Security Intel MCP
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"cve-vulnerability-lookup": {
"url": "https://security.datakoot.com/mcp"
}
}
}Puntos de conexión remotos
https://security.datakoot.com/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (5)
🟡cve_lookup(cve_id)
Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.
Esquema de entrada
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "e.g. CVE-2021-44228"
}
},
"required": [
"cve_id"
]
}🟢known_exploited(cve_id, limit, vendor, ransomware_only)
Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.
Esquema de entrada
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "Optional. Check a single CVE, e.g. CVE-2021-44228."
},
"limit": {
"type": "number",
"description": "When listing, how many newest entries to return (default 20, max 100)."
},
"vendor": {
"type": "string",
"description": "Optional. Filter by vendor or product name substring."
},
"ransomware_only": {
"type": "boolean",
"description": "Optional. Only vulns CISA links to known ransomware campaigns."
}
},
"required": []
}🟢epss_score(cve_id, cve_ids)
Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.
Esquema de entrada
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "A single CVE id."
},
"cve_ids": {
"type": "array",
"items": {
"type": "string"
},
"description": "Multiple CVE ids (or pass a comma-separated string)."
}
},
"required": []
}🟢package_vulnerabilities(ecosystem, name, version)
List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.
Esquema de entrada
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"description": "Package registry to look in. One of: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex."
},
"name": {
"type": "string",
"description": "Exact package name as published in that registry, e.g. lodash for npm, requests for pypi."
},
"version": {
"type": "string",
"description": "Optional; if given, only vulns affecting that version are returned"
}
},
"required": [
"ecosystem",
"name"
]
}⚪audit_dependencies(manifest, dependencies, ecosystem)
Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.
Esquema de entrada
{
"type": "object",
"properties": {
"manifest": {
"type": "string",
"description": "Raw package.json contents"
},
"dependencies": {
"type": "array",
"items": {
"type": "object"
},
"description": "[{name, version}] entries"
},
"ecosystem": {
"type": "string",
"description": "Default npm"
}
},
"required": []
}Comunidad
Evidencia