What this MCP does
Provides vulnerability intelligence, dependency and technology risk checks, IP reputation, DAST scans, and security findings management.
Tools
Input schema
{'type': 'object', 'required': ['name', 'version', 'ecosystem'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'description': 'Package name (e.g., "lodash", "django", "github.com/gorilla/mux")'}, 'version': {'type': 'string', 'maxLength': 50, 'description': 'Exact version (e.g., "4.17.20")'}, 'ecosystem': {'type': 'string', 'maxLength': 20, 'description': 'Package ecosystem: npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io'}}}
Input schema
{'type': 'object', 'required': ['technologies'], 'properties': {'technologies': {'type': 'string', 'pattern': '^[a-zA-Z0-9.,\\s\\-/()@]+$', 'maxLength': 2000, 'description': 'Comma-separated list of technology names (e.g., "Apache HTTP Server, OpenSSL, nginx"). Max 50 technologies.'}}}
Input schema
{'type': 'object', 'properties': {'days': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Number of days to look back (1-365, default: 30)'}}}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'pattern': '^[a-z0-9.-]+$', 'maxLength': 253, 'description': 'Domain registered under your Sectora account'}}}
Input schema
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'pattern': '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$', 'maxLength': 36, 'description': 'Scan UUID'}}}
Input schema
{'type': 'object', 'properties': {}}
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Maximum results to return (1-100, default: 20)'}}}
Input schema
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max findings (1-100, default: 25)'}, 'domain': {'type': 'string', 'maxLength': 253, 'description': 'Limit to a single domain (e.g., app.example.com)'}, 'status': {'enum': ['open', 'confirmed'], 'type': 'string', 'description': 'Filter by confirmation status'}, 'severity': {'type': 'string', 'maxLength': 50, 'description': 'Comma-separated severities to include: critical, high, medium, low, info'}}}
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max scans (1-100, default: 25)'}, 'status': {'type': 'string', 'maxLength': 20, 'description': 'Filter by status (queued, running, completed, failed)'}}}
Input schema
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
Input schema
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'pattern': '^(\\d{1,3}(\\.\\d{1,3}){3}|[0-9A-Fa-f:]{2,45})$', 'maxLength': 45, 'description': 'IPv4 (e.g., 1.2.3.4) or IPv6 (e.g., 2606:4700::1) address to look up'}}}
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 2048, 'description': 'Full URL to scan (must start with http:// or https://)'}, 'confirm': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Set to "true" to actually execute the scan. Without this, the call returns a preview only.'}, 'profile': {'enum': ['quick', 'standard', 'deep'], 'type': 'string', 'description': 'Scan profile: quick (~2 min), standard (~10 min), deep (~30 min)'}}}
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 200, 'description': 'Search keyword (CVE ID, technology name, or description)'}, 'is_kev': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs in CISA KEV catalog'}, 'severity': {'enum': ['CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'description': 'Filter by severity'}, 'has_exploit': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs with public exploits'}}}
Recent tool changes
Similar MCP servers
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…