此 MCP 可以做什么
Provides CVE intelligence, vulnerability scoring, exploit and sighting searches, security advisories, SSVC prioritization, and Linux or package vulnerability audits.
工具
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'description': 'CVE identification (CVE-YYYY-NNNNN)'}}}
输出模式
{'type': 'object', 'properties': {'series': {'type': 'array', 'items': {'type': 'object', 'properties': {'date': {'type': 'string', 'description': 'Date (YYYY-MM-DD)'}, 'model': {'type': 'string', 'description': 'Model version'}, 'score': {'type': 'string', 'description': 'Score (%)'}, 'percentile': {'type': 'string', 'description': 'Percentile (%)'}}}}}}
输入模式
{'type': 'object', 'required': ['report_id'], 'properties': {'limit': {'type': 'string', 'description': 'optional maximum number of results to return, when supported by the selected report'}, 'filters': {'type': 'object', 'description': 'optional object with report-specific filters'}, 'report_id': {'type': 'string', 'description': 'identifier of the report to execute'}}}
输出模式
{'type': 'object', 'required': ['report_id', 'data'], 'properties': {'data': {'oneOf': [{'type': 'array', 'items': {'type': 'object'}}, {'type': 'object'}], 'description': 'structured report rows or aggregated values'}, 'filters': {'type': 'object', 'description': 'optional JSON schema describing supported input parameters'}, 'summary': {'type': 'string', 'description': 'Optional Markdown summary of the report results'}, 'report_id': {'type': 'string', 'description': 'executed report identifier'}}}
输入模式
{'type': 'object', 'required': []}
输出模式
{'type': 'object', 'properties': {'reports': {'type': 'array', 'items': {'type': 'object', 'properties': {'title': {'type': 'string', 'description': 'human-readable report title'}, 'report_id': {'type': 'string', 'description': 'Report identifier'}, 'description': {'type': 'string', 'description': 'short explanation of what the report returns'}, 'input_schema': {'type': 'object', 'properties': {'additionalProperties': True}, 'description': 'optional JSON schema describing supported input parameters'}}}}}}
输入模式
{'type': 'object', 'required': ['os', 'version', 'packages'], 'properties': {'os': {'type': 'string', 'description': 'Linux distribution identifier supported by SecDB (use `linux_os` to obtain allowed values)'}, 'version': {'type': 'string', 'description': 'OS version or codename corresponding to the selected distribution'}, 'packages': {'type': 'string', 'description': 'list of installed packages, **one per line**, generated using the appropriate system command'}}}
输出模式
{'type': 'object', 'properties': {'report': {'type': 'array', 'items': {'type': 'object', 'description': 'structured objects describing the advisories affecting the audited packages'}}, 'summary': {'type': 'string', 'description': 'Markdown summary including total vulnerabilities, severity breakdown, and key findings'}}}
输入模式
{'type': 'object', 'required': []}
输出模式
{'type': 'object', 'properties': {'supported': {'type': 'array', 'items': {'type': 'object', 'properties': {'os': {'type': 'string', 'description': 'OS'}, 'versions': {'type': 'array', 'items': {'type': 'string', 'description': 'Version'}}}}}}}
输入模式
{'type': 'object', 'required': ['purls'], 'properties': {'purls': {'type': 'array', 'items': {'type': 'string'}, 'description': 'List of Package URLs (PURL) to audit'}}}
输出模式
{'type': 'object', 'properties': {'report': {'type': 'array', 'items': {'type': 'object', 'description': 'structured objects describing the advisories affecting the audited packages', 'additionalProperties': True}}, 'summary': {'type': 'string', 'description': 'Markdown summary including total vulnerabilities, severity breakdown, and key findings'}}}
输入模式
{'type': 'object', 'required': [], 'properties': {'query': {'type': 'string', 'description': 'Full-text-search for vulnerability name, CVE ID or Advisory ID, categories, etc.'}, 'cve_id': {'type': 'string', 'description': 'CVE identification (CVE-YYYY-NNNN)'}, 'status': {'enum': ['seen', 'confirmed', 'exploited', 'patched', 'not-exploited', 'not-confirmed', 'not-patched', 'exploitable', 'mentioned', 'mitigated'], 'type': 'string', 'description': 'Sighting status'}, 'category': {'enum': ['advisory', 'nasl', 'exploit', 'misp', 'scanner', 'poc', 'social'], 'type': 'string', 'description': 'Sighting category (scanner, exploit, advisory, nasl, etc.)'}}}
输入模式
