Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,562Letters: 14Defects: 1,336counted just now
teppi

Server definition

Hash
sha256:36a17d04c7f9b227c23a8fa21b4b4befa9360744fb55f6666f77c64e766803c6
What it is
What a remote MCP server returned when asked what it offers: 14 tools

The blob, as servednamed by its sha256

{ "instructions": null, "tools": [ { "description": "Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity, fixed versions, and references. Free tier eligible.", "inputSchema": { "properties": { "ecosystem": { "description": "Package ecosystem: npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io", "maxLength": 20, "type": "string" }, "name": { "description": "Package name (e.g., \"lodash\", \"django\", \"github.com/gorilla/mux\")", "maxLength": 200, "type": "string" }, "version": { "description": "Exact version (e.g., \"4.17.20\")", "maxLength": 50, "type": "string" } }, "required": [ "name", "version", "ecosystem" ], "type": "object" }, "name": "assess_dependency", "outputSchema": null }, { "description": "Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only.", "inputSchema": { "properties": { "technologies": { "description": "Comma-separated list of technology names (e.g., \"Apache HTTP Server, OpenSSL, nginx\"). Max 50 technologies.", "maxLength": 2000, "pattern": "^[a-zA-Z0-9.,\\s\\-/()@]+$", "type": "string" } }, "required": [ "technologies" ], "type": "object" }, "name": "assess_tech_risk", "outputSchema": null }, { "description": "Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog.", "inputSchema": { "properties": { "days": { "description": "Number of days to look back (1-365, default: 30)", "maxLength": 3, "pattern": "^\\d{1,3}$", "type": "string" } }, "type": "object" }, "name": "get_kev_recent", "outputSchema": null }, { "description": "Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TLS, etc.), and edge_health (whether Shield is actually intercepting traffic). Requires API key.", "inputSchema": { "properties": { "domain": { "description": "Domain registered under your Sectora account", "maxLength": 253, "pattern": "^[a-z0-9.-]+$", "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "get_my_posture", "outputSchema": null }, { "description": "Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key.", "inputSchema": { "properties": { "scan_id": { "description": "Scan UUID", "maxLength": 36, "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$", "type": "string" } }, "required": [ "scan_id" ], "type": "object" }, "name": "get_scan", "outputSchema": null }, { "description": "Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required.", "inputSchema": { "properties": {}, "type": "object" }, "name": "get_threat_stats", "outputSchema": null }, { "description": "Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability.", "inputSchema": { "properties": { "limit": { "description": "Maximum results to return (1-100, default: 20)", "maxLength": 3, "pattern": "^\\d{1,3}$", "type": "string" } }, "type": "object" }, "name": "get_trending_cves", "outputSchema": null }, { "description": "Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID.", "inputSchema": { "properties": { "cve_id": { "description": "CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)", "maxLength": 20, "pattern": "^CVE-\\d{4}-\\d{4,}$", "type": "string" } }, "required": [ "cve_id" ], "type": "object" }, "name": "get_weaponization_score", "outputSchema": null }, { "description": "List the API key owner's open security findings across all scans. Use this to answer \"what's my current exposure?\" Filter by severity, status, or domain. Returns finding summaries; call get_scan for full detail. Requires API key.", "inputSchema": { "properties": { "domain": { "description": "Limit to a single domain (e.g., app.example.com)", "maxLength": 253, "type": "string" }, "limit": { "description": "Max findings (1-100, default: 25)", "maxLength": 3, "pattern": "^\\d{1,3}$", "type": "string" }, "severity": { "description": "Comma-separated severities to include: critical, high, medium, low, info", "maxLength": 50, "type": "string" }, "status": { "description": "Filter by confirmation status", "enum": [ "open", "confirmed" ], "type": "string" } }, "type": "object" }, "name": "list_my_findings", "outputSchema": null }, { "description": "List the API key owner's recent scans with summary counts. Requires API key.", "inputSchema": { "properties": { "limit": { "description": "Max scans (1-100, default: 25)", "maxLength": 3, "pattern": "^\\d{1,3}$", "type": "string" }, "status": { "description": "Filter by status (queued, running, completed, failed)", "maxLength": 20, "type": "string" } }, "type": "object" }, "name": "list_my_scans", "outputSchema": null }, { "description": "Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE ID.", "inputSchema": { "properties": { "cve_id": { "description": "CVE identifier in format CVE-YYYY-NNNNN (e.g., CVE-2024-3400)", "maxLength": 20, "pattern": "^CVE-\\d{4}-\\d{4,}$", "type": "string" } }, "required": [ "cve_id" ], "type": "object" }, "name": "lookup_cve", "outputSchema": null }, { "description": "Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both).", "inputSchema": { "properties": { "ip": { "description": "IPv4 (e.g., 1.2.3.4) or IPv6 (e.g., 2606:4700::1) address to look up", "maxLength": 45, "pattern": "^(\\d{1,3}(\\.\\d{1,3}){3}|[0-9A-Fa-f:]{2,45})$", "type": "string" } }, "required": [ "ip" ], "type": "object" }, "name": "lookup_ip_reputation", "outputSchema": null }, { "description": "Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calling again with confirm:true to actually start the scan. Returns scan_id; poll status with get_scan. Domain must be verified in the Sectora account. Daily quota: 25 scans/24h per user. Requires API key.", "inputSchema": { "properties": { "confirm": { "description": "Set to \"true\" to actually execute the scan. Without this, the call returns a preview only.", "enum": [ "true", "false" ], "type": "string" }, "profile": { "description": "Scan profile: quick (~2 min), standard (~10 min), deep (~30 min)", "enum": [ "quick", "standard", "deep" ], "type": "string" }, "url": { "description": "Full URL to scan (must start with http:// or https://)", "maxLength": 2048, "type": "string" } }, "required": [ "url" ], "type": "object" }, "name": "scan_url", "outputSchema": null }, { "description": "Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text.", "inputSchema": { "properties": { "has_exploit": { "description": "Only show CVEs with public exploits", "enum": [ "true", "false" ], "type": "string" }, "is_kev": { "description": "Only show CVEs in CISA KEV catalog", "enum": [ "true", "false" ], "type": "string" }, "query": { "description": "Search keyword (CVE ID, technology name, or description)", "maxLength": 200, "type": "string" }, "severity": { "description": "Filter by severity", "enum": [ "CRITICAL", "HIGH", "MEDIUM", "LOW" ], "type": "string" } }, "required": [ "query" ], "type": "object" }, "name": "search_cves", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:36a17d04c7f9b227c23a8fa21b4b4befa9360744fb55f6666f77c64e766803c6 | sha256sum