Hybrid Analysis MCP integration for AI agents.
Connect AI agents to Hybrid Analysis through 5 structured actions, including get current key, get overview, and get report state. Review authentication, inpu…
- ACTION CONTRACTS
- 5
- AUTHENTICATION
- API key
- SOURCE STATUS
- Provider-backed
CATALOG SOURCE REVIEWED AUGUST 23, 2026 / ACTION NAMES AND SCHEMAS DERIVED FROM WORKING MACHINES PROVIDER SOURCE
CAPABILITY PROFILE
What the Hybrid Analysis integration exposes
The Hybrid Analysis Agent App exposes 5 provider-backed actions for security and data work. Its current contract lets an authorized agent get the authorization level for the current hybrid analysis api key, get the hybrid analysis overview for a sha256 file hash, and get the processing state of a hybrid analysis sandbox report. These operations are called through Working Machines as typed capabilities rather than through browser navigation or copied UI steps.
A connection uses API key. Before execution, the agent can inspect the selected action, its required fields, declared scopes, and expected output contract. Provider credentials remain inside the Working Machines runtime; the calling agent receives the capability and its structured result, not the underlying secret.
For reliable operation, start with the narrowest action that satisfies the task, resolve stable provider identifiers before changing state, and validate the returned object or status after execution. Availability still depends on the connected Hybrid Analysis account, granted provider permissions, workspace policy, region, plan, and upstream API behavior.
VERIFIED ACTION SAMPLE
Real Hybrid Analysis capabilities.
Showing 5 of 5 actions. Risk labels are conservative signals based on operation names, not substitutes for provider documentation or runtime policy.
get_current_keyREADGet the authorization level for the current Hybrid Analysis API key.
get_overviewREADGet the Hybrid Analysis overview for a SHA256 file hash.
INPUTS: sha256
get_report_stateREADGet the processing state of a Hybrid Analysis sandbox report.
INPUTS: reportId
get_report_summaryREADGet the summary of a Hybrid Analysis sandbox report.
INPUTS: reportId
search_hashREADFind Hybrid Analysis detonation reports associated with a file hash.
INPUTS: hash
INPUT CONTRACTS
Know what the action needs before it runs.
get_overview
sha256OPTIONAL- The SHA256 file hash to look up.
get_report_state
reportIdOPTIONAL- A Hybrid Analysis job ID or a report identifier formatted as sha256:environmentId.
get_report_summary
reportIdOPTIONAL- A Hybrid Analysis job ID or a report identifier formatted as sha256:environmentId.
search_hash
hashOPTIONAL- An MD5, SHA1, SHA256, or SHA512 file hash.
PROVIDER-SPECIFIC WORKFLOWS
Jobs this Agent App can support
Inspect Get Current Key
Get the authorization level for the current Hybrid Analysis API key. Use this as a bounded discovery step, retain the returned identifier, and avoid expanding the read beyond the task's stated scope.
get_current_keyVerify with Get Overview
Get the Hybrid Analysis overview for a SHA256 file hash. Compare the returned provider state with the intended outcome and preserve stable IDs or canonical links in the run record.
get_overviewSAFETY BOUNDARY
Operate Hybrid Analysis with explicit limits
- Authorize Hybrid Analysis with API key and grant only the provider access required by the selected actions.
- The current action names appear read-oriented, but returned Hybrid Analysis data may still be sensitive and should be minimized before it enters model context.
- Do not infer permission from catalog visibility. Workspace policy, connection identity, and upstream authorization still govern execution.
- No provider scope string is declared on the sampled actions. Verify the connected account's actual permissions in Hybrid Analysis rather than assuming unrestricted access.
- After a call, inspect the structured result and execution record before reporting that the Hybrid Analysis task completed successfully.
CONNECTION MODEL
API key
Hybrid Analysis API key sent in the api-key header. Get it at https://www.hybrid-analysis.com/profile?tab=api-key.
Working Machines stores provider credentials behind the execution boundary. An agent can use an authorized connection identity, but catalog discovery alone does not reveal OAuth tokens, API keys, or provider secrets.
- READ SIGNALS
- 5
- WRITE SIGNALS
- 0
- HIGH IMPACT
- 0
- REVIEW SIGNALS
- 0
EVIDENCE AND AVAILABILITY
Provider reference
Action names, input fields, authentication types, and counts on this page are generated from the Working Machines provider catalog. Provider behavior, quotas, object semantics, account eligibility, and regional availability remain governed by Hybrid Analysis.