{'type': 'object', 'required': ['cve_id', 'mission_prevalence', 'public_well_being_impact'], 'properties': {'cve_id': {'type': 'string', 'description': 'CVE ID'}, 'mission_prevalence': {'type': 'string', 'description': '# Mission Prevalence\n\nA mission essential function (MEF) is a function directly related to\naccomplishing the organization\'s mission as set forth in its statutory or\nexecutive charter. Identifying MEFs is part of business continuity planning\nor crisis planning. In contrast to non-essential functions, an organization\nmust perform a [MEF] during a disruption to normal operations. The mission\nis the reason an organization exists, and MEFs are how that mission is\nrealized. Non- essential functions support the smooth delivery or success\nof MEFs rather than directly supporting the mission.\n\n## Possible values\n\n- "M" or "Minimal"\n\nNeither support nor essential apply. The vulnerable component may be used\nwithin the entities, but it is not used as a mission-essential component,\nnor does it provide impactful support to mission-essential functions.\n\n- "S" or "Support"\n\nThe vulnerable component only supports MEFs for two or more entities.\n\n- "E" or "Essential"\n\nThe vulnerable component directly provides capabilities that constitute at\nleast one MEF for at least one entity; component failure may (but does not\nnecessarily) lead to overall mission failure.\n\n## Instructions for LLM\n\nAsk the user for the "Mission Prevalence" value before calling the tool.\n'}, 'public_well_being_impact': {'type': 'string', 'description': '# Public Well-being Impact\n\n## Possible values\n\n- "M" or "Minimal"\n\n**Type of Harm -> All**, The effect is below the threshold for all aspects\ndescribed in material.\n\n- "A" or "Material"\n\n**Type of Harm -> Physical harm**, Does one or more of the following:\n\n- Causes physical distress or injury to system users.\n- Introduces occupational safety hazards.\n- Reduces and/or results in failure of cyber-physical system safety margins.\n\n**Type of Harm -> Environment**, Major externalities (property damage,\nenvironmental damage, etc.) are imposed on other parties.\n\n**Type of Harm -> Financial**, Financial losses likely lead to bankruptcy of\nmultiple persons.\n\n**Type of Harm -> Psychological**, Widespread emotional or psychological harm,\nsufficient to necessitate counseling or therapy, impact populations of people.\n\n- "I" or "Irreversible"\n\n**Type of Harm -> Physical harm**, One or both of the following are true:\n\n- Multiple fatalities are likely.\n- The cyber-physical system, of which the vulnerable component is a part, isl\nikely lost or destroyed.\n\n**Type of Harm -> Environment**, Extreme or serious externalities (immediate\npublic health threat, environmental damage leading to small ecosystem collapse,\netc.) are imposed on other parties.\n\n**Type of Harm -> Financial**, Social systems (elections, financial grid, etc.)\nsupported by the software are destabilized and potentially collapse.\n\n**Type of Harm -> Psychological\tN/A\n\n\n## Instructions for LLM\n\nAsk the user for the "Public Well-being Impact" value before calling the tool.\n'}}}
输出模式
{'type': 'object', 'required': ['exploitation', 'technical_impact', 'automatable', 'mission_prevalence', 'public_well_being_impact', 'mission_and_well_being_impact_value', 'decision', 'vector_string'], 'properties': {'summary': {'type': 'string', 'description': 'Summary'}, 'decision': {'type': 'string', 'description': 'Decision'}, 'automatable': {'type': 'string', 'description': 'Automatable'}, 'exploitation': {'type': 'string', 'description': 'State of Exploitation (Evidence of Active Exploitation of a Vulnerability)'}, 'vector_string': {'type': 'string', 'description': 'SSVC Vector String'}, 'technical_impact': {'type': 'string', 'description': 'Technical Impact (Technical Impact of Exploiting the Vulnerability)'}, 'mission_prevalence': {'type': 'string', 'description': 'Mission Prevalence (Impact on Mission Essential Functions of Relevant Entities)'}, 'public_well_being_impact': {'type': 'string', 'description': 'Public Well-being Impact'}, 'mission_and_well_being_impact_value': {'type': 'string', 'description': 'Mission and Well-Being Impact Value'}}}
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'description': 'CVE identification (CVE-YYYY-NNNNN)'}}}
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'description': 'CVE identification (CVE-YYYY-NNNNN)'}}}
输出模式
{'type': 'object', 'required': ['cvss_version', 'cvss_base_score', 'cvss_base_severity', 'cvss_vector_string', 'epss_score'], 'properties': {'epss_score': {'type': 'string', 'description': 'EPSS score'}, 'cvss_explain': {'type': 'string', 'description': 'Explain CVSS'}, 'cvss_version': {'type': 'string', 'description': 'CVSS version'}, 'cvss_base_score': {'type': 'string', 'description': 'CVSS base score'}, 'cvss_base_severity': {'type': 'string', 'description': 'CVSS base severity'}, 'cvss_vector_string': {'type': 'string', 'description': 'CVSS vector string'}}}
输入模式
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': 'CVE ID, vulnerability name, Advisory ID, Exploit, etc.'}}}
输出模式
{'type': 'object', 'properties': {'results': {'type': 'array', 'items': {'type': 'string', 'description': 'Formatted result in Markdown'}}, 'summary': {'type': 'string', 'description': 'Search summary with found records (ID) and link for continue the search on SecDB'}}}
近期工具变更
类似的 MCP 服务器
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…