Skip to main content

Browse the directory

Showing 5 resources for "cve"
Saved
Active

Select entries to compare install and trust signals side by side.

Trust snapshot

5 results in this view

Claimed
0%(0/5)

3 trust signals differ in this sample: Review status, Source provenance, Submitter

Signals differ on Review status, Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

5 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (5/5)

Adoption queue

Browse adoption queue · balanced

0/5 visible results are ready for staged adoption under this preset.

ready 0caution 5hold 0

ContrastAPI Security Tools

No required blockers for this preset.

caution

64/100

Collect package checksum or signed artifact information.

mcp/contrastapi-mcp-server · trust review · confidence 83%

CVE MCP Server

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/cve-mcp-server · trust review · confidence 67%

Dependency Security Audit

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/dependency-security-audit-on-stop · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/lockfile-provenance-checker · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

0/5 results are high-confidence for the selected preset.

high 0medium 5low 0

ContrastAPI Security Tools

Address Package integrity before broader rollout.

medium

68/100

Missing: Package integrity

mcp/contrastapi-mcp-server · trust review

CVE MCP Server

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/cve-mcp-server · trust review

Dependency Security Audit

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

hooks/dependency-security-audit-on-stop · trust review

Freshness distribution

40% of this view is aging or stale

Median age 54 days; 3 fresh of 5 scanned. Re-verify the oldest entries.

median 54d

Aging

91–180 days

20%

1 entry

Stale

> 180 days

20%

1 entry

Theme distribution

Results center on security

100% of this view shares the top theme. Leading themes: security, cve, dependencies.

Focused

26 distinct themes across 5 scanned

Security intelligence MCP server that lets Claude look up CVEs, EPSS scores, CISA KEV status, OSV package vulnerabilities, exploit indicators, MITRE mappings, IP reputation, passive DNS, Shodan host data, malware intelligence, URL safety, and risk reports across optional third-party APIs.

ContrastAPI logo

49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.

A Stop hook that runs npm audit, pip-audit, safety, or bundler-audit automatically at the end of every Claude Code session, detecting CVEs and outdated packages across Node.js, Python, and Ruby projects.

Slash command that reviews the supply-chain risk of a project's dependencies using OpenSSF Scorecard health signals rather than CVE counts.

Invocation:/dependency-risk-review [package]
Safety ✓ Privacy ✓

PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.

Trigger:PostToolUse
Safety ✓ Privacy ✓