MCP serverio.kernelscan/kernelscan
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Overview
Score?
UNRATED 0.815
of what a free look can see, on 30 looks
Looks
35
last 11 hr ago
Tools
11
changed 6 days ago
More info
URL
kernelscan.io/mcp/
streamable-http
Says it is
KernelScan 1.26.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.815 · highest on record 0.8561
Toolsfrom sha256:8ff182d582…5e5bae · +0 −0 6 days ago
| Tool | Schema |
|---|---|
| create_product Create a new product, run analysis, and return its initial stats.
``config_upload_id`` references a previously-staged .config that the
caller POSTed to ``/api/conf |
input · no output |
| get_cve Fetch a single Linux kernel CVE by ID (e.g. ``CVE-2024-12345``).
No API key required: keyless callers get the public representation of a
CVE, but only for CVEs in |
input · no output |
| get_product Fetch one product owned by the caller, including the CVE breakdown.
Returns 404 (not 403) if the product belongs to another user, so
product existence isn't leaked |
input · no output |
| get_product_vex Return the VEX MANIFEST for one of the caller's products — metadata,
not the document.
Multi-megabyte CycloneDX documents (up to 8,000+ vulnerability entries)
|
input · no output |
| list_product_vex_entries Page through the VEX vulnerability entries of one of the caller's products.
Returns COMPLETE CycloneDX vulnerability objects for one bounded page
— never the root |
input · no output |
| list_products List the calling user's products with denormalized analysis stats.
Paid plans only (basic / pro / enterprise). Free callers get a clear
upgrade message.
|
input · output |
| request_access Explain how to get a KernelScan account (no API key needed).
Self-registration is open — there is no invitation to wait for and no
admin in the loop. The user sign |
input · no output |
| search_cves Search Linux kernel CVEs.
No API key required: keyless callers get the free public tier — recent
high-severity Linux kernel CVEs (capped at 25 results). Free *keye |
input · no output |
| submit_support_report Send a support / dispute report to KernelScan staff.
Use this when an automated CVE or factor assessment looks wrong, or
when you need to hand human-needed context |
input · no output |
| update_product Update a product owned by the caller. Re-runs analysis if the
kernel_version, arch, or referenced .config changed.
To change the .config, first POST the new file t |
input · no output |
| whoami Return the caller's identity, plan, and quota state.
Works without an API key: keyless callers get a lightweight public-tier
payload (no account) describing how to |
input · no output |
Verify it yourself
npx teppi-check https://kernelscan.io/mcp/curl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2P5B49F3ZV9BXPGDGK07