此 MCP 可以做什么
Provides vulnerability intelligence, dependency and technology risk checks, IP reputation, DAST scans, and security findings management.
工具
输入模式
{'type': 'object', 'required': ['name', 'version', 'ecosystem'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'description': 'Package name (e.g., "lodash", "django", "github.com/gorilla/mux")'}, 'version': {'type': 'string', 'maxLength': 50, 'description': 'Exact version (e.g., "4.17.20")'}, 'ecosystem': {'type': 'string', 'maxLength': 20, 'description': 'Package ecosystem: npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io'}}}
输入模式
{'type': 'object', 'required': ['technologies'], 'properties': {'technologies': {'type': 'string', 'pattern': '^[a-zA-Z0-9.,\\s\\-/()@]+$', 'maxLength': 2000, 'description': 'Comma-separated list of technology names (e.g., "Apache HTTP Server, OpenSSL, nginx"). Max 50 technologies.'}}}
输入模式
{'type': 'object', 'properties': {'days': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Number of days to look back (1-365, default: 30)'}}}
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'pattern': '^[a-z0-9.-]+$', 'maxLength': 253, 'description': 'Domain registered under your Sectora account'}}}
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'pattern': '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$', 'maxLength': 36, 'description': 'Scan UUID'}}}
输入模式
{'type': 'object', 'properties': {}}
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Maximum results to return (1-100, default: 20)'}}}
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max findings (1-100, default: 25)'}, 'domain': {'type': 'string', 'maxLength': 253, 'description': 'Limit to a single domain (e.g., app.example.com)'}, 'status': {'enum': ['open', 'confirmed'], 'type': 'string', 'description': 'Filter by confirmation status'}, 'severity': {'type': 'string', 'maxLength': 50, 'description': 'Comma-separated severities to include: critical, high, medium, low, info'}}}
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max scans (1-100, default: 25)'}, 'status': {'type': 'string', 'maxLength': 20, 'description': 'Filter by status (queued, running, completed, failed)'}}}
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
输入模式
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'pattern': '^(\\d{1,3}(\\.\\d{1,3}){3}|[0-9A-Fa-f:]{2,45})$', 'maxLength': 45, 'description': 'IPv4 (e.g., 1.2.3.4) or IPv6 (e.g., 2606:4700::1) address to look up'}}}
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 2048, 'description': 'Full URL to scan (must start with http:// or https://)'}, 'confirm': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Set to "true" to actually execute the scan. Without this, the call returns a preview only.'}, 'profile': {'enum': ['quick', 'standard', 'deep'], 'type': 'string', 'description': 'Scan profile: quick (~2 min), standard (~10 min), deep (~30 min)'}}}
输入模式
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 200, 'description': 'Search keyword (CVE ID, technology name, or description)'}, 'is_kev': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs in CISA KEV catalog'}, 'severity': {'enum': ['CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'description': 'Filter by severity'}, 'has_exploit': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs with public exploits'}}}
近期工具变更
类似的 MCP 服务器
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…