Serveur MCP

endoflife.ai — Software Lifecycle Intelligence

io.github.endoflife-ai/endoflife-mcp
Outils développeur Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Checks software end-of-life status, lifecycle schedules, upgrade paths, SBOM component risk, CISA KEV exposure, edge-device support, and stack risk.

check_eol
Check end-of-life status
Check whether a specific version of a software product is end-of-life (EOL). Returns lifecycle status, the EOL date, days remaining or days past EOL, the latest release, and eol_date_source (where the date comes from: vendor-override, vendor-fetched, vendor-verified, custom, upstream, or discrepancy) with its source URL. Use this for "is X version Y still supported?" questions.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['product', 'version'], 'properties': {'product': {'type': 'string', 'description': 'Product slug or name, e.g. "postgresql", "nodejs", "ubuntu".'}, 'version': {'type': 'string', 'description': 'Version/cycle, e.g. "14", "18", "20.04".'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
check_sbom
Check an SBOM
Audit a CycloneDX or SPDX JSON software bill of materials. Components are mapped to tracked products and scored for EOL risk; unmatched components are listed honestly rather than guessed. Pass the SBOM as a JSON string or object. Free tier scores up to 5 matched components per call; Pro up to 50.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['sbom'], 'properties': {'sbom': {'description': 'The SBOM document (JSON string or object). CycloneDX (bomFormat/components) or SPDX (spdxVersion/packages).'}, 'max_items': {'type': 'integer', 'description': 'Maximum matched components to score (default 50).'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
get_edge_device_status
EOS Edge Device status
Query the EOS Edge Device Intelligence feed — firewalls, VPN gateways and appliances, ADCs, router and switch operating systems — with end-of-support status in the vocabulary of CISA BOD 26-02 (eos, within-12-months, scheduled, no-date-announced). Filter by platform or vendor name, by status, or by model/line. Each platform carries its KEV summary, vendor-stated successor and provenance. Use for "which of our edge devices are past support or expire within 12 months?".
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'model': {'type': 'string', 'description': 'Optional substring matched against the line / model name, e.g. "ISA6000", "7.2", "SMA 100".'}, 'status': {'enum': ['eos', 'within-12-months', 'scheduled', 'no-date-announced'], 'type': 'string', 'description': 'Optional status filter.'}, 'platform': {'type': 'string', 'description': 'Optional substring matched against platform slug, name, vendor or category, e.g. "fortinet", "ivanti", "vpn".'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
get_kev_exposure
CISA KEV exposure
The exploited-vulnerability record for a product: every CVE CISA lists against it in the Known Exploited Vulnerabilities catalog, with the date added, the federal due date and CISA's required-action text verbatim (the "discontinue use" entries are the ones that matter for end-of-life versions), plus any entries from endoflife.ai's Exploited & Unpatchable feed (exploited CVEs whose affected versions will never receive a fix). Pass an optional version to include its support status alongside.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['product'], 'properties': {'product': {'type': 'string', 'description': 'Product slug or name, e.g. "ivanti-connect-secure", "fortios".'}, 'version': {'type': 'string', 'description': 'Optional version/cycle to check support status for.'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
get_product_lifecycle
Full lifecycle table
Get the full version history for one product: every tracked version/cycle with its release date, EOL date, support status, and EOL Risk Score. Use for "give me the whole EOL schedule for X".
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['product'], 'properties': {'product': {'type': 'string', 'description': 'Product slug or name, e.g. "postgresql".'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
get_risk_score
EOL Risk Score
Get the proprietary EOL Risk Score (0-100) for a product version, with the four-factor breakdown (EOL recency, attack surface, CISA KEV exposure, extended support). Omit "version" to score the product's highest-risk (most recently end-of-lifed) release. Use this to quantify how dangerous it is to keep running something.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['product'], 'properties': {'product': {'type': 'string', 'description': 'Product slug or name, e.g. "openssl", "python".'}, 'version': {'type': 'string', 'description': 'Optional version/cycle. Omit for the highest-risk release.'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
get_upcoming_eol
Upcoming end-of-life calendar
What reaches end-of-life soon. Returns every tracked version whose EOL date falls within the next N days (default 90), optionally limited to a list of products, sorted by date. Also lists versions that went EOL within the last "recent_past_days" days when set. Use for "what in our stack expires this quarter?".
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'days': {'type': 'integer', 'description': 'Look-ahead window in days (default 90, max 730).'}, 'products': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional product slugs or names to restrict to (max 50). Omit for the whole catalog.'}, 'recent_past_days': {'type': 'integer', 'description': 'Also include versions that went EOL within this many days in the past (default 0).'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
get_upgrade_path
Upgrade path
Where to move a product version: the current version's support status and score, the supported releases with the longest remaining support, endoflife.ai's recommended target, and the vendor's stated successor where one is published (edge appliances). Use after check_eol says a version is EOL.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['product'], 'properties': {'product': {'type': 'string', 'description': 'Product slug or name.'}, 'version': {'type': 'string', 'description': 'Optional current version/cycle.'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
list_products
Find a product slug
List or search the products endoflife.ai tracks (500+). Pass an optional "query" substring to find the canonical slug for a product before calling the other tools (e.g. "postgres" → "postgresql"). Returns matching product slugs.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'query': {'type': 'string', 'description': 'Optional case-insensitive substring filter.'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
scan_stack
Scan a stack
Audit a whole stack at once. Provide a list of products (optionally with versions) — e.g. parsed from a package.json or Dockerfile — and get an EOL Risk Score for each, so you can see what is unsupported and dangerous in one call. For CycloneDX or SPDX documents use check_sbom instead. Free tier: up to 5 items; Pro: up to 50.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['items'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object', 'required': ['product'], 'properties': {'product': {'type': 'string', 'description': 'Product slug or name.'}, 'version': {'type': 'string', 'description': 'Optional version/cycle. Omit for highest-risk release.'}}}, 'description': 'List of stack components to score.'}}}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
Ajouté
check_sbom
17 September 2026 12:41
Ajouté
get_upgrade_path
17 September 2026 12:41
Ajouté
get_edge_device_status
17 September 2026 12:41
Ajouté
get_upcoming_eol
17 September 2026 12:41
Ajouté
get_kev_exposure
17 September 2026 12:41
Ajouté
get_product_lifecycle
17 September 2026 12:41
Ajouté
list_products
17 September 2026 12:41
Ajouté
scan_stack
17 September 2026 12:41
Ajouté
get_risk_score
17 September 2026 12:41
Ajouté
check_eol
17 September 2026 12:41

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…