Security Intel MCP
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"cve-vulnerability-lookup": {
"url": "https://security.datakoot.com/mcp"
}
}
}Remote-Endpunkte
https://security.datakoot.com/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (5)
🟢cve_lookup(cve_id)
Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.
Eingabe-Schema
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "CVE identifier, e.g. CVE-2021-44228 (case-insensitive; a bare 2021-44228 also works)."
}
},
"required": [
"cve_id"
]
}Ausgabe-Schema
{
"type": "object",
"properties": {
"id": {},
"status": {},
"description": {},
"cvss": {},
"cwe": {},
"published": {},
"last_modified": {},
"references": {},
"known_exploited": {},
"exploit_probability": {},
"sources": {}
},
"additionalProperties": true
}🟢known_exploited(cve_id, limit, vendor, ransomware_only)
Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.
Eingabe-Schema
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "Optional. Check a single CVE, e.g. CVE-2021-44228."
},
"limit": {
"type": "number",
"description": "When listing, how many newest entries to return (default 20, max 100)."
},
"vendor": {
"type": "string",
"description": "Optional. Filter by vendor or product name substring."
},
"ransomware_only": {
"type": "boolean",
"description": "Optional. Only vulns CISA links to known ransomware campaigns."
}
},
"required": []
}Ausgabe-Schema
{
"type": "object",
"properties": {
"catalog_version": {},
"catalog_count": {},
"released": {},
"returned": {},
"filter": {},
"vulnerabilities": {},
"source": {},
"cve_id": {},
"listed": {},
"vendor": {},
"product": {},
"name": {},
"date_added": {},
"due_date": {},
"known_ransomware_use": {},
"required_action": {}
},
"additionalProperties": true
}🟢epss_score(cve_id, cve_ids)
Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.
Eingabe-Schema
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "A single CVE id."
},
"cve_ids": {
"type": "array",
"items": {
"type": "string"
},
"description": "Multiple CVE ids (or pass a comma-separated string)."
}
},
"required": []
}Ausgabe-Schema
{
"type": "object",
"properties": {
"model": {},
"as_of": {},
"scored": {},
"scores": {},
"note": {},
"source": {}
},
"additionalProperties": true
}🟢package_vulnerabilities(ecosystem, name, version)
List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.
Eingabe-Schema
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"description": "Package registry to look in. One of: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex."
},
"name": {
"type": "string",
"description": "Exact package name as published in that registry, e.g. lodash for npm, requests for pypi."
},
"version": {
"type": "string",
"description": "Optional; if given, only vulns affecting that version are returned"
}
},
"required": [
"ecosystem",
"name"
]
}Ausgabe-Schema
{
"type": "object",
"properties": {
"ecosystem": {},
"name": {},
"version": {},
"vulnerability_count": {},
"vulnerabilities": {},
"source": {}
},
"additionalProperties": true
}🟢audit_dependencies(manifest, dependencies, ecosystem)
Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.
Eingabe-Schema
{
"type": "object",
"properties": {
"manifest": {
"type": "string",
"description": "Raw package.json contents"
},
"dependencies": {
"type": "array",
"items": {
"type": "object"
},
"description": "[{name, version}] entries"
},
"ecosystem": {
"type": "string",
"description": "Package registry for the dependencies: npm (default), pypi, cargo, go, maven, rubygems, nuget, composer, pub, or hex."
}
},
"required": []
}Ausgabe-Schema
{
"type": "object",
"properties": {
"ecosystem": {},
"packages_audited": {},
"packages_with_vulnerabilities": {},
"total_vulnerabilities": {},
"packages_not_found": {},
"packages_unverified": {},
"verdict": {},
"findings": {},
"source": {}
},
"additionalProperties": true
}Community
Nachweis