Server definition
- Hash
- sha256:c5eba7dbee473a9f929931532d8c0c05a931b754737214db45e49b96948b68e4
- What it is
- What a remote MCP server returned when asked what it offers: 5 tools
The blob, as servednamed by its sha256
{
"instructions": "Security Intel: vulnerability intelligence for AI agents — CVE lookups enriched with real-world exploitation signal (NVD + CISA Known-Exploited + EPSS), per-package known vulnerabilities and whole-manifest dependency audits (OSV), plus a live feed of what's actively exploited (known_exploited) and exploit-probability scoring (epss_score). Call audit_dependencies before trusting a project's dependency tree; use known_exploited + epss_score to prioritize what to patch first.",
"tools": [
{
"description": "Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.",
"inputSchema": {
"properties": {
"dependencies": {
"description": "[{name, version}] entries",
"items": {
"type": "object"
},
"type": "array"
},
"ecosystem": {
"description": "Package registry for the dependencies: npm (default), pypi, cargo, go, maven, rubygems, nuget, composer, pub, or hex.",
"type": "string"
},
"manifest": {
"description": "Raw package.json contents",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "audit_dependencies",
"outputSchema": {
"additionalProperties": true,
"properties": {
"ecosystem": {},
"findings": {},
"packages_audited": {},
"packages_not_found": {},
"packages_unverified": {},
"packages_with_vulnerabilities": {},
"source": {},
"total_vulnerabilities": {},
"verdict": {}
},
"type": "object"
}
},
{
"description": "Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.",
"inputSchema": {
"properties": {
"cve_id": {
"description": "CVE identifier, e.g. CVE-2021-44228 (case-insensitive; a bare 2021-44228 also works).",
"type": "string"
}
},
"required": [
"cve_id"
],
"type": "object"
},
"name": "cve_lookup",
"outputSchema": {
"additionalProperties": true,
"properties": {
"cvss": {},
"cwe": {},
"description": {},
"exploit_probability": {},
"id": {},
"known_exploited": {},
"last_modified": {},
"published": {},
"references": {},
"sources": {},
"status": {}
},
"type": "object"
}
},
{
"description": "Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.",
"inputSchema": {
"properties": {
"cve_id": {
"description": "A single CVE id.",
"type": "string"
},
"cve_ids": {
"description": "Multiple CVE ids (or pass a comma-separated string).",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [],
"type": "object"
},
"name": "epss_score",
"outputSchema": {
"additionalProperties": true,
"properties": {
"as_of": {},
"model": {},
"note": {},
"scored": {},
"scores": {},
"source": {}
},
"type": "object"
}
},
{
"description": "Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.",
"inputSchema": {
"properties": {
"cve_id": {
"description": "Optional. Check a single CVE, e.g. CVE-2021-44228.",
"type": "string"
},
"limit": {
"description": "When listing, how many newest entries to return (default 20, max 100).",
"type": "number"
},
"ransomware_only": {
"description": "Optional. Only vulns CISA links to known ransomware campaigns.",
"type": "boolean"
},
"vendor": {
"description": "Optional. Filter by vendor or product name substring.",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "known_exploited",
"outputSchema": {
"additionalProperties": true,
"properties": {
"catalog_count": {},
"catalog_version": {},
"cve_id": {},
"date_added": {},
"due_date": {},
"filter": {},
"known_ransomware_use": {},
"listed": {},
"name": {},
"product": {},
"released": {},
"required_action": {},
"returned": {},
"source": {},
"vendor": {},
"vulnerabilities": {}
},
"type": "object"
}
},
{
"description": "List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.",
"inputSchema": {
"properties": {
"ecosystem": {
"description": "Package registry to look in. One of: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.",
"type": "string"
},
"name": {
"description": "Exact package name as published in that registry, e.g. lodash for npm, requests for pypi.",
"type": "string"
},
"version": {
"description": "Optional; if given, only vulns affecting that version are returned",
"type": "string"
}
},
"required": [
"ecosystem",
"name"
],
"type": "object"
},
"name": "package_vulnerabilities",
"outputSchema": {
"additionalProperties": true,
"properties": {
"ecosystem": {},
"name": {},
"source": {},
"version": {},
"vulnerabilities": {},
"vulnerability_count": {}
},
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:c5eba7dbee473a9f929931532d8c0c05a931b754737214db45e49b96948b68e4 | sha256sum