vdb

Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.

我该使用它吗

质量与安全性

A
描述质量
94%
模式完整度
91%
命名质量
80%
投毒风险
80%
权限匹配度
100%
协议合规性
100%

发现(2)

  • HIGHTool poisoning patterns detected
  • INFOTool description contains placeholder or incomplete text在 vdb_lookup 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~785token 数(工具定义)
~534 B典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.61%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "vdb": {
      "command": "uvx",
      "args": [
        "vdb-mcp"
      ]
    }
  }
}

可运行的软件包

pypivdb-mcp0.2.6stdio

远程端点

https://vdb.ai.kr/mcpstreamable-http

它能做什么

工具清单

工具(7)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟡vdb_check_package(purl, version)

BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.

输入模式

{
  "type": "object",
  "properties": {
    "purl": {
      "type": "string",
      "description": "Package URL, e.g. 'pkg:npm/lodash' or 'pkg:pypi/requests'"
    },
    "version": {
      "type": "string",
      "description": "Optional version. If supplied, range matching is applied."
    }
  },
  "required": [
    "purl"
  ]
}
🟡vdb_check_packages(packages)

Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.

输入模式

{
  "type": "object",
  "properties": {
    "packages": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "List of PURLs or 'ecosystem/name' shorthand."
    }
  },
  "required": [
    "packages"
  ]
}
⚪vdb_scan_lockfile(filename, content, path)

BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.

输入模式

{
  "type": "object",
  "properties": {
    "filename": {
      "type": "string",
      "description": "e.g. 'package-lock.json' — the format is detected from it"
    },
    "content": {
      "type": "string",
      "description": "The file's text."
    },
    "path": {
      "type": "string",
      "description": "Local runs only (uvx vdb-mcp): read the file here instead of passing content."
    }
  },
  "required": [
    "filename"
  ]
}
🟢vdb_lookup(id)

Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).

输入模式

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string"
    }
  },
  "required": [
    "id"
  ]
}
🟢vdb_search(query, limit)

Free-text search over the VDB vulnerability corpus.

输入模式

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string"
    },
    "limit": {
      "type": "integer",
      "default": 20
    }
  },
  "required": [
    "query"
  ]
}
🟢vdb_check_mcp_server(server_id)

BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.

输入模式

{
  "type": "object",
  "properties": {
    "server_id": {
      "type": "string",
      "description": "e.g. 'mcp:community/shell-runner'"
    }
  },
  "required": [
    "server_id"
  ]
}
🟢vdb_list_slopsquatting(ecosystem, limit)

List packages currently flagged as slopsquatting candidates in a given ecosystem.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "npm | PyPI | crates.io | Go | Maven"
    },
    "limit": {
      "type": "integer",
      "default": 50
    }
  }
}

社区

评价此服务器

证据

最近观测

已验证未记录版本7 个工具