Skip to main content
Glama
README.md
# Vulnary-MCP

A MCP (Model Context Protocol) server for open-source vulnerability intelligence. It can look up CVEs and check packages against known vulnerabilities, directly from an MCP-compatible AI assistant.

Combines [OSV.dev](https://osv.dev) (open-source package vulnerabilities) and [NVD](https://nvd.nist.gov) (CVE database) into a small set of MCP tools.

## Features

- 🔍 Look up a CVE by ID and get a parsed summary (description, severity, score, references) from NVD
- 📦 Check a specific package/version for known vulnerabilities via OSV.dev
- 📋 Batch-check a list of dependencies in one call
- 📄 Scan the raw contents of a package.json or requirements.txt file for known vulnerabilities
- 🧩 Works with any MCP-compatible client (Claude Desktop, Claude Code, LM Studio, etc.)


## Installation

```bash
git clone https://github.com/Agam-S/Vulnary-MCP
cd Vulnary-MCP
npm install
npm run build
```

## Usage

Add it to your MCP client's config, pointing at the built entry point:

```json
{
  "mcpServers": {
    "vulnary": {
      "command": "node",
      "args": ["/absolute/path/to/Vulnary-MCP/dist/index.js"]
    }
  }
}
```

Restart the client and the tools below should appear.

## Tools

| Tool | Description |
|---|---|
| `lookup_cve` | 	Fetch a parsed summary (description, severity, score, references) for a CVE ID from NVD |
| `check_package` | Query OSV.dev for known vulnerabilities in a specific package + version (requires ecosystem, e.g. npm, PyPI) |
| `scan_dependencies` | Batch-check a list of `{ name, version }` dependencies against OSV.dev for a given ecosystem |
| `scan_dependency_file` | Parse the raw contents of a `package.json` or `requirements.txt` file and batch-check every listed dependency against OSV.dev |


## Note: 
`scan_dependency_file` reads dependencies straight out of `package.json` (dependencies + devDependencies) or a `requirements.txt` with pinned == versions. It does not parse lockfiles (`package-lock.json`, `Pipfile.lock`, etc.) or unpinned/range version specifiers.


## Resources:
* [NVD API Guide](nvdGuide.md)
* [OSV API Guide](osvGuide.md)


## License
MIT License. See [LICENSE](LICENSE) for details.

TDQS

A3.9/5.0

Scored across 4 tools

Disambiguation5/5

Each tool targets a clearly distinct use case: CVE lookup, single-package query, batch dependency scan, and manifest file parsing. The overlap between check_package and scan_dependencies is well-delineated by single-item vs. batch/list operations, so an agent should not misselect.

Naming Consistency5/5

All tool names follow a consistent verb_noun snake_case pattern with purposeful verbs: lookup, check, scan, scan. This makes the action and target of each tool predictable and easy to reason about.

Tool Count5/5

Four tools is a well-scoped set for a vulnerability lookup and dependency scanning server. Each tool earns its place and there is no redundancy or unnecessary bloat.

Completeness5/5

The tool surface covers the core vulnerability workflow: fetching CVE details, querying a single package, scanning a dependency list, and parsing a manifest file. No significant lifecycle or workflow gaps exist for the stated purpose.

Maintenance

ActivitySlowing
ResponsivenessNo issues