@attestd/mcp
OfficialAllows checking specific versions of NGINX for known CVEs and supply-chain risks.
Allows checking JavaScript packages hosted on npm for vulnerabilities and supply-chain compromises.
Allows checking specific versions of PostgreSQL for known CVEs and supply-chain risks.
Allows checking Python packages hosted on PyPI for vulnerabilities and supply-chain compromises.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@attestd/mcpCheck if lodash 4.17.21 has any critical vulnerabilities."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@attestd/mcp
Attestd checks whether a dependency version has exploitable CVEs or a confirmed supply-chain compromise. One API call returns a structured risk response.
Official Model Context Protocol (MCP) server for Attestd. Exposes CVE risk and supply-chain checks as tools for Claude Code, Claude Desktop, and any MCP-compatible client.
Get a free API key · Full docs
stdio transport: run via
npx -y @attestd/mcpwith no global install.check_package_vulnerability: wrapsGET /v1/checkusing@attestd/sdk.check_batch_vulnerabilities: checks up to 100 packages in one call. Use for lockfile and manifest audits.list_covered_products: returns Attestd-covered products. With an API key, returns live data fromGET /v1/products. Without a key, returns the static bundled infrastructure list.get_cve_details: returns CVSS, EPSS, KEV status, and affected products for a single CVE id.
Prerequisites
Node.js 18+
An Attestd API key from the portal. Required for
check_package_vulnerability,check_batch_vulnerabilities,get_cve_details, and livelist_covered_products.
Related MCP server: Cybersecurity MCP Server
Claude Code / MCP config
Add to ~/.claude/mcp.json or project .mcp.json:
{
"mcpServers": {
"attestd": {
"command": "npx",
"args": ["-y", "@attestd/mcp"],
"env": {
"ATTESTD_API_KEY": "your-api-key-here"
}
}
}
}Optional: override the API base URL (e.g. dev):
"env": {
"ATTESTD_API_KEY": "your-api-key-here",
"ATTESTD_BASE_URL": "https://dev.api.attestd.io"
}Tools
check_package_vulnerability
Argument | Type | Description |
| string | Product slug ( |
| string | Exact version ( |
Returns JSON with:
Field | Meaning |
|
|
|
|
| CISA KEV signal |
|
|
|
|
| Patch guidance |
| Synthesis confidence 0.0–1.0 |
| CVE IDs contributing to the risk assessment |
| Package name integrity: typosquat or AI-hallucinated name ( |
| Explanation when |
| PyPI/npm supply-chain signal |
On invalid/missing API key or rate limit, returns isError: true with a JSON error string.
check_batch_vulnerabilities
Argument | Type | Description |
| array | Array of |
Quota is checked upfront. If the batch would exceed your monthly quota, a 429 is returned before any calls are billed.
Returns JSON with count and results. Supported items include the same fields as check_package_vulnerability minus typosquat. Outside-coverage items return only product, version, outsideCoverage: true, and riskState: null.
list_covered_products
No arguments. With an API key, returns live JSON from GET /v1/products:
Field | Meaning |
|
|
| Combined count of CVE products and supply chain packages |
| CVE infrastructure slugs with display names |
| Monitored PyPI/npm packages |
Without an API key, returns the static bundled list:
Field | Meaning |
|
|
| Number of bundled infrastructure products |
| Array of |
get_cve_details
Argument | Type | Description |
| string | CVE identifier, e.g. |
Returns JSON with:
Field | Meaning |
|
|
| CVE identifier |
| NVD description text |
| CVSS base score and vector |
| CISA KEV signal |
| Remotely exploitable |
| Authentication required for exploitation |
| Attestd product slugs affected by this CVE |
| EPSS probability and percentile |
| ISO timestamps |
When the CVE is not found, returns { "found": false, "cveId": "..." } without isError. On invalid/missing API key or rate limit, returns isError: true with a JSON error string.
Verify locally
npm run build
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.jsLicense
MIT. See LICENSE.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseBqualityDmaintenanceEnables checking npm packages for known security vulnerabilities using the OSV API before installation. Supports both single package checks and bulk vulnerability scanning for multiple packages at once.2
- AlicenseNot gradedqualityDmaintenanceEnables searching the NIST NVD for CVEs, retrieving full CVE details, checking software for known vulnerabilities, and searching the CPE database.MIT
- AlicenseNot gradedqualityAmaintenanceEnables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.4MIT
- FlicenseNot gradedqualityCmaintenanceScans Python, Node.js, Java/Spring, and PHP dependency manifests for known vulnerabilities using OSV and GitHub Advisory APIs.
Related MCP Connectors
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/attestd-io/attestd-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server