vdb
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
- 0.2.6
- Version
- remote + pypi
- Transport
- 7
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 7 tools scanned
- metadata: scanned
- packages: 1 checked
No findings.
Tools (7)
vdb_check_package
BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.
vdb_check_packages
Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.
vdb_scan_lockfile
BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.
vdb_lookup
Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).
vdb_search
Free-text search over the VDB vulnerability corpus.
vdb_check_mcp_server
BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.
vdb_list_slopsquatting
List packages currently flagged as slopsquatting candidates in a given ecosystem.