MCP Server

Security Intel MCP

com.datakoot/cve-vulnerability-lookup
Developer Tools Security Public & reachable MCP 2026-07-28

What this MCP does

Looks up CVEs and exploitability signals and audits software dependency manifests for known vulnerabilities.

audit_dependencies
Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.
Input schema
{'type': 'object', 'required': [], 'properties': {'manifest': {'type': 'string', 'description': 'Raw package.json contents'}, 'ecosystem': {'type': 'string', 'description': 'Default npm'}, 'dependencies': {'type': 'array', 'items': {'type': 'object'}, 'description': '[{name, version}] entries'}}}
cve_lookup
Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.
Input schema
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'description': 'e.g. CVE-2021-44228'}}}
epss_score
Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.
Input schema
{'type': 'object', 'required': [], 'properties': {'cve_id': {'type': 'string', 'description': 'A single CVE id.'}, 'cve_ids': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Multiple CVE ids (or pass a comma-separated string).'}}}
known_exploited
Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.
Input schema
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'number', 'description': 'When listing, how many newest entries to return (default 20, max 100).'}, 'cve_id': {'type': 'string', 'description': 'Optional. Check a single CVE, e.g. CVE-2021-44228.'}, 'vendor': {'type': 'string', 'description': 'Optional. Filter by vendor or product name substring.'}, 'ransomware_only': {'type': 'boolean', 'description': 'Optional. Only vulns CISA links to known ransomware campaigns.'}}}
package_vulnerabilities
List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.
Input schema
{'type': 'object', 'required': ['ecosystem', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Exact package name as published in that registry, e.g. lodash for npm, requests for pypi.'}, 'version': {'type': 'string', 'description': 'Optional; if given, only vulns affecting that version are returned'}, 'ecosystem': {'type': 'string', 'description': 'Package registry to look in. One of: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.'}}}
Added
audit_dependencies
Sept. 17, 2026, 12:34 p.m.
Added
package_vulnerabilities
Sept. 17, 2026, 12:34 p.m.
Added
epss_score
Sept. 17, 2026, 12:34 p.m.
Added
known_exploited
Sept. 17, 2026, 12:34 p.m.
Added
cve_lookup
Sept. 17, 2026, 12:34 p.m.

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…