com.vulnrable/vulnrable

vulnrable

Security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS.

1.0.0
Version
remote
Transport
4
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 4 tools scanned
  • metadata: scanned

No findings.

Tools (4)

  • check_package

    Security assessment of one npm or PyPI package: letter grade, findings, known vulnerabilities, deprecation status, and — for MCP servers in our directory — the real resolved dependency count. Use before recommending or installing a package.

  • list_mcp_servers

    The MCP server directory with real resolved dependency counts. Use when recommending an MCP server, or to compare how much third-party code candidates pull into the agent. For a graded security assessment of one server, call check_package.

  • check_cve

    Details for one CVE or GHSA identifier, including whether CISA lists it as actively exploited (KEV) and its EPSS exploitation probability. Use to judge real-world urgency.

  • latest_vulns

    Recently published vulnerabilities from the tracked pool, ranked KEV-first then by EPSS. Use for "what should I worry about this week".