exploitwatch
Check dependencies against CISA's real Known Exploited Vulnerabilities feed.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"exploitwatch": {
"url": "https://exploitwatch-kappa.vercel.app/api/mcp"
}
}
}Remote endpoints
https://exploitwatch-kappa.vercel.app/api/mcpstreamable-httpWhat it can do
Tool inventory
Tools (1)
🟢check_kev(dependencies)
Check a comma-separated list of software dependency/product names (e.g. 'lodash, openssl, apache struts') against CISA's real, public Known Exploited Vulnerabilities (KEV) catalog. Returns any current matches with the CVE ID, description, date added, and known ransomware use -- grounded in CISA's live feed, not a guess. Useful for triaging whether a project's dependencies include anything under active exploitation right now.
Input Schema
{
"type": "object",
"properties": {
"dependencies": {
"type": "string",
"description": "Comma-separated dependency/product names, e.g. 'express, lodash, openssl'"
}
},
"required": [
"dependencies"
]
}Community
Evidence