MCP 서버

sectora

io.github.megabrainee/sectora
보안 공개 · 연결 가능 MCP 2026-07-28

이 MCP로 할 수 있는 일

Provides vulnerability intelligence, dependency and technology risk checks, IP reputation, DAST scans, and security findings management.

assess_dependency
Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity, fixed versions, and references. Free tier eligible.
입력 스키마
{'type': 'object', 'required': ['name', 'version', 'ecosystem'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'description': 'Package name (e.g., "lodash", "django", "github.com/gorilla/mux")'}, 'version': {'type': 'string', 'maxLength': 50, 'description': 'Exact version (e.g., "4.17.20")'}, 'ecosystem': {'type': 'string', 'maxLength': 20, 'description': 'Package ecosystem: npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io'}}}
assess_tech_risk
Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only.
입력 스키마
{'type': 'object', 'required': ['technologies'], 'properties': {'technologies': {'type': 'string', 'pattern': '^[a-zA-Z0-9.,\\s\\-/()@]+$', 'maxLength': 2000, 'description': 'Comma-separated list of technology names (e.g., "Apache HTTP Server, OpenSSL, nginx"). Max 50 technologies.'}}}
get_kev_recent
Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog.
입력 스키마
{'type': 'object', 'properties': {'days': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Number of days to look back (1-365, default: 30)'}}}
get_my_posture
Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TLS, etc.), and edge_health (whether Shield is actually intercepting traffic). Requires API key.
입력 스키마
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'pattern': '^[a-z0-9.-]+$', 'maxLength': 253, 'description': 'Domain registered under your Sectora account'}}}
get_scan
Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key.
입력 스키마
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'pattern': '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$', 'maxLength': 36, 'description': 'Scan UUID'}}}
get_threat_stats
Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required.
입력 스키마
{'type': 'object', 'properties': {}}
get_trending_cves
Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Maximum results to return (1-100, default: 20)'}}}
get_weaponization_score
Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID.
입력 스키마
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
list_my_findings
List the API key owner's open security findings across all scans. Use this to answer "what's my current exposure?" Filter by severity, status, or domain. Returns finding summaries; call get_scan for full detail. Requires API key.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max findings (1-100, default: 25)'}, 'domain': {'type': 'string', 'maxLength': 253, 'description': 'Limit to a single domain (e.g., app.example.com)'}, 'status': {'enum': ['open', 'confirmed'], 'type': 'string', 'description': 'Filter by confirmation status'}, 'severity': {'type': 'string', 'maxLength': 50, 'description': 'Comma-separated severities to include: critical, high, medium, low, info'}}}
list_my_scans
List the API key owner's recent scans with summary counts. Requires API key.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max scans (1-100, default: 25)'}, 'status': {'type': 'string', 'maxLength': 20, 'description': 'Filter by status (queued, running, completed, failed)'}}}
lookup_cve
Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE ID.
입력 스키마
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
lookup_ip_reputation
Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both).
입력 스키마
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'pattern': '^(\\d{1,3}(\\.\\d{1,3}){3}|[0-9A-Fa-f:]{2,45})$', 'maxLength': 45, 'description': 'IPv4 (e.g., 1.2.3.4) or IPv6 (e.g., 2606:4700::1) address to look up'}}}
scan_url
Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calling again with confirm:true to actually start the scan. Returns scan_id; poll status with get_scan. Domain must be verified in the Sectora account. Daily quota: 25 scans/24h per user. Requires API key.
입력 스키마
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 2048, 'description': 'Full URL to scan (must start with http:// or https://)'}, 'confirm': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Set to "true" to actually execute the scan. Without this, the call returns a preview only.'}, 'profile': {'enum': ['quick', 'standard', 'deep'], 'type': 'string', 'description': 'Scan profile: quick (~2 min), standard (~10 min), deep (~30 min)'}}}
search_cves
Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text.
입력 스키마
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 200, 'description': 'Search keyword (CVE ID, technology name, or description)'}, 'is_kev': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs in CISA KEV catalog'}, 'severity': {'enum': ['CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'description': 'Filter by severity'}, 'has_exploit': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs with public exploits'}}}
추가됨
assess_dependency
2026년 9월 17일 12:45 PM
추가됨
get_my_posture
2026년 9월 17일 12:45 PM
추가됨
scan_url
2026년 9월 17일 12:45 PM
추가됨
get_scan
2026년 9월 17일 12:45 PM
추가됨
list_my_scans
2026년 9월 17일 12:45 PM
추가됨
list_my_findings
2026년 9월 17일 12:45 PM
추가됨
get_threat_stats
2026년 9월 17일 12:45 PM
추가됨
lookup_ip_reputation
2026년 9월 17일 12:45 PM
추가됨
get_weaponization_score
2026년 9월 17일 12:45 PM
추가됨
get_trending_cves
2026년 9월 17일 12:45 PM
추가됨
get_kev_recent
2026년 9월 17일 12:45 PM
추가됨
search_cves
2026년 9월 17일 12:45 PM
추가됨
assess_tech_risk
2026년 9월 17일 12:45 PM
추가됨
lookup_cve
2026년 9월 17일 12:45 PM