此 MCP 可以做什么
Provides CVE intelligence covering exploitation, detection, affected packages, fixed versions, exploit chains, and remediation prioritization.
工具
输入模式
{'type': 'object', 'properties': {'claim': {'enum': ['observed', 'potential'], 'type': 'string', 'description': 'observed: the source reports attacks that chained them; potential: the source reports they can be chained'}, 'limit': {'type': 'integer', 'description': '1..500 (default 100)'}, 'since': {'type': 'string', 'description': 'Pairs first seen on or after this day (YYYY-MM-DD)'}, 'source': {'type': 'string', 'description': 'Evidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc, exploitdb or exploit_code'}}}
输入模式
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'CVE id, such as CVE-2024-3400'}}}
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'description': '1..100 (default 25)'}, 'window': {'enum': ['7d', '30d'], 'type': 'string', 'description': 'Rise window (default 7d)'}}}
输入模式
{'type': 'object', 'properties': {}}
输入模式
{'type': 'object', 'properties': {'kev': {'enum': ['0', '1'], 'type': 'string', 'description': 'Restrict to CVEs outside (0) or inside (1) CISA KEV'}, 'limit': {'type': 'integer', 'description': '1..500 (default 100)'}, 'window': {'enum': ['7', '30'], 'type': 'string', 'description': 'Sighting window in days (default 7)'}}}
输入模式
{'type': 'object', 'properties': {'cve': {'type': 'string', 'description': "Scope to one CVE's change history, such as CVE-2024-3400"}, 'type': {'enum': ['first_published', 'kev_added', 'detection_added', 'remediation_added', 'first_sighted', 'chain_added', 'ssvc_changed', 'kev_due_changed', 'kev_triage_flag_changed', 'kev_notes_changed'], 'type': 'string'}, 'limit': {'type': 'integer'}, 'since': {'type': 'string'}, 'cursor': {'type': 'string'}}}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'Package name, verbatim (for example @babel/core or org.jenkins-ci.main:jenkins-core)'}, 'purl': {'type': 'string', 'description': 'Package URL, such as pkg:npm/lodash or pkg:maven/org.apache.logging.log4j/log4j-core'}, 'ecosystem': {'type': 'string', 'description': 'OSV ecosystem (npm, PyPI, Maven, Go, crates.io, Packagist, RubyGems, NuGet, …) or purl type (pypi, cargo, composer, gem, golang, …)'}}}
输入模式
{'type': 'object', 'properties': {'q': {'type': 'string'}, 'ti': {'enum': ['total', 'partial'], 'type': 'string', 'description': 'CISA SSVC Technical impact, for CVEs with a CISA assessment held'}, 'bod': {'enum': ['3df', '3d', '14d', '60d', 'fsu'], 'type': 'string', 'description': 'BOD 26-04 Table 1 read at the stated exposure: a mapping of KEV status and CISA SSVC values to a timeline key at that exposure'}, 'cwe': {'type': 'string'}, 'eco': {'type': 'string'}, 'fix': {'enum': ['0', '1'], 'type': 'string'}, 'kev': {'enum': ['0', '1'], 'type': 'string'}, 'pkg': {'type': 'string'}, 'sev': {'type': 'string'}, 'page': {'type': 'integer'}, 'ssvc': {'enum': ['0', '1'], 'type': 'string', 'description': 'Whether this dataset holds a CISA SSVC assessment for the CVE'}, 'year': {'type': 'string'}, 'limit': {'type': 'integer'}, 'watch': {'enum': ['0', '1'], 'type': 'string', 'description': 'On KEV Watch at tier 1 or 2: reported as exploited by trackers other than CISA, outside CISA KEV'}, 'detect': {'enum': ['0', '1'], 'type': 'string'}, 'kev_to': {'type': 'string', 'description': 'ISO day, exclusive upper bound on the CISA listing date'}, 'vendor': {'type': 'string'}, 'chained': {'enum': ['0', '1'], 'type': 'string', 'description': 'In a known exploit chain: a cited source reports the CVE was used together with another CVE in one exploit chain'}, 'exposed': {'enum': ['0', '1'], 'type': 'string', 'description': 'The exposure branch for bod: 1 publicly exposed (default), 0 internal'}, 'malware': {'enum': ['0', '1'], 'type': 'string', 'description': 'A published source ties a named malware family, tool, campaign or ransomware group to the CVE'}, 'sighted': {'enum': ['7', '30'], 'type': 'string', 'description': 'Field sighting window in days: a named sensor network recorded the CVE within the last 7 or 30 days'}, 'epss_gte': {'type': 'number'}, 'kev_from': {'type': 'string', 'description': 'ISO day, inclusive lower bound on the CISA listing date'}, 'technique': {'type': 'string', 'description': 'ATT&CK technique id, such as T1190 or T1059.001'}, 'kev_vendor': {'type': 'string', 'description': "CISA's vendorProject, verbatim (for example 'Palo Alto Networks')"}, 'ransomware': {'enum': ['0', '1'], 'type': 'string'}, 'automatable': {'enum': ['0', '1'], 'type': 'string'}, 'triage_flag': {'enum': ['0', '1'], 'type': 'string', 'description': "CISA's forensic triage flag on the KEV entry (BOD 26-04)"}, 'chainability': {'enum': ['0', '1'], 'type': 'string', 'description': 'On KCV Watch™: the CVE carries at least one chain candidate, a same-product pair whose extracted exploit capabilities connect, derived from exploit-capability analysis; a candidate is not a confirmed chain'}}}
输入模式
{'type': 'object', 'required': ['ids'], 'properties': {'ids': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 50, 'minItems': 1, 'description': 'CVE ids, such as CVE-2024-3400 (1 to 50)'}, 'exposure': {'enum': ['yes', 'no', 'unknown'], 'type': 'string', 'description': "Whether the asset is publicly exposed, the agency's own per-asset value; unknown returns both branches"}}}
近期工具变更
类似的 MCP 服务器
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…