vulnrable
Security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS.
- 1.0.0
- Version
- remote
- Transport
- 4
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 4 tools scanned
- metadata: scanned
No findings.
Tools (4)
check_package
Security assessment of one npm or PyPI package: letter grade, findings, known vulnerabilities, deprecation status, and — for MCP servers in our directory — the real resolved dependency count. Use before recommending or installing a package.
list_mcp_servers
The MCP server directory with real resolved dependency counts. Use when recommending an MCP server, or to compare how much third-party code candidates pull into the agent. For a graded security assessment of one server, call check_package.
check_cve
Details for one CVE or GHSA identifier, including whether CISA lists it as actively exploited (KEV) and its EPSS exploitation probability. Use to judge real-world urgency.
latest_vulns
Recently published vulnerabilities from the tracked pool, ranked KEV-first then by EPSS. Use for "what should I worry about this week".