vdb

Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.

我該用這個嗎

品質與安全性

A
說明品質
94%
結構描述完整度
91%
命名品質
80%
汙染風險
80%
權限相符程度
100%
協定合規性
100%

發現項目(2)

  • HIGHTool poisoning patterns detected
  • INFOTool description contains placeholder or incomplete text在 vdb_lookup 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~785Token(工具定義)
~534 B典型回應大小
中等的注意力影響(128k 上下文的 0.61%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "vdb": {
      "command": "uvx",
      "args": [
        "vdb-mcp"
      ]
    }
  }
}

可執行的套件

pypivdb-mcp0.2.6stdio

遠端端點

https://vdb.ai.kr/mcpstreamable-http

它能做什麼

工具清單

工具(7)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟡vdb_check_package(purl, version)

BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.

輸入結構描述

{
  "type": "object",
  "properties": {
    "purl": {
      "type": "string",
      "description": "Package URL, e.g. 'pkg:npm/lodash' or 'pkg:pypi/requests'"
    },
    "version": {
      "type": "string",
      "description": "Optional version. If supplied, range matching is applied."
    }
  },
  "required": [
    "purl"
  ]
}
🟡vdb_check_packages(packages)

Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.

輸入結構描述

{
  "type": "object",
  "properties": {
    "packages": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "List of PURLs or 'ecosystem/name' shorthand."
    }
  },
  "required": [
    "packages"
  ]
}
⚪vdb_scan_lockfile(filename, content, path)

BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.

輸入結構描述

{
  "type": "object",
  "properties": {
    "filename": {
      "type": "string",
      "description": "e.g. 'package-lock.json' — the format is detected from it"
    },
    "content": {
      "type": "string",
      "description": "The file's text."
    },
    "path": {
      "type": "string",
      "description": "Local runs only (uvx vdb-mcp): read the file here instead of passing content."
    }
  },
  "required": [
    "filename"
  ]
}
🟢vdb_lookup(id)

Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).

輸入結構描述

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string"
    }
  },
  "required": [
    "id"
  ]
}
🟢vdb_search(query, limit)

Free-text search over the VDB vulnerability corpus.

輸入結構描述

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string"
    },
    "limit": {
      "type": "integer",
      "default": 20
    }
  },
  "required": [
    "query"
  ]
}
🟢vdb_check_mcp_server(server_id)

BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.

輸入結構描述

{
  "type": "object",
  "properties": {
    "server_id": {
      "type": "string",
      "description": "e.g. 'mcp:community/shell-runner'"
    }
  },
  "required": [
    "server_id"
  ]
}
🟢vdb_list_slopsquatting(ecosystem, limit)

List packages currently flagged as slopsquatting candidates in a given ecosystem.

輸入結構描述

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "npm | PyPI | crates.io | Go | Maven"
    },
    "limit": {
      "type": "integer",
      "default": 50
    }
  }
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本7 個工具