Qu1cksc0pe
All-in-One malware analysis tool.
Install / Use
claude mcp add CYB3RMX -- npx -y github:CYB3RMX/Qu1cksc0peIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of Qu1cksc0pe
Qu1cksc0pe scores 87/100 on our quality scale, 483rd of 777 Security skills we index.
Its MCP Server is 32 KB long, well organised into 59 sections with 12 code examples: a thorough specification that gives an agent plenty to work with.
With 2,062 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 10 days ago, so Qu1cksc0pe is actively maintained.
- Our last check on 2026-09-28 found the source still online.
- It is released under GPL-3.0, a copyleft license: you can use it, but modified versions you distribute must carry the same license.
- Its trust signals score 95/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
Qu1cksc0pe compared with similar skills
All 4 of these similar skills score higher than Qu1cksc0pe; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| Qu1cksc0pe (this skill)by CYB3RMX | 87 | 2.1k | 10d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 86.0k | 13d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install Qu1cksc0pe?
- Run
claude mcp add CYB3RMX -- npx -y github:CYB3RMX/Qu1cksc0pe. The install tabs above show the steps for each supported agent. - Which AI agents does Qu1cksc0pe work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is Qu1cksc0pe safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is GPL-3.0-licensed and scores 95/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is Qu1cksc0pe still maintained?
- The repository was last updated 10 days ago, so Qu1cksc0pe is actively maintained.
Skill content
View source on GitHubQu1cksc0pe
<a href="https://www.buymeacoffee.com/cyb3rmx"><img src="https://www.buymeacoffee.com/assets/img/custom_images/orange_img.png" height="40px"></a><br><br> <img src="https://img.shields.io/badge/-Linux-black?style=for-the-badge&logo=Linux&logoColor=white"> <img src="https://img.shields.io/badge/-Python-black?style=for-the-badge&logo=python&logoColor=white"> <img src="https://img.shields.io/badge/-Terminal-black?style=for-the-badge&logo=GNU%20Bash&logoColor=white"> <img src="https://img.shields.io/badge/-GPL%203.0-black?style=for-the-badge&Color=white">
<p align="center"> <img width="400" src="https://user-images.githubusercontent.com/42123683/216772963-0b035e5a-c9db-4a6e-ac32-ebca22921405.png" alt="logo"> </p> <br>All-in-One malware analysis tool for analyze many file types, from Windows binaries to E-Mail files.<br>You can get:
- What DLL files are used.
- Functions and APIs.
- Sections and segments.
- URLs, IP addresses and emails.
- Android permissions (Dangerous/Special/Info).
- MITRE ATT&CK mappings (Windows + Linux static analysis).
- File extensions and their names.
- Embedded executables/exploits. <br><b>And so on...</b><br>
Qu1cksc0pe aims to get even more information about suspicious files and helps user realize what that file is capable of.
Qu1cksc0pe Can Analyze Currently
| Files | Analysis Type |
| :--- | :--- |
| Windows Executables (.exe, .dll, .msi, .bin) | Static, Dynamic |
| Linux Executables (.elf, .bin) | Static, Dynamic |
| MacOS Executables (mach-o) | Static |
| Android Files (.apk, .jar, .dex) | Static, Dynamic(for now .apk only) |
| Golang Binaries (Linux) | Static |
| Document Files | Static; sandboxed VBA behavior emulation when macros are present |
| VBScript/VBA Family (.vbs, .vbe, .vba, .vb, .bas, .cls, .frm) | Static + sandboxed behavior emulation (--docs) |
| AppleScript Source (.applescript, including content detected under misleading VB-family extensions) | Static (--analyze) |
| HTML Documents (.html, .htm) | Static + isolated inline JavaScript behavior emulation (--analyze) |
| JavaScript (.js) | Static + isolated behavior emulation (--analyze) |
| HTA / HTML Application (.hta) | Static + isolated JScript behavior emulation (--analyze) |
| Windows Batch Scripts (.bat, .cmd, including content detected under misleading VB-family extensions) | Static (--analyze) |
| Windows Shortcut (.lnk) | Static (--analyze) |
| Archive Files (.zip, .rar, .ace) | Static |
| PCAP Files (.pcap) | Static |
| PowerShell Scripts (.ps1, .PS1) | Static + bounded in-memory behavior emulation (--analyze) |
| E-Mail Files (.eml) | Static |
MCP Server
Qu1cksc0pe ships an MCP server (Modules/mcp_server.py) that exposes its static-analysis features as tools for MCP-aware clients (Claude Code, Claude Desktop, etc.). It shells out to qu1cksc0pe.py the same way the Web UI does, so it needs no code changes to stay in sync with the CLI, and it only imports the mcp package itself at startup (the individual analyzers' own dependencies are only needed once a tool actually runs).
