Cvefeed Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Cvefeed Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol (MCP) server for the CVEFeed.io vulnerability intelligence API. Gives Claude Desktop, Cursor, Cline, and any other MCP-aware agent direct access to CVE search, project subscriptions, and vulnerability alerts.
pip install cvefeed-mcp
# or
uvx cvefeed-mcpCreate a Project API Token at https://cvefeed.io/project/settings/api-tokens/, copy it, and export it alongside the numeric id of the project the token was issued for:
export CVEFEED_API_TOKEN=cvefeed_XXXXXXXX_...
export CVEFEED_PROJECT_ID=42Each token is bound to exactly one project — one MCP install targets one project. The project id is the integer in your project dashboard URL (/project/detail/<slug>/; the numeric id is also shown in the project settings page).
MCP tools span four resource scopes. Grant read on every resource the agent may touch so it doesn't hit an "insufficient scope" error mid-task:
vulnerabilities: read — CVE / CPE / CVEQL / EPSS discovery toolssubscriptions: read (or write to let the agent add / remove product subscriptions)alerts: read (or write to let the agent mark alerts as read)activity_log: read — Enterprise only; required by read_project_activity_logwrite implies read, so you don't need to tick both on the same resource.
Optionally override the base URL for staging or self-hosted deployments:
export CVEFEED_BASE_URL=https://cvefeed.io # defaultAdd to your ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or equivalent:
{
"mcpServers": {
"cvefeed": {
"command": "uvx",
"args": ["cvefeed-mcp"],
"env": {
"CVEFEED_API_TOKEN": "cvefeed_XXXXXXXX_...",
"CVEFEED_PROJECT_ID": "42"
}
}
}
}Same MCP server config format — point command at cvefeed-mcp (or uvx cvefeed-mcp) and set CVEFEED_API_TOKEN + CVEFEED_PROJECT_ID in the env block.
| Tool | Purpose | Auth required |
|---|---|---|
search_cves | Full-text and filter search over the CVE catalog | Optional |
get_cve_detail | Fetch full metadata for a single CVE | Optional |
run_cveql_query | Execute a CVEQL query for advanced hunting | Optional |
lookup_by_cpe | Resolve CPE 2.3 URIs to CVEs/products/vendors | Pro tier |
get_exploit_intel | Public exploits and EPSS scores | Pro tier |
list_product_subscriptions | List subscriptions on the configured project | subscriptions:read |
add_product_subscription | Subscribe the project to a product | subscriptions:write |
remove_product_subscription | Unsubscribe from a product | subscriptions:write |
search_products | Search products with subscription status | subscriptions:read |
list_project_alerts | Read vulnerability alerts on the project | alerts:read |
mark_alert_read | Mark an alert as read | alerts:write |
read_project_activity_log | Read project audit log | activity_log:read, Enterprise |
Every project-scoped tool targets the single project set via CVEFEED_PROJECT_ID; the LLM never passes a project id.
cd mcp-server
pip install -e ".[dev]"
pytest -vShips stdio transport only (what Claude Desktop, Cursor, and Cline expect). Remote streamable-HTTP transport may follow in a later release.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.