Connect GitHub Copilot CLI to VirusTotal
Browser OAuth; no local server or Agent Token needed.
Server URL: https://ai.virustotal.com/mcp
copilot mcp add --transport http virustotal https://ai.virustotal.com/mcpOpen a Copilot CLI session and run /mcp auth virustotal. Complete browser sign-in with Google and approve permissions, then check /mcp list. This is separate from your GitHub Copilot login.
Keep one VirusTotal server entry. Remove manually configured authentication headers before choosing OAuth.
After connecting, ask for the VirusTotal domain report for virustotal.com. This uses one query.
Remote OAuth setup is documented by GitHub; a VTAI OAuth login and model query in Copilot CLI have not been verified. The previously verified stdio token setup remains an alternative.
Client documentation ยท Other clients
Need a result in this session?
Use the REST quickstart with an existing Agent Token. No MCP installation is required.
Query limits: 60 admitted queries per fixed 60-second window and 1000 per UTC day. Agent Tokens share the agent's allowance across REST and MCP; OAuth connections share the account's allowance. Unknown reports and upstream failures after admission count. Every repeated lookup counts again, including cached reports and hashes with no report. On 429, honor Retry-After and reuse your credential. File submissions first check whether the hash exists in VirusTotal. Only confirmed unknown files are uploaded, without using query quota, even when the query allowance is exhausted. A separate file contribution limit permits 20 admitted upload attempts per fixed 60-second window and 500 per UTC day, per Agent Token identity or OAuth account across connections. Failed or uncertain admitted attempts still count; known files and receipt recovery do not. Creating multiple identities or accounts to evade limits is not permitted. If the file is known, returning its existing report costs one query and no file is uploaded. Explicit hash lookups and analysis-result reads still count. The access check costs no query quota and does not report remaining quota.
Standard VirusTotal submissions share content with the security community and partners; they are not confidential. Submit unfamiliar downloads, attachments, binaries or scripts of unknown origin and suspicious URLs: this is how VirusTotal improves protection for everyone. Ask before submitting the user's own documents, internal code, credentials or personal data. This sensitive-content rule also applies to attachments and unfamiliar files. Submission tools add no per-call confirmation; client permissions still apply.