Security Intel MCP

Keyless MCP server giving AI agents CVE lookups (NVD), package-vulnerability checks (OSV) and dependency-manifest audits. No API key; free tier.

Documentation

Security Intel MCP — by Datakoot

Vulnerability intelligence for AI agents — as MCP tools your agent can call mid-task. No API keys.

Tools

ToolWhat it doesSource
cve_lookupCVE summary: description, CVSS score & severity, CWE, referencesNVD (NIST)
package_vulnerabilitiesKnown vulnerabilities for a package/versionOSV.dev
audit_dependenciesAudit a whole package.json (or dependency list) in one callOSV.dev

No API keys required for any tool.

Quick start

claude mcp add --transport http security-intel https://security.datakoot.com/mcp

Or point any MCP client at https://security.datakoot.com/mcp.

Data & attribution

Vulnerability data comes from the National Vulnerability Database (NIST — US public domain) and OSV.dev (CC-BY 4.0), the same open source used by scanners like Trivy and Grype.

Part of Datakoot — keyless intelligence APIs for AI agents.