Hybrid Analysis MCP integration for AI agents.

Connect AI agents to Hybrid Analysis through 5 structured actions, including get current key, get overview, and get report state. Review authentication, inpu…

ACTION CONTRACTS
5
AUTHENTICATION
API key
SOURCE STATUS
Provider-backed

CATALOG SOURCE REVIEWED AUGUST 23, 2026 / ACTION NAMES AND SCHEMAS DERIVED FROM WORKING MACHINES PROVIDER SOURCE

CAPABILITY PROFILE

What the Hybrid Analysis integration exposes

The Hybrid Analysis Agent App exposes 5 provider-backed actions for security and data work. Its current contract lets an authorized agent get the authorization level for the current hybrid analysis api key, get the hybrid analysis overview for a sha256 file hash, and get the processing state of a hybrid analysis sandbox report. These operations are called through Working Machines as typed capabilities rather than through browser navigation or copied UI steps.

A connection uses API key. Before execution, the agent can inspect the selected action, its required fields, declared scopes, and expected output contract. Provider credentials remain inside the Working Machines runtime; the calling agent receives the capability and its structured result, not the underlying secret.

For reliable operation, start with the narrowest action that satisfies the task, resolve stable provider identifiers before changing state, and validate the returned object or status after execution. Availability still depends on the connected Hybrid Analysis account, granted provider permissions, workspace policy, region, plan, and upstream API behavior.

VERIFIED ACTION SAMPLE

Real Hybrid Analysis capabilities.

Showing 5 of 5 actions. Risk labels are conservative signals based on operation names, not substitutes for provider documentation or runtime policy.

get_current_keyREAD

Get the authorization level for the current Hybrid Analysis API key.

get_overviewREAD

Get the Hybrid Analysis overview for a SHA256 file hash.

INPUTS: sha256

get_report_stateREAD

Get the processing state of a Hybrid Analysis sandbox report.

INPUTS: reportId

get_report_summaryREAD

Get the summary of a Hybrid Analysis sandbox report.

INPUTS: reportId

search_hashREAD

Find Hybrid Analysis detonation reports associated with a file hash.

INPUTS: hash

INPUT CONTRACTS

Know what the action needs before it runs.

get_overview

sha256OPTIONAL
The SHA256 file hash to look up.

get_report_state

reportIdOPTIONAL
A Hybrid Analysis job ID or a report identifier formatted as sha256:environmentId.

get_report_summary

reportIdOPTIONAL
A Hybrid Analysis job ID or a report identifier formatted as sha256:environmentId.

search_hash

hashOPTIONAL
An MD5, SHA1, SHA256, or SHA512 file hash.

PROVIDER-SPECIFIC WORKFLOWS

Jobs this Agent App can support

Inspect Get Current Key

Get the authorization level for the current Hybrid Analysis API key. Use this as a bounded discovery step, retain the returned identifier, and avoid expanding the read beyond the task's stated scope.

get_current_key

Verify with Get Overview

Get the Hybrid Analysis overview for a SHA256 file hash. Compare the returned provider state with the intended outcome and preserve stable IDs or canonical links in the run record.

get_overview

SAFETY BOUNDARY

Operate Hybrid Analysis with explicit limits

  • Authorize Hybrid Analysis with API key and grant only the provider access required by the selected actions.
  • The current action names appear read-oriented, but returned Hybrid Analysis data may still be sensitive and should be minimized before it enters model context.
  • Do not infer permission from catalog visibility. Workspace policy, connection identity, and upstream authorization still govern execution.
  • No provider scope string is declared on the sampled actions. Verify the connected account's actual permissions in Hybrid Analysis rather than assuming unrestricted access.
  • After a call, inspect the structured result and execution record before reporting that the Hybrid Analysis task completed successfully.

CONNECTION MODEL

API key

Hybrid Analysis API key sent in the api-key header. Get it at https://www.hybrid-analysis.com/profile?tab=api-key.

Working Machines stores provider credentials behind the execution boundary. An agent can use an authorized connection identity, but catalog discovery alone does not reveal OAuth tokens, API keys, or provider secrets.

READ SIGNALS
5
WRITE SIGNALS
0
HIGH IMPACT
0
REVIEW SIGNALS
0

EVIDENCE AND AVAILABILITY

Provider reference

Action names, input fields, authentication types, and counts on this page are generated from the Working Machines provider catalog. Provider behavior, quotas, object semantics, account eligibility, and regional availability remain governed by Hybrid Analysis.

Official Hybrid Analysis website

ONE CONNECTION. REAL WORK.

Give your agent software it can use.

Connect through MCP or explore the Agent App catalog and choose only the capabilities your workflow needs.

EXPLORE AGENT APPS