vulnrable

Security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS.

使うべきか

品質と安全性

A
説明の品質
90%
スキーマの完全性
88%
命名の品質
95%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~435トークン数(ツール定義)
~645 B一般的なレスポンスサイズ
注意への影響は最小限(128k コンテキストの 0.34%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "vulnrable": {
      "url": "https://vulnrable.com/api/mcp"
    }
  }
}

リモートエンドポイント

https://vulnrable.com/api/mcpstreamable-http

できること

ツール一覧

ツール(4)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢check_package(name, ecosystem)

Security assessment of one npm or PyPI package: letter grade, findings, known vulnerabilities, deprecation status, and — for MCP servers in our directory — the real resolved dependency count. Use before recommending or installing a package.

入力スキーマ

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "maxLength": 214,
      "description": "Exact package name"
    },
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "PyPI"
      ]
    }
  },
  "required": [
    "name",
    "ecosystem"
  ]
}
🟢list_mcp_servers(sort_by, understates_only)

The MCP server directory with real resolved dependency counts. Use when recommending an MCP server, or to compare how much third-party code candidates pull into the agent. For a graded security assessment of one server, call check_package.

入力スキーマ

{
  "type": "object",
  "properties": {
    "sort_by": {
      "type": "string",
      "enum": [
        "total_packages",
        "name"
      ],
      "default": "total_packages",
      "description": "total_packages sorts heaviest first"
    },
    "understates_only": {
      "type": "boolean",
      "default": false,
      "description": "Only servers whose count understates real surface (mostly prebuilt binaries)"
    }
  }
}
🟢check_cve(id)

Details for one CVE or GHSA identifier, including whether CISA lists it as actively exploited (KEV) and its EPSS exploitation probability. Use to judge real-world urgency.

入力スキーマ

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "e.g. CVE-2024-3094 or GHSA-xxxx-xxxx-xxxx"
    }
  },
  "required": [
    "id"
  ]
}
⚪latest_vulns(limit, kev_only, min_severity)

Recently published vulnerabilities from the tracked pool, ranked KEV-first then by EPSS. Use for "what should I worry about this week".

入力スキーマ

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 25,
      "default": 10
    },
    "kev_only": {
      "type": "boolean",
      "default": false
    },
    "min_severity": {
      "type": "string",
      "enum": [
        "LOW",
        "MEDIUM",
        "HIGH",
        "CRITICAL"
      ]
    }
  }
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 4 件