kr.ai.vdb/vdb

vdb

Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.

0.2.6
Version
remote + pypi
Transport
7
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 7 tools scanned
  • metadata: scanned
  • packages: 1 checked

No findings.

Tools (7)

  • vdb_check_package

    BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.

  • vdb_check_packages

    Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.

  • vdb_scan_lockfile

    BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.

  • vdb_lookup

    Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).

  • vdb_search

    Free-text search over the VDB vulnerability corpus.

  • vdb_check_mcp_server

    BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.

  • vdb_list_slopsquatting

    List packages currently flagged as slopsquatting candidates in a given ecosystem.