Security Intel MCP
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"cve-vulnerability-lookup": {
"url": "https://security.datakoot.com/mcp"
}
}
}원격 엔드포인트
https://security.datakoot.com/mcpstreamable-http할 수 있는 일
도구 목록
도구 (5)
🟡cve_lookup(cve_id)
Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.
입력 스키마
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "e.g. CVE-2021-44228"
}
},
"required": [
"cve_id"
]
}🟢known_exploited(cve_id, limit, vendor, ransomware_only)
Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.
입력 스키마
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "Optional. Check a single CVE, e.g. CVE-2021-44228."
},
"limit": {
"type": "number",
"description": "When listing, how many newest entries to return (default 20, max 100)."
},
"vendor": {
"type": "string",
"description": "Optional. Filter by vendor or product name substring."
},
"ransomware_only": {
"type": "boolean",
"description": "Optional. Only vulns CISA links to known ransomware campaigns."
}
},
"required": []
}🟢epss_score(cve_id, cve_ids)
Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.
입력 스키마
{
"type": "object",
"properties": {
"cve_id": {
"type": "string",
"description": "A single CVE id."
},
"cve_ids": {
"type": "array",
"items": {
"type": "string"
},
"description": "Multiple CVE ids (or pass a comma-separated string)."
}
},
"required": []
}🟢package_vulnerabilities(ecosystem, name, version)
List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.
입력 스키마
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"description": "Package registry to look in. One of: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex."
},
"name": {
"type": "string",
"description": "Exact package name as published in that registry, e.g. lodash for npm, requests for pypi."
},
"version": {
"type": "string",
"description": "Optional; if given, only vulns affecting that version are returned"
}
},
"required": [
"ecosystem",
"name"
]
}⚪audit_dependencies(manifest, dependencies, ecosystem)
Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.
입력 스키마
{
"type": "object",
"properties": {
"manifest": {
"type": "string",
"description": "Raw package.json contents"
},
"dependencies": {
"type": "array",
"items": {
"type": "object"
},
"description": "[{name, version}] entries"
},
"ecosystem": {
"type": "string",
"description": "Default npm"
}
},
"required": []
}커뮤니티
증거