Server definition
- Hash
- sha256:31f0bc524783488c7b58339d948fc710c9ee21f4e693ae799728f7463627d26a
- What it is
- What a remote MCP server returned when asked what it offers: 7 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.",
"inputSchema": {
"properties": {
"server_id": {
"description": "e.g. 'mcp:community/shell-runner'",
"type": "string"
}
},
"required": [
"server_id"
],
"type": "object"
},
"name": "vdb_check_mcp_server",
"outputSchema": null
},
{
"description": "BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.",
"inputSchema": {
"properties": {
"purl": {
"description": "Package URL, e.g. 'pkg:npm/lodash' or 'pkg:pypi/requests'",
"type": "string"
},
"version": {
"description": "Optional version. If supplied, range matching is applied.",
"type": "string"
}
},
"required": [
"purl"
],
"type": "object"
},
"name": "vdb_check_package",
"outputSchema": null
},
{
"description": "Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.",
"inputSchema": {
"properties": {
"packages": {
"description": "List of PURLs or 'ecosystem/name' shorthand.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"packages"
],
"type": "object"
},
"name": "vdb_check_packages",
"outputSchema": null
},
{
"description": "List packages currently flagged as slopsquatting candidates in a given ecosystem.",
"inputSchema": {
"properties": {
"ecosystem": {
"description": "npm | PyPI | crates.io | Go | Maven",
"type": "string"
},
"limit": {
"default": 50,
"type": "integer"
}
},
"type": "object"
},
"name": "vdb_list_slopsquatting",
"outputSchema": null
},
{
"description": "Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).",
"inputSchema": {
"properties": {
"id": {
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"name": "vdb_lookup",
"outputSchema": null
},
{
"description": "BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.",
"inputSchema": {
"properties": {
"content": {
"description": "The file's text.",
"type": "string"
},
"filename": {
"description": "e.g. 'package-lock.json' — the format is detected from it",
"type": "string"
},
"path": {
"description": "Local runs only (uvx vdb-mcp): read the file here instead of passing content.",
"type": "string"
}
},
"required": [
"filename"
],
"type": "object"
},
"name": "vdb_scan_lockfile",
"outputSchema": null
},
{
"description": "Free-text search over the VDB vulnerability corpus.",
"inputSchema": {
"properties": {
"limit": {
"default": 20,
"type": "integer"
},
"query": {
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "vdb_search",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:31f0bc524783488c7b58339d948fc710c9ee21f4e693ae799728f7463627d26a | sha256sum