vulnrable
Security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"vulnrable": {
"url": "https://vulnrable.com/api/mcp"
}
}
}远程端点
https://vulnrable.com/api/mcpstreamable-http它能做什么
工具清单
工具(4)
🟢check_package(name, ecosystem)
Security assessment of one npm or PyPI package: letter grade, findings, known vulnerabilities, deprecation status, and — for MCP servers in our directory — the real resolved dependency count. Use before recommending or installing a package.
输入模式
{
"type": "object",
"properties": {
"name": {
"type": "string",
"maxLength": 214,
"description": "Exact package name"
},
"ecosystem": {
"type": "string",
"enum": [
"npm",
"PyPI"
]
}
},
"required": [
"name",
"ecosystem"
]
}🟢list_mcp_servers(sort_by, understates_only)
The MCP server directory with real resolved dependency counts. Use when recommending an MCP server, or to compare how much third-party code candidates pull into the agent. For a graded security assessment of one server, call check_package.
输入模式
{
"type": "object",
"properties": {
"sort_by": {
"type": "string",
"enum": [
"total_packages",
"name"
],
"default": "total_packages",
"description": "total_packages sorts heaviest first"
},
"understates_only": {
"type": "boolean",
"default": false,
"description": "Only servers whose count understates real surface (mostly prebuilt binaries)"
}
}
}🟢check_cve(id)
Details for one CVE or GHSA identifier, including whether CISA lists it as actively exploited (KEV) and its EPSS exploitation probability. Use to judge real-world urgency.
输入模式
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "e.g. CVE-2024-3094 or GHSA-xxxx-xxxx-xxxx"
}
},
"required": [
"id"
]
}⚪latest_vulns(limit, kev_only, min_severity)
Recently published vulnerabilities from the tracked pool, ranked KEV-first then by EPSS. Use for "what should I worry about this week".
输入模式
{
"type": "object",
"properties": {
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 25,
"default": 10
},
"kev_only": {
"type": "boolean",
"default": false
},
"min_severity": {
"type": "string",
"enum": [
"LOW",
"MEDIUM",
"HIGH",
"CRITICAL"
]
}
}
}社区
证据