general MCP Server
Query vulnerability databases and security feeds directly through the Model Context Protocol.
Discovered via github-topic:model-context-protocol and last synced Today.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Generate a formatted executive security report for one or more CVEs with recommendations
Retrieve CAPEC attack pattern details associated with a CWE or CVE
Get open ports, services, banners, and vulnerabilities for an IP via Shodan
Host/port/service reconnaissance
Compute composite 0–100 risk score using CVSS, EPSS, KEV status, and PoC availability
Fetch detailed CVE record from NVD including CVSS scores, CWEs, affected products, references, and timeline
Search GitHub for public proof-of-concept exploits and exploit code repositories
Get EPSS exploitation probability (0–1) and percentile for one or more CVEs
Query GreyNoise for IP scan/attack activity, classification, and associated CVEs
Scan package names and versions against OSV.dev for known vulnerabilities
IP noise/scan activity intelligence
**CISA KEV**
Search NVD for CVEs by keyword, product name, severity, or date range
Retrieve trending CVEs based on high EPSS scores and recent KEV additions
**EPSS**
**AbuseIPDB**
**CIRCL PDNS**
**GitHub Code Search**
TTL
Check IP address abuse history and confidence score via AbuseIPDB
Look up ransomware payment addresses and transaction data from Ransomwhere
How to Get
Weight
**OSV.dev**
**VirusTotal**
**Exploit-DB**
**Ubuntu Security**
Parse and explain a CVSS v3.1 vector string with per-metric breakdown
Batch-fetch details for up to 20 CVEs in a single call with parallel enrichment
Map a CVE or CWE to relevant MITRE ATT&CK techniques, tactics, and mitigations
Rank a list of CVEs by composite risk score for triage prioritization
Retrieve historical DNS resolution data for a domain from CIRCL Passive DNS
Description
Analyze file hashes, URLs, domains, or IPs against 70+ antivirus engines
Search MalwareBazaar for malware samples by hash, tag, or signature
Query ThreatFox for Indicators of Compromise linked to malware families
Search GitHub Security Advisories by ecosystem, package, or severity
Submit a URL for scanning or retrieve previous scan results from URLScan.io
10× faster NVD lookups (50 req/30s vs 5)
GitHub Advisory search + exploit PoC search
IP reputation lookups
File/URL/domain/IP malware scanning
URL scanning and website analysis
Label
Data Provided
**NVD**
No published limit
**GitHub Advisories**
**MITRE ATT&CK**
**Shodan**
**MalwareBazaar**
**ThreatFox**
**Ransomwhere**
**URLScan.io**
**Nuclei Templates**
**MSRC**
**Red Hat Security**
Extract and categorize all reference links for a CVE (patches, advisories, exploits)
> **⚡ Zero-key start:** Eight tools work without any API key — EPSS, CISA KEV, OSV.dev, MITRE ATT&CK, CWE lookups, CVSS parsing, Ransomwhere, and NVD (at reduced rate). You can start using the server immediately and add keys progressively. --- ## ⚙️ Configuration ### Environment variables (.env.example) ```env # NVD API key — free at https://nvd.nist.gov/developers/request-an-api-key # Without key: 5 req/30s
Check whether a CVE appears in CISA's Known Exploited Vulnerabilities catalog
Look up Common Weakness Enumeration details by CWE ID from embedded database
Determine if known proof-of-concept code exists for a CVE across multiple sources
**GreyNoise**