Install the extra dependency (already included in requirements.txt):
pip install "mcp>=2.0.0"
Launch it through the --mcp flag, same as every other Qu1cksc0pe command:
python3 qu1cksc0pe.py --mcp
Transport defaults to streamable-http (binds 127.0.0.1:8765/mcp), so the server is a persistent process any number of clients can attach to and detach from independently -- run it once in its own terminal, point clients at http://127.0.0.1:8765/mcp. Override with:
SC0PE_MCP_TRANSPORT=stdio python3 qu1cksc0pe.py --mcp # traditional one-client-per-process model
| Env var | Default | |
| :--- | :--- | :--- |
| SC0PE_MCP_TRANSPORT | streamable-http | streamable-http, stdio, or sse. |
| SC0PE_MCP_HOST | 127.0.0.1 | Bind address for streamable-http/sse. |
| SC0PE_MCP_PORT | 8765 | Bind port for streamable-http/sse. |
| SC0PE_MCP_HTTP_PATH | /mcp | URL path for streamable-http. |
A project-level .mcp.json is included so Claude Code picks the server up automatically for this repo. It pins stdio explicitly (via env), since Claude Code spawns and owns a fresh process per session rather than attaching to one you started yourself:
{
"mcpServers": {
"qu1cksc0pe": {
"command": "python3",
"args": ["qu1cksc0pe.py", "--mcp"],
"env": { "SC0PE_MCP_TRANSPORT": "stdio" }
}
}
}
If python3 on your PATH isn't the interpreter with Qu1cksc0pe's dependencies installed (common on Windows, or with multiple Python installs), change command to the full path of the right python/python.exe, or run python3 -c "import mcp" first to check.
Tools: analyze_file, analyze_document, analyze_archive, detect_packer, detect_language, extract_iocs, check_resources, check_signatures, scan_hash, scan_virustotal, configure_virustotal_api_key, configure_ai_api_key, update_hash_database, list_supported_file_types. Each tool validates its input file/folder locally (rejecting files >= 50MB, since the CLI would otherwise prompt interactively) before invoking the CLI, and returns the resulting JSON report(s) plus captured console output. Interactive-only features (--watch dynamic analysis, --ui, --install) are intentionally not exposed as tools.
The five analysis tools that support ai=True also take an ai_provider argument ("auto"/"ollama" (default, local), "claude", "openai", "deepseek", "kimi", or "glm") -- see AI Analysis Providers below. Configure a cloud key first with configure_ai_api_key(provider="claude", api_key="...") (or whichever provider).
Logs: every tool call and CLI dispatch (command, duration, exit code, reports collected) is logged to stderr and to sc0pe_reports/mcp/mcp_server.log. Set SC0PE_MCP_LOG_LEVEL=DEBUG for full stderr output too, or SC0PE_MCP_LOG_FILE=0 to disable the file sink.
AI Analysis Providers
--ai (and the MCP tools' ai=True) summarizes a generated report with an LLM. Ollama (local) is the default; five cloud backends are also supported.
| Provider | Flag/value | Env var |
| :--- | :--- | :--- |
| Ollama (default) | auto or ollama | OLLAMA_HOST |
| Claude (Anthropic) | claude | ANTHROPIC_API_KEY |
| OpenAI | openai | OPENAI_API_KEY |
| DeepSeek | deepseek | DEEPSEEK_API_KEY |
| Kimi (Moonshot AI) | kimi | MOONSHOT_API_KEY |
| GLM (Zhipu AI) | glm | ZHIPUAI_API_KEY |
Ollama needs no key -- install Ollama and select the model via [Ollama] model in Systems/Multiple/multiple.conf. For a cloud provider, either set its env var above, or save a key through the interactive key manager:
python qu1cksc0pe.py --key_init
# >>> Qu1cksc0pe API Key Manager
# 1) VirusTotal
# 2) Claude (Anthropic)
# 3) OpenAI
# 4) DeepSeek
# 5) Kimi (Moonshot AI)
# 6) GLM (Zhipu AI)
# 0) Exit
--key_init --key_provider <name> (e.g. --key_provider claude) skips the menu and prompts for just that one key -- useful for scripts (this is what the MCP server's configure_ai_api_key/configure_virustotal_api_key tools do under the hood).
