting, and flexible data management.
- [21risk](https://composio.dev/toolkits/_21risk) - 21RISK is a web app built for easy checklist, audit, and compliance management. It streamlines risk processes so teams can focus on what matters.
- [Abstract](https://composio.dev/toolkits/abstract) - Abstract provides a suite of APIs for automating data validation and enrichment tasks. It helps developers streamline workflows and ensure data quality with minimal effort.
- [Addressfinder](https://composio.dev/toolkits/addressfinder) - Addressfinder is a data quality platform for verifying addresses, emails, and phone numbers. It helps you ensure accurate customer and contact data every time.
- [Agenty](https://composio.dev/toolkits/agenty) - Agenty is a web scraping and automation platform for extracting data and automating browser tasks—no coding needed. It streamlines data collection, monitoring, and repetitive online actions.
- [Ambee](https://composio.dev/toolkits/ambee) - Ambee is an environmental data platform providing real-time, hyperlocal APIs for air quality, weather, and pollen. Get precise environmental insights to power smarter decisions in your apps and workflows.
- [Ambient weather](https://composio.dev/toolkits/ambient_weather) - Ambient Weather is a platform for personal weather stations with a robust API for accessing local, real-time, and historical weather data. Get detailed environmental insights directly from your own sensors for smarter apps and automations.
- [Anonyflow](https://composio.dev/toolkits/anonyflow) - Anonyflow is a service for encryption-based data anonymization and secure data sharing. It helps organizations meet GDPR, CCPA, and HIPAA data privacy compliance requirements.
- [Api ninjas](https://composio.dev/toolkits/api_ninjas) - Api ninjas offers 120+ public APIs spanning categories like weather, finance, sports, and more. Developers use it to supercharge apps with real-time data and actionable endpoints.
- [Api sports](https://composio.dev/toolkits/api_sports) - Api sports is a comprehensive sports data platform covering 2,000+ competitions with live scores and 15+ years of stats. Instantly access up-to-date sports information for analysis, apps, or chatbots.
- [Apify](https://composio.dev/toolkits/apify) - Apify is a cloud platform for building, deploying, and managing web scraping and automation tools called Actors. It lets you automate data extraction and workflow tasks at scale—no infrastructure headaches.
- [Autom](https://composio.dev/toolkits/autom) - Autom is a lightning-fast search engine results data platform for Google, Bing, and Brave. Developers use it to access fresh, low-latency SERP data on demand.
- [Beaconchain](https://composio.dev/toolkits/beaconchain) - Beaconchain is a real-time analytics platform for Ethereum 2.0's Beacon Chain. It provides detailed insights into validators, blocks, and overall network performance.
- [Big data cloud](https://composio.dev/toolkits/big_data_cloud) - BigDataCloud provides APIs for geolocation, reverse geocoding, and address validation. Instantly access reliable location intelligence to enhance your applications and workflows.
- [Bigpicture io](https://composio.dev/toolkits/bigpicture_io) - BigPicture.io offers APIs for accessing detailed company and profile data. Instantly enrich your applications with up-to-date insights on 20M+ businesses.
- [Bitquery](https://composio.dev/toolkits/bitquery) - Bitquery is a blockchain data platform offering indexed, real-time, and historical data from 40+ blockchains via GraphQL APIs. Get unified, reliable access to complex on-chain data for analytics, trading, and research.
- [Brightdata](https://composio.dev/toolkits/brightdata) - Brightdata is a leading web data platform offering advanced scraping, SERP APIs, and anti-bot tools. It lets you collect public web data at scale, bypassing blocks and friction.
- [Builtwith](https://composio.dev/toolkits/builtwith) - BuiltWith is a web technology profiler that uncovers the technologies powering any website. Gain actionable insights into analytics, hosting, and content management stacks for smarter research and lead generation.
- [Byteforms](https://composio.dev/toolkits/byteforms) - Byteforms is an all-in-one platform for creating forms, managing submissions, and integrating data. It streamlines workflows by centralizing form data collection and automation.
- [Cabinpanda](https://composio.dev/toolkits/cabinpanda) - Cabinpanda is a data collection platform for building and managing online forms. It helps streamline how you gather, organize, and analyze responses.

## Frequently Asked Questions

### Do I need my own developer credentials to use Virustotal with Composio?

Yes, Virustotal requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

### Can I use multiple toolkits together?

Yes! Composio's Tool Router enables agents to use multiple toolkits. [Learn more](https://docs.composio.dev/tool-router/overview).

### Is Composio secure?

Composio is SOC 2 and ISO 27001 compliant with all data encrypted in transit and at rest. [Learn more](https://trust.composio.dev).

### What if the API changes?

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

---
[See all toolkits](https://composio.dev/toolkits) · [Composio docs](https://docs.composio.dev/llms.txt)
