sectora

Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.

我該用這個嗎

品質與安全性

A
說明品質
97%
結構描述完整度
92%
命名品質
96%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,834Token(工具定義)
~811 B典型回應大小
中等的注意力影響(128k 上下文的 1.43%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "sectora": {
      "url": "https://mcp.sectora.io/mcp"
    }
  }
}

遠端端點

https://mcp.sectora.io/mcpstreamable-http

它能做什麼

工具清單

工具(14)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢lookup_cve(cve_id)

Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE ID.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)",
      "pattern": "^CVE-\\d{4}-\\d{4,}$",
      "maxLength": 20
    }
  },
  "required": [
    "cve_id"
  ]
}
🟢assess_tech_risk(technologies)

Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only.

輸入結構描述

{
  "type": "object",
  "properties": {
    "technologies": {
      "type": "string",
      "description": "Comma-separated list of technology names (e.g., \"Apache HTTP Server, OpenSSL, nginx\"). Max 50 technologies.",
      "pattern": "^[a-zA-Z0-9.,\\s\\-/()@]+$",
      "maxLength": 2000
    }
  },
  "required": [
    "technologies"
  ]
}
🟢search_cves(query, severity, is_kev, has_exploit)

Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text.

輸入結構描述

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Search keyword (CVE ID, technology name, or description)",
      "maxLength": 200
    },
    "severity": {
      "type": "string",
      "description": "Filter by severity",
      "enum": [
        "CRITICAL",
        "HIGH",
        "MEDIUM",
        "LOW"
      ]
    },
    "is_kev": {
      "type": "string",
      "description": "Only show CVEs in CISA KEV catalog",
      "enum": [
        "true",
        "false"
      ]
    },
    "has_exploit": {
      "type": "string",
      "description": "Only show CVEs with public exploits",
      "enum": [
        "true",
        "false"
      ]
    }
  },
  "required": [
    "query"
  ]
}
🟢get_kev_recent(days)

Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog.

輸入結構描述

{
  "type": "object",
  "properties": {
    "days": {
      "type": "string",
      "description": "Number of days to look back (1-365, default: 30)",
      "pattern": "^\\d{1,3}$",
      "maxLength": 3
    }
  }
}
🟢get_trending_cves(limit)

Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability.

輸入結構描述

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "string",
      "description": "Maximum results to return (1-100, default: 20)",
      "pattern": "^\\d{1,3}$",
      "maxLength": 3
    }
  }
}
🟢get_weaponization_score(cve_id)

Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve_id": {
      "type": "string",
      "description": "CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)",
      "pattern": "^CVE-\\d{4}-\\d{4,}$",
      "maxLength": 20
    }
  },
  "required": [
    "cve_id"
  ]
}
⚪lookup_ip_reputation(ip)

Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both).

輸入結構描述

{
  "type": "object",
  "properties": {
    "ip": {
      "type": "string",
      "description": "IPv4 (e.g., 1.2.3.4) or IPv6 (e.g., 2606:4700::1) address to look up",
      "pattern": "^(\\d{1,3}(\\.\\d{1,3}){3}|[0-9A-Fa-f:]{2,45})$",
      "maxLength": 45
    }
  },
  "required": [
    "ip"
  ]
}
🟢get_threat_stats

Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required.

輸入結構描述

{
  "type": "object",
  "properties": {}
}
🟢list_my_findings(severity, status, domain, limit)

List the API key owner's open security findings across all scans. Use this to answer "what's my current exposure?" Filter by severity, status, or domain. Returns finding summaries; call get_scan for full detail. Requires API key.

輸入結構描述

{
  "type": "object",
  "properties": {
    "severity": {
      "type": "string",
      "description": "Comma-separated severities to include: critical, high, medium, low, info",
      "maxLength": 50
    },
    "status": {
      "type": "string",
      "description": "Filter by confirmation status",
      "enum": [
        "open",
        "confirmed"
      ]
    },
    "domain": {
      "type": "string",
      "description": "Limit to a single domain (e.g., app.example.com)",
      "maxLength": 253
    },
    "limit": {
      "type": "string",
      "description": "Max findings (1-100, default: 25)",
      "pattern": "^\\d{1,3}$",
      "maxLength": 3
    }
  }
}
🟢list_my_scans(limit, status)

List the API key owner's recent scans with summary counts. Requires API key.

輸入結構描述

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "string",
      "description": "Max scans (1-100, default: 25)",
      "pattern": "^\\d{1,3}$",
      "maxLength": 3
    },
    "status": {
      "type": "string",
      "description": "Filter by status (queued, running, completed, failed)",
      "maxLength": 20
    }
  }
}
🟢get_scan(scan_id)

Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key.

輸入結構描述

{
  "type": "object",
  "properties": {
    "scan_id": {
      "type": "string",
      "description": "Scan UUID",
      "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
      "maxLength": 36
    }
  },
  "required": [
    "scan_id"
  ]
}
🟢scan_url(url, profile, confirm)

Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calling again with confirm:true to actually start the scan. Returns scan_id; poll status with get_scan. Domain must be verified in the Sectora account. Daily quota: 25 scans/24h per user. Requires API key.

輸入結構描述

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Full URL to scan (must start with http:// or https://)",
      "maxLength": 2048
    },
    "profile": {
      "type": "string",
      "description": "Scan profile: quick (~2 min), standard (~10 min), deep (~30 min)",
      "enum": [
        "quick",
        "standard",
        "deep"
      ]
    },
    "confirm": {
      "type": "string",
      "description": "Set to \"true\" to actually execute the scan. Without this, the call returns a preview only.",
      "enum": [
        "true",
        "false"
      ]
    }
  },
  "required": [
    "url"
  ]
}
🟢get_my_posture(domain)

Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TLS, etc.), and edge_health (whether Shield is actually intercepting traffic). Requires API key.

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain registered under your Sectora account",
      "pattern": "^[a-z0-9.-]+$",
      "maxLength": 253
    }
  },
  "required": [
    "domain"
  ]
}
🟢assess_dependency(name, version, ecosystem)

Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity, fixed versions, and references. Free tier eligible.

輸入結構描述

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Package name (e.g., \"lodash\", \"django\", \"github.com/gorilla/mux\")",
      "maxLength": 200
    },
    "version": {
      "type": "string",
      "description": "Exact version (e.g., \"4.17.20\")",
      "maxLength": 50
    },
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem: npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io",
      "maxLength": 20
    }
  },
  "required": [
    "name",
    "version",
    "ecosystem"
  ]
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本14 個工具
已驗證未記錄版本14 個工具