Security Intel MCP

CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
94%
命名品質
84%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~774Token(工具定義)
~925 B典型回應大小
中等的注意力影響(128k 上下文的 0.60%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "cve-vulnerability-lookup": {
      "url": "https://security.datakoot.com/mcp"
    }
  }
}

遠端端點

https://security.datakoot.com/mcpstreamable-http

它能做什麼

工具清單

工具(5)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟡cve_lookup(cve_id)

Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "e.g. CVE-2021-44228"
    }
  },
  "required": [
    "cve_id"
  ]
}
🟢known_exploited(cve_id, limit, vendor, ransomware_only)

Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "Optional. Check a single CVE, e.g. CVE-2021-44228."
    },
    "limit": {
      "type": "number",
      "description": "When listing, how many newest entries to return (default 20, max 100)."
    },
    "vendor": {
      "type": "string",
      "description": "Optional. Filter by vendor or product name substring."
    },
    "ransomware_only": {
      "type": "boolean",
      "description": "Optional. Only vulns CISA links to known ransomware campaigns."
    }
  },
  "required": []
}
🟢epss_score(cve_id, cve_ids)

Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "A single CVE id."
    },
    "cve_ids": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Multiple CVE ids (or pass a comma-separated string)."
    }
  },
  "required": []
}
🟢package_vulnerabilities(ecosystem, name, version)

List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.

輸入結構描述

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package registry to look in. One of: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex."
    },
    "name": {
      "type": "string",
      "description": "Exact package name as published in that registry, e.g. lodash for npm, requests for pypi."
    },
    "version": {
      "type": "string",
      "description": "Optional; if given, only vulns affecting that version are returned"
    }
  },
  "required": [
    "ecosystem",
    "name"
  ]
}
⚪audit_dependencies(manifest, dependencies, ecosystem)

Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.

輸入結構描述

{
  "type": "object",
  "properties": {
    "manifest": {
      "type": "string",
      "description": "Raw package.json contents"
    },
    "dependencies": {
      "type": "array",
      "items": {
        "type": "object"
      },
      "description": "[{name, version}] entries"
    },
    "ecosystem": {
      "type": "string",
      "description": "Default npm"
    }
  },
  "required": []
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本5 個工具
已驗證未記錄版本5 個工具