MCP 服务器

sectora

io.github.megabrainee/sectora
安全 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Provides vulnerability intelligence, dependency and technology risk checks, IP reputation, DAST scans, and security findings management.

assess_dependency
Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity, fixed versions, and references. Free tier eligible.
输入模式
{'type': 'object', 'required': ['name', 'version', 'ecosystem'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'description': 'Package name (e.g., "lodash", "django", "github.com/gorilla/mux")'}, 'version': {'type': 'string', 'maxLength': 50, 'description': 'Exact version (e.g., "4.17.20")'}, 'ecosystem': {'type': 'string', 'maxLength': 20, 'description': 'Package ecosystem: npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io'}}}
assess_tech_risk
Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only.
输入模式
{'type': 'object', 'required': ['technologies'], 'properties': {'technologies': {'type': 'string', 'pattern': '^[a-zA-Z0-9.,\\s\\-/()@]+$', 'maxLength': 2000, 'description': 'Comma-separated list of technology names (e.g., "Apache HTTP Server, OpenSSL, nginx"). Max 50 technologies.'}}}
get_kev_recent
Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog.
输入模式
{'type': 'object', 'properties': {'days': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Number of days to look back (1-365, default: 30)'}}}
get_my_posture
Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TLS, etc.), and edge_health (whether Shield is actually intercepting traffic). Requires API key.
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'pattern': '^[a-z0-9.-]+$', 'maxLength': 253, 'description': 'Domain registered under your Sectora account'}}}
get_scan
Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key.
输入模式
{'type': 'object', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'pattern': '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$', 'maxLength': 36, 'description': 'Scan UUID'}}}
get_threat_stats
Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required.
输入模式
{'type': 'object', 'properties': {}}
get_trending_cves
Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability.
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Maximum results to return (1-100, default: 20)'}}}
get_weaponization_score
Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID.
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
list_my_findings
List the API key owner's open security findings across all scans. Use this to answer "what's my current exposure?" Filter by severity, status, or domain. Returns finding summaries; call get_scan for full detail. Requires API key.
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max findings (1-100, default: 25)'}, 'domain': {'type': 'string', 'maxLength': 253, 'description': 'Limit to a single domain (e.g., app.example.com)'}, 'status': {'enum': ['open', 'confirmed'], 'type': 'string', 'description': 'Filter by confirmation status'}, 'severity': {'type': 'string', 'maxLength': 50, 'description': 'Comma-separated severities to include: critical, high, medium, low, info'}}}
list_my_scans
List the API key owner's recent scans with summary counts. Requires API key.
输入模式
{'type': 'object', 'properties': {'limit': {'type': 'string', 'pattern': '^\\d{1,3}$', 'maxLength': 3, 'description': 'Max scans (1-100, default: 25)'}, 'status': {'type': 'string', 'maxLength': 20, 'description': 'Filter by status (queued, running, completed, failed)'}}}
lookup_cve
Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE ID.
输入模式
{'type': 'object', 'required': ['cve_id'], 'properties': {'cve_id': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'maxLength': 20, 'description': 'CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)'}}}
lookup_ip_reputation
Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both).
输入模式
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'pattern': '^(\\d{1,3}(\\.\\d{1,3}){3}|[0-9A-Fa-f:]{2,45})$', 'maxLength': 45, 'description': 'IPv4 (e.g., 1.2.3.4) or IPv6 (e.g., 2606:4700::1) address to look up'}}}
scan_url
Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calling again with confirm:true to actually start the scan. Returns scan_id; poll status with get_scan. Domain must be verified in the Sectora account. Daily quota: 25 scans/24h per user. Requires API key.
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 2048, 'description': 'Full URL to scan (must start with http:// or https://)'}, 'confirm': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Set to "true" to actually execute the scan. Without this, the call returns a preview only.'}, 'profile': {'enum': ['quick', 'standard', 'deep'], 'type': 'string', 'description': 'Scan profile: quick (~2 min), standard (~10 min), deep (~30 min)'}}}
search_cves
Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text.
输入模式
{'type': 'object', 'required': ['query'], 'properties': {'query': {'type': 'string', 'maxLength': 200, 'description': 'Search keyword (CVE ID, technology name, or description)'}, 'is_kev': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs in CISA KEV catalog'}, 'severity': {'enum': ['CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'description': 'Filter by severity'}, 'has_exploit': {'enum': ['true', 'false'], 'type': 'string', 'description': 'Only show CVEs with public exploits'}}}
已添加
assess_dependency
2026年9月17日 12:45
已添加
get_my_posture
2026年9月17日 12:45
已添加
scan_url
2026年9月17日 12:45
已添加
get_scan
2026年9月17日 12:45
已添加
list_my_scans
2026年9月17日 12:45
已添加
list_my_findings
2026年9月17日 12:45
已添加
get_threat_stats
2026年9月17日 12:45
已添加
lookup_ip_reputation
2026年9月17日 12:45
已添加
get_weaponization_score
2026年9月17日 12:45
已添加
get_trending_cves
2026年9月17日 12:45
已添加
get_kev_recent
2026年9月17日 12:45
已添加
search_cves
2026年9月17日 12:45
已添加
assess_tech_risk
2026年9月17日 12:45
已添加
lookup_cve
2026年9月17日 12:45