Vulnary-MCP
Related Servers
Alternatives to Vulnary-MCP
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityBmaintenanceMCP server for retrieving vulnerability data (CVE) via HTTP, testable with MCP Inspector and OpenCode.1-
- AlicenseAqualityCmaintenanceMCP server that provides tools to search, filter, and retrieve CVE data from the NVD API, including by ID, keyword, severity, and recency.4MIT
- AlicenseNot gradedqualityCmaintenanceMCP server for searching NIST's National Vulnerability Database, enabling retrieval of recent CVEs, keyword/CPE/CWE searches, and detailed CVE information.Apache 2.0
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol (MCP) server for querying the NIST National Vulnerability Database (NVD) API, enabling search and retrieval of CVE details, temporal context, and KEV catalog entries.14MIT
- AlicenseAqualityBmaintenanceMCP server for checking packages against an AI-aware vulnerability database, including CVEs, slopsquatting, CISA KEV, and MCP-server trust profiles.1054 PyPIElastic 2.0
- AlicenseAqualityBmaintenanceA local MCP server that scans repository dependencies for known vulnerabilities (CVEs) using OSV.dev, enriches findings with NVD and CISA KEV data, and supports triage, remediation, and accepted risk management directly from an AI coding assistant.630 npm1MIT
TDQS
Scored across 4 tools
Each tool targets a clearly distinct use case: CVE lookup, single-package query, batch dependency scan, and manifest file parsing. The overlap between check_package and scan_dependencies is well-delineated by single-item vs. batch/list operations, so an agent should not misselect.
All tool names follow a consistent verb_noun snake_case pattern with purposeful verbs: lookup, check, scan, scan. This makes the action and target of each tool predictable and easy to reason about.
Four tools is a well-scoped set for a vulnerability lookup and dependency scanning server. Each tool earns its place and there is no redundancy or unnecessary bloat.
The tool surface covers the core vulnerability workflow: fetching CVE details, querying a single package, scanning a dependency list, and parsing a manifest file. No significant lifecycle or workflow gaps exist for the stated purpose.