Security Intel MCP server
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
0 stars
Reviews
Write oneNobody has reviewed Security Intel MCP yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Security Intel MCP tools (5)
write = sends, deletes, buys or postsaudit_dependenciesFreeAudit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.
cve_lookupFreeLook up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.
epss_scoreFreeGet the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.
known_exploitedFreeCheck whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.
package_vulnerabilitiesFreeList known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 177ms20/20
- Tool poisoning5 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancelast push 5 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Install directly
claude mcp add --transport http cve-vulnerability-lookup https://security.datakoot.com/mcp
Security Intel MCP: common questions
- Is Security Intel MCP server safe?
- Yes, by our scan: it is graded A (89/100). Read the Security Intel MCP safety report
- How do I install Security Intel MCP?
- It runs remotely at security.datakoot.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Security Intel MCP need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Security Intel MCP maintained?
- The last commit was 5 days ago (2026-09-15). The latest release is v2.1.0.
- Is Security Intel MCP up?
- 100% of our last 8 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Security Intel MCP?
- Servers from other publishers that do the same job: npm Registry MCP Server, grim-mcp server and Security Txt Cra Lint MCP server. Compare all Security Intel MCP alternatives.
Alternatives to Security Intel MCP
Same job from other publishers: the closest match first, then the best rated.
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- grim-mcpSecurity audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.not reviewedGrowingC
- Security Txt Cra Lint13 rules that decide whether a vulnerability report ever reaches younot reviewedGrowingA
- Google Workspace Admin Security-Audit MCPMCP server for Google Workspace security auditing — login audit, external sharing, daily briefnot reviewedGrowingA
- Presend MCP ServerFree MCP server: 36 security & dev API tools -- WHOIS, DNS, CVE, IP reputation, Cosmos SDK.not reviewedGrowingB