# Explicit provider selection (auto/ollama is the default -- no flag needed for local analysis)
python qu1cksc0pe.py --file suspicious_file --analyze --ai --ai_provider claude
The default (auto/unset) is unchanged from prior versions: Ollama, falling back to a heuristic summary if it's unavailable. Cloud providers are strictly opt-in -- report data is only sent off-machine if you explicitly pass --ai_provider <name> or set SC0PE_AI_PROVIDER. See the Environment Variables table for model/base-URL/timeout/token tuning per provider.
Usage
python qu1cksc0pe.py --file suspicious_file --analyze
# Launch Web UI
python3 qu1cksc0pe.py --ui
Screenshot
Updates
<b>18/09/2026</b>
- [X] Windows dynamic analysis: improved x86/x64 API tracing, process-tree monitoring, PID reuse handling, and debugger cleanup. Live-memory YARA/IOC scanning, bounded memory exports, and process injection/hollowing checks are enabled by default. Correlated API sequences and image anomalies are reported as candidates, not confirmed malicious execution.
- [X] Linux dynamic analysis:
--watchnow supports process-tree monitoring withstrace/ltrace, network connections, open files, live-memory YARA/IOC scanning, and structured behavior observations. Reports record collection errors and incomplete coverage. - [X] Android dynamic analysis: added explicit ADB device selection, APK installation or installed-package monitoring, native/Java Frida hooks, process tracking, logcat, file changes, and sampled memory analysis. Fixed stale Frida detach events affecting replacement sessions; APK/device ABI compatibility and installation failures are now reported.
- [X] Android static analysis: improved manifest, permissions, component, and network-security checks; bounded archive/member scanning; and isolated JADX output. Limited
aaptrecovery preserves package identity and observed permissions when the manifest parser fails. Partial decompilation is reported explicitly, and generic component names no longer establish a malware-family candidate. - [X] YARA updates: expanded the bundled rules and added Koodous metadata compatibility for Android. Missing metadata remains unknown; compilation failures and partial scans are visible in reports. Fixed lost matches from rules without string instances and overly broad conditions that caused false positives. Added
tools/audit_yara_rules.pyto check compilation and empty-input matches.
<b>14/09/2026</b>
- [X] New feature: PowerShell analysis (
--analyze) now includes Qu1cksc0pe's bounded, in-memory abstract emulator. It models supported PowerShell operations and selected .NET APIs to report dynamic code, network requests, process attempts, and filesystem activity without invoking a real PowerShell runtime or fetching network responses. Unsupported operations, unresolved inputs, and resource limits can leave the analysis incomplete; speculative behavior does not establish runtime reachability.
<b>01/09/2026</b>
- [X] New feature: malicious JavaScript can now be emulated automatically during HTML/JS/HTA analysis by a native, bounded abstract interpreter. Browser, WSH, ActiveX, Node.js network/process/filesystem/registry APIs and decoded
evallayers are modeled entirely in memory; sample code, commands, files, and network requests are never executed on the host.
<b>25/08/2026</b>
- [X] New feature: Office VBA projects and plaintext VBScript/VBA-family files are now emulated automatically in a native, in-memory sandbox during
--docsanalysis. The normal static scan still runs, and JSON reports include the emulation findings, IOC event trace, network requests, process attempts, persistence activity, and virtual files. - [X] New feature: added AppleScript source analysis to
Modules/apple_analyzer.py, including execution, network, credential-access, collection, persistence, defense-evasion, filesystem, shell-command, URL, and YARA indicators. Use--analyze; AppleScript is never executed throughosascript. - [X] New feature: added dedicated Windows Batch analysis for
.bat/.cmdfiles, with execution, persistence, defense-evasion, download/network, obfuscation, IOC, and YARA detection.
<b>12/08/2026</b>
- [X] New feature: added an MCP server (
--mcp,Modules/mcp_server.py,.mcp.json) exposing Qu1cksc0pe as tools for MCP clients like Claude Code, defaulting tostreamable-http(persistent, multi-client;stdio/ssealso available) with logging to stderr andsc0pe_reports/mcp/mcp_server.log(SC0PE_MCP_LOG_LEVEL/SC0PE_MCP_LOG_FILE). See the "MCP Server" s
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.0kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.4k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
