MCP serverio.echelongraph/echelongraph-mcp
CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan).
Read more
CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.Overview
Score?
UNRATED 0.084
of what a free look can see, on 1 looks
Looks
1
last 16 hr ago
Tools
14
More info
URL
mcp.echelongraph.io/mcp
streamable-http
Says it is
echelongraph-mcp 2.6.1
protocol 2025-06-18
In the record since
16 hr ago
Among servers18,413 with a card
0median 0.606 · this server 0.084 · highest on record 0.8561
Toolsfrom sha256:5884ca174d…04700e
| Tool | Schema |
|---|---|
| check_affected Whether a product or package at a given version is affected by known CVEs, from the same matcher as echelongraph.io/am-i-affected. Two lookup paths. The CPE path takes product (the |
input · output |
| check_sbom Check a dependency list against EchelonGraph's advisory corpus, one verdict per component. Pass purls (package URLs, up to 2,000 distinct) or sbom (a CycloneDX JSON or SPDX JSON do |
input · output |
| cve_exposure Internet-exposure footprint for one CVE from EchelonGraph's KEV-exposure radar: how many internet-facing services (distinct ip:port, returned as exposed_hosts; a machine answering |
input · output |
| cve_intel Weakness, public exploit code, affected packages and fixed versions for one CVE, from EchelonGraph's per-CVE enrichment. Returns cwes (each cwe_id with its name and source), exploi |
input · output |
| cve_summary Summary of EchelonGraph's CVE Pulse feed: summary.total active CVEs, their counts by severity band (summary.critical, summary.high, summary.medium, summary.low), the count with no |
input · output |
| epss_history How one CVE's EPSS score (FIRST's exploit-prediction probability, 0 to 1, with its percentile) has changed, as EchelonGraph recorded it: points, oldest first, each with at, epss_sc |
input · output |
| exposure_radar Aggregate totals from EchelonGraph's internet-exposure radars, each refreshed on its own schedule: internet-facing services running actively-exploited (CISA-KEV) CVEs, plus the ran |
input · output |
| get_cve Full record for one CVE: description, severity, cvss_v3_score, cvss_v4_score and cvss_v4_severity (when the record has a CVSS v4 score), echelongraph_score and echelongraph_severit |
input · output |
| get_cwe One CWE (weakness class) and the CVEs classified under it. Returns cwe_id, name and description (from the MITRE CWE catalog EchelonGraph embeds, version catalog_version), total (th |
input · output |
| get_vendor_advisory One vendor advisory in full, by vendor and the vendor's advisory ID (the vendor and vendor_advisory_id fields of a row from search_vendor_advisories or vendor_advisories_for_cve): |
input · output |
| kev_recent The CVEs CISA has added to its Known Exploited Vulnerabilities (KEV) catalog, newest first, from EchelonGraph's copy of that catalog, which polls CISA's feed every 5 minutes. Each |
input · output |
| search_cves Search/list CVEs from EchelonGraph's CVE feed (NVD + MITRE-CNA pre-NVD + CISA-KEV + EPSS + GitHub GHSA, each polled on a schedule). Filter by severity, minimum CVSS, free text, and |
input · output |
| search_vendor_advisories Search or list vendor-published advisories, newest first. query is matched case-insensitively as a substring of each advisory's title, description, vendor name, vendor_advisory_id, |
input · output |
| vendor_advisories_for_cve The vendor-published advisories that name one CVE, newest first, at most 20: for each, vendor, vendor_display_name, vendor_advisory_id, title, severity and cvss_v3_score where the |
input · output |
Verify it yourself
npx teppi-check https://mcp.echelongraph.io/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M42QZ9N56STQYR23JX27FKYA