Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,070Paid calls: 1,523Letters: 13Defects: 1,322counted 4 min ago
teppi

Server definition

Hash
sha256:31f0bc524783488c7b58339d948fc710c9ee21f4e693ae799728f7463627d26a
What it is
What a remote MCP server returned when asked what it offers: 7 tools

The blob, as servednamed by its sha256

{ "instructions": null, "tools": [ { "description": "BEFORE recommending a community/unofficial MCP server, check it here. Scope risk is evaluated independently of advisory risk — an unvetted publisher asking for shell or filesystem access is refused even with a clean record. Follow the returned `agent_action`.", "inputSchema": { "properties": { "server_id": { "description": "e.g. 'mcp:community/shell-runner'", "type": "string" } }, "required": [ "server_id" ], "type": "object" }, "name": "vdb_check_mcp_server", "outputSchema": null }, { "description": "BEFORE recommending or installing any package, check it here. The response carries `agent_action`: REFUSE (do not add it — relay the `because` text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.", "inputSchema": { "properties": { "purl": { "description": "Package URL, e.g. 'pkg:npm/lodash' or 'pkg:pypi/requests'", "type": "string" }, "version": { "description": "Optional version. If supplied, range matching is applied.", "type": "string" } }, "required": [ "purl" ], "type": "object" }, "name": "vdb_check_package", "outputSchema": null }, { "description": "Bulk-check several packages in one call — always prefer this over repeated vdb_check_package. Each result carries its own `agent_action` (REFUSE / CONFIRM / PROCEED) plus a top-level `agent_action` for the batch. Follow them; relay `because` when refusing. Send names EXACTLY as written — do not correct a typo first, the call is the typo test.", "inputSchema": { "properties": { "packages": { "description": "List of PURLs or 'ecosystem/name' shorthand.", "items": { "type": "string" }, "type": "array" } }, "required": [ "packages" ], "type": "object" }, "name": "vdb_check_packages", "outputSchema": null }, { "description": "List packages currently flagged as slopsquatting candidates in a given ecosystem.", "inputSchema": { "properties": { "ecosystem": { "description": "npm | PyPI | crates.io | Go | Maven", "type": "string" }, "limit": { "default": 50, "type": "integer" } }, "type": "object" }, "name": "vdb_list_slopsquatting", "outputSchema": null }, { "description": "Fetch a single vulnerability by ID or alias (e.g. CVE-2024-1234, GHSA-xxxx-yyyy-zzzz, VDB-SLOP-…).", "inputSchema": { "properties": { "id": { "type": "string" } }, "required": [ "id" ], "type": "object" }, "name": "vdb_lookup", "outputSchema": null }, { "description": "BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns `agent_action`: REFUSE means do not merge.", "inputSchema": { "properties": { "content": { "description": "The file's text.", "type": "string" }, "filename": { "description": "e.g. 'package-lock.json' — the format is detected from it", "type": "string" }, "path": { "description": "Local runs only (uvx vdb-mcp): read the file here instead of passing content.", "type": "string" } }, "required": [ "filename" ], "type": "object" }, "name": "vdb_scan_lockfile", "outputSchema": null }, { "description": "Free-text search over the VDB vulnerability corpus.", "inputSchema": { "properties": { "limit": { "default": 20, "type": "integer" }, "query": { "type": "string" } }, "required": [ "query" ], "type": "object" }, "name": "vdb_search", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:31f0bc524783488c7b58339d948fc710c9ee21f4e693ae799728f7463627d26a | sha256sum