endoflife.ai — Software Lifecycle Intelligence
EOL dates, risk scores, CISA KEV exposure, SBOM audits and edge-device EOS for 500+ products.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"endoflife-mcp": {
"url": "https://mcp.endoflife.ai"
}
}
}遠端端點
https://mcp.endoflife.aistreamable-http它能做什麼
工具清單
工具(10)
🟢check_eol(product, version)
Check whether a specific version of a software product is end-of-life (EOL). Returns lifecycle status, the EOL date, days remaining or days past EOL, the latest release, and eol_date_source (where the date comes from: vendor-override, vendor-fetched, vendor-verified, custom, upstream, or discrepancy) with its source URL. Use this for "is X version Y still supported?" questions.
輸入結構描述
{
"type": "object",
"properties": {
"product": {
"type": "string",
"description": "Product slug or name, e.g. \"postgresql\", \"nodejs\", \"ubuntu\"."
},
"version": {
"type": "string",
"description": "Version/cycle, e.g. \"14\", \"18\", \"20.04\"."
}
},
"required": [
"product",
"version"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_risk_score(product, version)
Get the proprietary EOL Risk Score (0-100) for a product version, with the four-factor breakdown (EOL recency, attack surface, CISA KEV exposure, extended support). Omit "version" to score the product's highest-risk (most recently end-of-lifed) release. Use this to quantify how dangerous it is to keep running something.
輸入結構描述
{
"type": "object",
"properties": {
"product": {
"type": "string",
"description": "Product slug or name, e.g. \"openssl\", \"python\"."
},
"version": {
"type": "string",
"description": "Optional version/cycle. Omit for the highest-risk release."
}
},
"required": [
"product"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢scan_stack(items)
Audit a whole stack at once. Provide a list of products (optionally with versions) — e.g. parsed from a package.json or Dockerfile — and get an EOL Risk Score for each, so you can see what is unsupported and dangerous in one call. For CycloneDX or SPDX documents use check_sbom instead. Free tier: up to 5 items; Pro: up to 50.
輸入結構描述
{
"type": "object",
"properties": {
"items": {
"type": "array",
"description": "List of stack components to score.",
"items": {
"type": "object",
"properties": {
"product": {
"type": "string",
"description": "Product slug or name."
},
"version": {
"type": "string",
"description": "Optional version/cycle. Omit for highest-risk release."
}
},
"required": [
"product"
]
}
}
},
"required": [
"items"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢list_products(query)
List or search the products endoflife.ai tracks (500+). Pass an optional "query" substring to find the canonical slug for a product before calling the other tools (e.g. "postgres" → "postgresql"). Returns matching product slugs.
輸入結構描述
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Optional case-insensitive substring filter."
}
},
"required": []
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_product_lifecycle(product)
Get the full version history for one product: every tracked version/cycle with its release date, EOL date, support status, and EOL Risk Score. Use for "give me the whole EOL schedule for X".
輸入結構描述
{
"type": "object",
"properties": {
"product": {
"type": "string",
"description": "Product slug or name, e.g. \"postgresql\"."
}
},
"required": [
"product"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_kev_exposure(product, version)
The exploited-vulnerability record for a product: every CVE CISA lists against it in the Known Exploited Vulnerabilities catalog, with the date added, the federal due date and CISA's required-action text verbatim (the "discontinue use" entries are the ones that matter for end-of-life versions), plus any entries from endoflife.ai's Exploited & Unpatchable feed (exploited CVEs whose affected versions will never receive a fix). Pass an optional version to include its support status alongside.
輸入結構描述
{
"type": "object",
"properties": {
"product": {
"type": "string",
"description": "Product slug or name, e.g. \"ivanti-connect-secure\", \"fortios\"."
},
"version": {
"type": "string",
"description": "Optional version/cycle to check support status for."
}
},
"required": [
"product"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_upcoming_eol(products, days, recent_past_days)
What reaches end-of-life soon. Returns every tracked version whose EOL date falls within the next N days (default 90), optionally limited to a list of products, sorted by date. Also lists versions that went EOL within the last "recent_past_days" days when set. Use for "what in our stack expires this quarter?".
輸入結構描述
{
"type": "object",
"properties": {
"products": {
"type": "array",
"items": {
"type": "string"
},
"description": "Optional product slugs or names to restrict to (max 50). Omit for the whole catalog."
},
"days": {
"type": "integer",
"description": "Look-ahead window in days (default 90, max 730)."
},
"recent_past_days": {
"type": "integer",
"description": "Also include versions that went EOL within this many days in the past (default 0)."
}
},
"required": []
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_edge_device_status(platform, status, model)
Query the EOS Edge Device Intelligence feed — firewalls, VPN gateways and appliances, ADCs, router and switch operating systems — with end-of-support status in the vocabulary of CISA BOD 26-02 (eos, within-12-months, scheduled, no-date-announced). Filter by platform or vendor name, by status, or by model/line. Each platform carries its KEV summary, vendor-stated successor and provenance. Use for "which of our edge devices are past support or expire within 12 months?".
輸入結構描述
{
"type": "object",
"properties": {
"platform": {
"type": "string",
"description": "Optional substring matched against platform slug, name, vendor or category, e.g. \"fortinet\", \"ivanti\", \"vpn\"."
},
"status": {
"type": "string",
"enum": [
"eos",
"within-12-months",
"scheduled",
"no-date-announced"
],
"description": "Optional status filter."
},
"model": {
"type": "string",
"description": "Optional substring matched against the line / model name, e.g. \"ISA6000\", \"7.2\", \"SMA 100\"."
}
},
"required": []
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢get_upgrade_path(product, version)
Where to move a product version: the current version's support status and score, the supported releases with the longest remaining support, endoflife.ai's recommended target, and the vendor's stated successor where one is published (edge appliances). Use after check_eol says a version is EOL.
輸入結構描述
{
"type": "object",
"properties": {
"product": {
"type": "string",
"description": "Product slug or name."
},
"version": {
"type": "string",
"description": "Optional current version/cycle."
}
},
"required": [
"product"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢check_sbom(sbom, max_items)
Audit a CycloneDX or SPDX JSON software bill of materials. Components are mapped to tracked products and scored for EOL risk; unmatched components are listed honestly rather than guessed. Pass the SBOM as a JSON string or object. Free tier scores up to 5 matched components per call; Pro up to 50.
輸入結構描述
{
"type": "object",
"properties": {
"sbom": {
"description": "The SBOM document (JSON string or object). CycloneDX (bomFormat/components) or SPDX (spdxVersion/packages)."
},
"max_items": {
"type": "integer",
"description": "Maximum matched components to score (default 50)."
}
},
"required": [
"sbom"
]
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}社群
證據