vuln-intel-mcp
by rohanrajnist
README.md
# vuln-intel-mcp
A local **MCP server** that gives any AI agent — Claude Desktop, Claude Code, Cline, Cursor, or your own — CVE remediation intelligence from public sources: **NVD**, **CISA KEV**, and **FIRST EPSS**.
**Your model does the reasoning. This server does not.**
That is the whole point: the server only does the token-free work — fetching public vulnerability data over HTTP and computing an objective priority. It **never calls an LLM, needs no API key, and sends nothing anywhere except read-only requests to public vulnerability databases.** The remediation write-up and the ServiceNow note are produced by *your* model, in *your* session, from the structured facts the tools return. No one's API tokens are consumed but your own.
Built by [Rohan Raj](https://clawofrohan.com/vuln-intel). A hosted demo with AI synthesis and a live cost ledger runs at **clawofrohan.com/vuln-intel**.
---
## Install & connect
You need Python 3.10+. The easiest runner is [`uv`](https://docs.astral.sh/uv/) (`uvx` downloads and runs on demand — nothing to install permanently).
### Claude Code
```bash
claude mcp add vuln-intel -- uvx vuln-intel-mcp
```
### Claude Desktop
Edit `claude_desktop_config.json` (Settings → Developer → Edit Config):
```json
{
"mcpServers": {
"vuln-intel": {
"command": "uvx",
"args": ["vuln-intel-mcp"]
}
}
}
```
### Cline / Cursor / any MCP client
Same shape — command `uvx`, args `["vuln-intel-mcp"]`. Or if you installed it with `pip install vuln-intel-mcp`, use command `vuln-intel-mcp` with no args.
Restart the client, and ask it something like *"Should I patch CVE-2024-3400?"* or *"What's the exploit status of Log4Shell?"*
---
## Tools
| Tool | What it returns (token-free) | What your model does with it |
|------|------------------------------|------------------------------|
| `cve_lookup` | NVD facts, CVSS, CWEs, affected products, fix versions from CPE data, EPSS probability, CISA KEV status, and a computed **P1–P4** priority | Writes fix versions, remediation steps, workarounds, and a ServiceNow VR note |
| `cve_search` | Candidate CVEs for a free-form product/keyword query (NVD keyword search) | Picks the right CVE, then calls `cve_lookup` |
| `cve_exploit_intel` | Public exploit signals — KEV exploited/ransomware flags, EPSS score, and public GitHub repos referencing the CVE (often PoC/exploit code) | Judges weaponization and urgency |
---
## Optional environment variables
All optional — the server works with none. These raise **your own** public-API rate limits:
- `NVD_API_KEY` — a free [NVD API key](https://nvd.nist.gov/developers/request-an-api-key) for higher NVD throughput.
- `GITHUB_TOKEN` — a GitHub token for more GitHub repo searches in `cve_exploit_intel`.
---
## Privacy
- No telemetry. No account. No key required.
- Outbound requests go only to `services.nvd.nist.gov`, `api.first.org`, `cisa.gov`, and (for exploit intel) `api.github.com`.
- The CVE ids and search terms you look up are sent to those public services, exactly as if you visited them in a browser.
## License
MIT © Rohan Raj
This server cannot be deployed
Maintenance
ActivityStale
ResponsivenessNo issues