kr.ai.vdb/vdb
Related Servers
Alternatives to kr.ai.vdb/vdb
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityBmaintenanceAn MCP server that verifies npm and PyPI packages before installation, checking for existence, known vulnerabilities, OpenSSF scorecard, and typosquatting, returning an ALLOW/WARN/BLOCK verdict.MIT
- AlicenseNot gradedqualityDmaintenanceMCP server that checks npm and PyPI package health, providing maintenance signals, version info, CVE counts, and alternative suggestions.MIT
- AlicenseAqualityBmaintenanceAn MCP server that gives AI assistants the ability to check open-source packages for vulnerabilities, enrich findings with real-world exploit intelligence, and statically analyse whether vulnerable code is actually reachable in your project.31Apache 2.0
- AlicenseAqualityBmaintenanceMCP server for querying CVE and package vulnerability data from NVD and OSV.dev, allowing CVE lookups and dependency scanning.41MIT
- AlicenseNot gradedqualityCmaintenanceMCP server that scans PyPI packages and GitHub repos for security vulnerabilities, dangerous patterns, and prompt injection vectors, providing trust scores (0-10) and side-by-side comparisons.MIT
- AlicenseAqualityBmaintenanceA local MCP server that scans repository dependencies for known vulnerabilities (CVEs) using OSV.dev, enriches findings with NVD and CISA KEV data, and supports triage, remediation, and accepted risk management directly from an AI coding assistant.630 npm1MIT
TDQS
Scored across 10 tools
Each tool has a clearly distinct purpose: single vs bulk package checks, lockfile scanning, vulnerability lookup vs search, MCP server vetting, slopsquatting listing, harden analysis, post-fix verification, and VEX generation. Even the two checking tools are cleanly separated by input cardinality and workflow stage. No ambiguity about which tool to select for a given task.
All tool names follow the consistent `vdb_` prefix with snake_case verb_noun or verb patterns (e.g., check_package, scan_lockfile, harden_verify). The naming makes the action and target predictable across the entire set, with no style mixing or vague verbs.
Ten tools is well within the ideal range for a vulnerability database and supply-chain security server. Each tool earns its place by covering a distinct stage—package vetting, bulk checks, lockfile analysis, lookup/search, MCP server risk, and remediation—without redundant or filler tools.
The tool surface provides full lifecycle coverage: check packages, scan lockfiles for transitive risk, look up and search vulnerabilities, vet MCP servers, list slopsquatting candidates, run reachability analysis, verify fixes, and generate VEX documents. There are no obvious gaps or dead ends for the stated domain.