From superpowers
Automates VirusTotal scans, file analysis, and reports via Rube MCP and Composio toolkit. Discovers tools with RUBE_SEARCH_TOOLS, manages connections, and executes workflows for security tasks.
npx claudepluginhub lunartech-x/superpowers --plugin superpowersThis skill uses the workspace's default tool permissions.
Automate Virustotal operations through Composio's Virustotal toolkit via Rube MCP.
Automates SecurityTrails operations via Composio toolkit and Rube MCP. Discovers tools dynamically with RUBE_SEARCH_TOOLS, manages connections, and executes workflows securely.
Guides SentinelOne Purple MCP tools: uvx install, Service User token auth, GraphQL/REST APIs, transport modes, rate limits, error handling for 23 read-only tools across Purple AI, alerts, vulnerabilities, assets.
Builds Python pipeline to collect suspicious files from EDR/email gateways, submit to VirusTotal/Cuckoo/Any.Run sandboxes, generate IOC verdicts for SIEM. For SOC malware triage at scale.
Share bugs, ideas, or general feedback.
Automate Virustotal operations through Composio's Virustotal toolkit via Rube MCP.
Toolkit docs: composio.dev/toolkits/virustotal
RUBE_MANAGE_CONNECTIONS with toolkit virustotalRUBE_SEARCH_TOOLS first to get current tool schemasGet Rube MCP: Add https://rube.app/mcp as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
RUBE_SEARCH_TOOLS respondsRUBE_MANAGE_CONNECTIONS with toolkit virustotalAlways discover available tools before executing workflows:
RUBE_SEARCH_TOOLS
queries: [{use_case: "Virustotal operations", known_fields: ""}]
session: {generate_id: true}
This returns available tool slugs, input schemas, recommended execution plans, and known pitfalls.
RUBE_SEARCH_TOOLS
queries: [{use_case: "your specific Virustotal task"}]
session: {id: "existing_session_id"}
RUBE_MANAGE_CONNECTIONS
toolkits: ["virustotal"]
session_id: "your_session_id"
RUBE_MULTI_EXECUTE_TOOL
tools: [{
tool_slug: "TOOL_SLUG_FROM_SEARCH",
arguments: {/* schema-compliant args from search results */}
}]
memory: {}
session_id: "your_session_id"
RUBE_SEARCH_TOOLSRUBE_MANAGE_CONNECTIONS shows ACTIVE status before executing toolsmemory in RUBE_MULTI_EXECUTE_TOOL calls, even if empty ({})| Operation | Approach |
|---|---|
| Find tools | RUBE_SEARCH_TOOLS with Virustotal-specific use case |
| Connect | RUBE_MANAGE_CONNECTIONS with toolkit virustotal |
| Execute | RUBE_MULTI_EXECUTE_TOOL with discovered tool slugs |
| Bulk ops | RUBE_REMOTE_WORKBENCH with run_composio_tool() |
| Full schema | RUBE_GET_TOOL_SCHEMAS for tools with schemaRef |
Powered by Composio