Skip to main content
Glama
0pstech

kr.ai.vdb/vdb

by 0pstech

vdb-mcp

mcp-name: kr.ai.vdb/vdb

MCP (Model Context Protocol) server for VDB — the AI-aware vulnerability database. Lets Claude Desktop, Claude Code, Cursor, Cline, Continue, and any MCP client check packages while generating code: known CVEs, slopsquatting (LLM-hallucinated package names an attacker may have registered), CISA KEV status, MCP-server trust profiles, and more.

Quick start

uvx vdb-mcp          # or: pipx run vdb-mcp

Claude Desktop (claude_desktop_config.json) / Cursor (.cursor/mcp.json):

{
  "mcpServers": {
    "vdb": { "command": "uvx", "args": ["vdb-mcp"] }
  }
}

No install at all — point any streamable-HTTP MCP client at the hosted endpoint:

{
  "mcpServers": {
    "vdb": { "url": "https://vdb.ai.kr/mcp" }
  }
}

That's it — the server talks to the hosted instance at https://vdb.ai.kr by default. Anonymous use gets a free per-IP trial; add an API key for unmetered access (free at https://vdb.ai.kr/signup):

{
  "mcpServers": {
    "vdb": {
      "command": "uvx",
      "args": ["vdb-mcp"],
      "env": { "VDB_API_TOKEN": "vdb_..." }
    }
  }
}

Related MCP server: mcp-package-health

Tools

Tool

What it does

vdb_check_package

Check one package (purl + optional version) for vulnerabilities, slop risk, KEV

vdb_check_packages

Bulk slopsquatting / risk check for a list of packages

vdb_lookup

Fetch one advisory by ID (CVE-…, GHSA-…, VDB-SLOP-…)

vdb_search

Free-text search over the vulnerability corpus

vdb_check_mcp_server

Trust tier + permission scopes of a community MCP server

vdb_list_slopsquatting

Current slopsquatting candidates per ecosystem

Environment

Variable

Default

Meaning

VDB_API_URL

https://vdb.ai.kr

VDB instance to query (set for self-hosted)

VDB_API_TOKEN

(empty)

vdb_… API key — unmetered, per-account quota

MCP_MODE

stdio

stdio or sse (long-running HTTP server)

MCP_PORT

7700

SSE port

Why

LLMs hallucinate package names; attackers register them (slopsquatting). LLMs also happily recommend packages with known RCEs. VDB gives your agent a guardrail: one tool call before npm install / pip install. See https://vdb.ai.kr/connect for the one-line prompt variant that needs no MCP at all.

License

Elastic License 2.0 — free to use, including inside commercial organizations and CI. The only restrictions: you may not offer this software to third parties as a hosted or managed service, or resell it as a product. Commercial licensing beyond that: dev@egdee.com. API usage is governed by the VDB service terms regardless of how you call it.

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    MCP server for comprehensive PyPI package intelligence, providing tools for dependency analysis, security scanning, health scoring, license compliance, and trend tracking.
    Last updated
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
    Last updated
    485
    7
    Business Source 1.1
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that gives AI assistants the ability to check open-source packages for vulnerabilities, enrich findings with real-world exploit intelligence, and statically analyse whether vulnerable code is actually reachable in your project.
    Last updated
    3
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

  • MCP server for hex.pm and hexdocs.pm: search, inspect, compare, and audit Elixir packages

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/0pstech/vdb-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server