vdb
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
Should I use this
Quality & Safety
Findings (2)
- HIGH
- INFOin vdb_lookup
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"vdb": {
"command": "uvx",
"args": [
"vdb-mcp"
]
}
}
}Runnable packages
0.2.6stdioRemote endpoints
https://vdb.ai.kr/mcpstreamable-httpWhat it can do
Tool inventory
Tools (7)
🟡vdb_check_package(purl, version)
BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.
Input Schema
{
"type": "object",
"properties": {
"purl": {
"type": "string",
"description": "Package URL, e.g. 'pkg:npm/lodash' or 'pkg:pypi/requests'"
},
"version": {
"type": "string",
"description": "Optional version. If supplied, range matching is applied."
}
},
"required": [
"purl"
]
}🟡vdb_check_packages(packages)
Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.
Input Schema
{
"type": "object",
"properties": {
"packages": {
"type": "array",
"items": {
"type": "string"
},
"description": "List of PURLs or 'ecosystem/name' shorthand."
}
},
"required": [
"packages"
]
}⚪vdb_scan_lockfile(filename, content, path)
BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.
Input Schema
{
"type": "object",
"properties": {
"filename": {
"type": "string",
"description": "e.g. 'package-lock.json' — the format is detected from it"
},
"content": {
"type": "string",
"description": "The file's text."
},
"path": {
"type": "string",
"description": "Local runs only (uvx vdb-mcp): read the file here instead of passing content."
}
},
"required": [
"filename"
]
}🟢vdb_lookup(id)
Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string"
}
},
"required": [
"id"
]
}🟢vdb_search(query, limit)
Free-text search over the VDB vulnerability corpus.
Input Schema
{
"type": "object",
"properties": {
"query": {
"type": "string"
},
"limit": {
"type": "integer",
"default": 20
}
},
"required": [
"query"
]
}🟢vdb_check_mcp_server(server_id)
BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.
Input Schema
{
"type": "object",
"properties": {
"server_id": {
"type": "string",
"description": "e.g. 'mcp:community/shell-runner'"
}
},
"required": [
"server_id"
]
}🟢vdb_list_slopsquatting(ecosystem, limit)
List packages currently flagged as slopsquatting candidates in a given ecosystem.
Input Schema
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"description": "npm | PyPI | crates.io | Go | Maven"
},
"limit": {
"type": "integer",
"default": 50
}
}
}Community
Evidence