Virustotal connects to a Nagent workspace with an API key. Once it is connected, agents can call 16 Virustotal actions, such as "Add VirusTotal Comment", "Add Vote" and "Get Analysis Report". Nothing is enabled on connect: each action is allowed one at a time, and an action with side effects runs or waits for a person according to the agent's level.
Every operation an agent can call against Virustotal, with input parameters and output schema.
VIRUSTOTAL_ADD_COMMENTTool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use after analyzing a resource to leave contextual feedback. Provide exactly one identifier per call.
Input parameters
URL resource identifier to comment on. Mutually exclusive with file, domain, and ip_address.
SHA-256 hash of the file to comment on. Mutually exclusive with url, domain, and ip_address.
The comment text to add.
Domain name to comment on. Mutually exclusive with file, url, and ip_address.
IP address to comment on. Mutually exclusive with file, url, and domain.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_ADD_VOTETool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing analysis results to submit your verdict.
Input parameters
The vote data object to submit.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_ANALYSISTool to retrieve the analysis report of a file or URL submission. Use after obtaining an analysis ID to fetch its detailed report. Analysis results may be incomplete immediately after submission; poll until the report status is 'completed' before treating results as final.
Input parameters
The identifier of the analysis to retrieve
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_COMMENTSTool to retrieve the latest comments on a VirusTotal resource. Use when you need to review user-generated comments for a file, URL, domain, or IP after obtaining its identifier.
Input parameters
Sort order by comment date ('asc' or 'desc')
Number of comments to return per page (default: 10, max: 40)
Pagination cursor for fetching next page
Resource identifier to get comments for (SHA-256, URL, domain, or IP address)
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_DOMAIN_RELATIONSHIPSTool to retrieve relationship objects for a given domain. Use when you have a domain and need to explore its related entities.
Input parameters
Number of items to return per page (1-40). Defaults to server default if omitted.
Pagination cursor for fetching next page of results.
The domain name to query (e.g., 'example.com').
Type of relationship to retrieve. Allowed values: communicating_files, referrer_files, downloaded_files, resolutions, subdomains, categories, whois, ssl_certificates, detected_downloaded_samples, detected_referrer_samples.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_DOMAIN_REPORTTool to retrieve the analysis report of a domain. Use when you need detailed insight on a domain's reputation and analysis stats. No malicious signals on obscure or low-traffic domains may indicate limited analysis history rather than safety — treat sparse results as 'unknown', not 'safe'. Covers external OSINT only (reputation, malware, SSL posture); cannot analyze internal/private assets.
Input parameters
The domain name to retrieve the report for (e.g., 'example.com')
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_FILE_REPORTTool to retrieve the analysis report of a file. Use when you have a file's hash and need detailed scan metadata. Recently submitted files may return partial results; retry after a short delay before treating the report as final.
Input parameters
Unique file identifier (SHA-256, SHA-1, MD5 hash or scan_id)
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_IP_ADDRESS_RELATIONSHIPSTool to retrieve objects related to a specific IP address by relationship type. Use when you have an IP and need to explore connected files, URLs, or other entities.
Input parameters
The IPv4 or IPv6 address to query (e.g., '8.8.8.8').
Number of items to return per page (1-40). Defaults to server default if omitted.
Pagination cursor for fetching next page of results.
Type of relationship to retrieve. Allowed values: communicating_files, downloaded_files, communicating_urls.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_IP_ADDRESS_REPORTTool to retrieve the analysis report of an IP address. Use when you need detailed insight on an IP's reputation, ASN, country, and analysis stats. Low or zero detections indicate unknown risk, not safety — treat sparse data accordingly. Provides external OSINT only; insufficient as standalone compliance evidence.
Input parameters
The IP address to retrieve the report for (IPv4 or IPv6) Note: this parameter is named `ip`, not `ipAddress` (used by ABUSEIPDB_CHECK_IP); using the wrong name causes validation failure.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_METADATATool to retrieve VirusTotal metadata. Use when you need information about available privileges, relationships between resources (like files, domains, IPs, URLs), and supported antivirus engines.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_URL_REPORTTool to retrieve the analysis report of a URL. Use when you have a URL identifier (base64-url without padding) and need detailed scan results, reputation, and metadata. Results may be incomplete immediately after submission; retry with short delays if scan engines are still processing before treating the report as final.
Input parameters
Base64 URL identifier (RFC 4648 without padding) of the URL
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_GET_VOTESTool to retrieve votes on files, URLs, domains, or IP addresses. Use when you need to view community votes for a given object.
Input parameters
Maximum number of votes to retrieve (default: 10, max: 40).
Pagination cursor for fetching subsequent pages of results.
Identifier of the object (e.g., file hash, URL-encoded URL, domain name, or IP address).
Type of the object to retrieve votes for: 'files', 'urls', 'domains', or 'ip_addresses'.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_RESCAN_FILETool to re-analyze a previously submitted file. Use when you need updated analysis results after an initial scan.
Input parameters
Unique file identifier (SHA-256, SHA-1, or MD5 hash of the file) to re-analyze.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_SCAN_URLTool to submit a URL for scanning. Use when you have a URL and need to submit it to VirusTotal to obtain an analysis ID for later retrieval. The returned analysis ID is preliminary — scanning engines may not have finished. Poll VIRUSTOTAL_GET_URL_REPORT with the ID using short delays to retrieve complete results.
Input parameters
The URL to be analyzed.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_SEARCHTool to search for objects in the VirusTotal database. Use when locating files, URLs, domains, IPs, or comments matching a query. Supports pagination with limit and cursor.
Input parameters
Maximum number of items to return (1-40). Defaults to 10 if not specified.
Query string to search in the VirusTotal database. Can be a file hash, URL, domain, IP address, or an advanced search query.
Pagination cursor from a previous SEARCH response. Use to retrieve the next batch of results.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
VIRUSTOTAL_UPLOAD_FILETool to upload a file for scanning. Use when you have binary file content ready to submit for VirusTotal analysis.
Input parameters
Binary content of the file to upload.
Optional filename to use for the uploaded file.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
Agents can call 16 Virustotal actions on Nagent, including "Add VirusTotal Comment", "Add Vote" and "Get Analysis Report". Add VirusTotal Comment: Add a comment to a VirusTotal resource (file, URL, domain, or IP address). Each action is listed on this page with its input parameters and its output.
Virustotal connects with an API key, under your workspace's own connection. Nothing is enabled on connect: each action is allowed one at a time and can be scoped to the agents that need it.
Add VirusTotal Comment takes 1 required input: text. It also takes 4 optional inputs: url, file, domain and ip_address. It returns data, error and successful.