Skip to main content

Browse the directory

Showing 4 resources for "cve"
Saved
Active

Source-backed filter active — add entries to compare trust side by side.

Trust snapshot

4 results in this view

Claimed
0%(0/4)

3 trust signals differ in this sample: Review status, Source provenance, Submitter

Signals differ on Review status, Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

4 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (4/4)

Adoption queue

Browse adoption queue · balanced

0/4 visible results are ready for staged adoption under this preset.

ready 0caution 4hold 0

ContrastAPI Security Tools

No required blockers for this preset.

caution

64/100

Collect package checksum or signed artifact information.

mcp/contrastapi-mcp-server · trust review · confidence 83%

CVE MCP Server

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/cve-mcp-server · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/lockfile-provenance-checker · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

0/4 results are high-confidence for the selected preset.

high 0medium 4low 0

ContrastAPI Security Tools

Address Package integrity before broader rollout.

medium

68/100

Missing: Package integrity

mcp/contrastapi-mcp-server · trust review

CVE MCP Server

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/cve-mcp-server · trust review

Freshness distribution

Mostly fresh with a few aging entries

Median age 54 days; 3 fresh, 1 aging or stale of 4 scanned.

median 54d

Aging

91–180 days

25%

1 entry

Stale

> 180 days

0%

0 entries

Oldest entries in this view

Theme distribution

Results center on security

100% of this view shares the top theme. Leading themes: security, cve, supply-chain.

Focused

23 distinct themes across 4 scanned

Security intelligence MCP server that lets Claude look up CVEs, EPSS scores, CISA KEV status, OSV package vulnerabilities, exploit indicators, MITRE mappings, IP reputation, passive DNS, Shodan host data, malware intelligence, URL safety, and risk reports across optional third-party APIs.

ContrastAPI logo

49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.

Slash command that reviews the supply-chain risk of a project's dependencies using OpenSSF Scorecard health signals rather than CVE counts.

Invocation:/dependency-risk-review [package]
Safety ✓ Privacy ✓

PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.

Trigger:PostToolUse
Safety ✓ Privacy ✓