@attestd/mcp
OfficialAllows checking specific versions of NGINX for known CVEs and supply-chain risks.
Allows checking JavaScript packages hosted on npm for vulnerabilities and supply-chain compromises.
Allows checking specific versions of PostgreSQL for known CVEs and supply-chain risks.
Allows checking Python packages hosted on PyPI for vulnerabilities and supply-chain compromises.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@attestd/mcpCheck if lodash 4.17.21 has any critical vulnerabilities."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@attestd/mcp
Attestd checks whether a dependency version has exploitable CVEs or a confirmed supply-chain compromise. One API call returns a structured risk response.
Official Model Context Protocol (MCP) server for Attestd. Exposes CVE risk and supply-chain checks as tools for Claude Code, Claude Desktop, and any MCP-compatible client.
Get a free API key · Full docs
stdio transport: run via
npx -y @attestd/mcpwith no global install.check_package_vulnerability: wrapsGET /v1/checkusing@attestd/sdk.check_batch_vulnerabilities: checks up to 100 packages in one call. Use for lockfile and manifest audits.list_covered_products: returns Attestd-covered products. With an API key, returns live data fromGET /v1/products. Without a key, returns the static bundled infrastructure list.get_cve_details: returns CVSS, EPSS, KEV status, and affected products for a single CVE id.
Prerequisites
Node.js 18+
An Attestd API key from the portal. Required for
check_package_vulnerability,check_batch_vulnerabilities,get_cve_details, and livelist_covered_products.
Related MCP server: Dependency Checker MCP Server
Claude Code / MCP config
Add to ~/.claude/mcp.json or project .mcp.json:
{
"mcpServers": {
"attestd": {
"command": "npx",
"args": ["-y", "@attestd/mcp"],
"env": {
"ATTESTD_API_KEY": "your-api-key-here"
}
}
}
}Optional: override the API base URL (e.g. dev):
"env": {
"ATTESTD_API_KEY": "your-api-key-here",
"ATTESTD_BASE_URL": "https://dev.api.attestd.io"
}Tools
check_package_vulnerability
Argument | Type | Description |
| string | Product slug ( |
| string | Exact version ( |
Returns JSON with:
Field | Meaning |
|
|
|
|
| CISA KEV signal |
|
|
|
|
| Patch guidance |
| Synthesis confidence 0.0–1.0 |
| CVE IDs contributing to the risk assessment |
| Package name integrity: typosquat or AI-hallucinated name ( |
| Explanation when |
| PyPI/npm supply-chain signal |
On invalid/missing API key or rate limit, returns isError: true with a JSON error string.
check_batch_vulnerabilities
Argument | Type | Description |
| array | Array of |
Quota is checked upfront. If the batch would exceed your monthly quota, a 429 is returned before any calls are billed.
Returns JSON with count and results. Supported items include the same fields as check_package_vulnerability minus typosquat. Outside-coverage items return only product, version, outsideCoverage: true, and riskState: null.
list_covered_products
No arguments. With an API key, returns live JSON from GET /v1/products:
Field | Meaning |
|
|
| Combined count of CVE products and supply chain packages |
| CVE infrastructure slugs with display names |
| Monitored PyPI/npm packages |
Without an API key, returns the static bundled list:
Field | Meaning |
|
|
| Number of bundled infrastructure products |
| Array of |
get_cve_details
Argument | Type | Description |
| string | CVE identifier, e.g. |
Returns JSON with:
Field | Meaning |
|
|
| CVE identifier |
| NVD description text |
| CVSS base score and vector |
| CISA KEV signal |
| Remotely exploitable |
| Authentication required for exploitation |
| Attestd product slugs affected by this CVE |
| EPSS probability and percentile |
| ISO timestamps |
When the CVE is not found, returns { "found": false, "cveId": "..." } without isError. On invalid/missing API key or rate limit, returns isError: true with a JSON error string.
Verify locally
npm run build
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.jsLicense
MIT. See LICENSE.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseBqualityDmaintenanceEnables checking npm packages for known security vulnerabilities using the OSV API before installation. Supports both single package checks and bulk vulnerability scanning for multiple packages at once.Last updated2
- AlicenseBqualityCmaintenanceEnables security scanning for npm dependencies by checking manifest and lockfiles against the OSV.dev and Socket.dev vulnerability databases. It provides tools to detect vulnerabilities in specific packages and retrieve detailed technical reports for identified security issues.Last updated315MIT
- Alicense-qualityDmaintenanceEnables searching the NIST NVD for CVEs, retrieving full CVE details, checking software for known vulnerabilities, and searching the CPE database.Last updatedMIT
- Alicense-qualityAmaintenanceEnables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.Last updated4MIT
Related MCP Connectors
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/attestd-io/attestd-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server