Skip to main content

cve-mcp-server-security-intelligence

Production-grade MCP server providing Claude with 27 security intelligence tools across 21 APIs for vulnerability research, CVE analysis, threat intelligence, and risk scoring

Jump to install

Source facts

Repository
reason-machines/mcp-skills
Last source activity
May 16, 2026 at 20:48
Detected SKILL.md language
English
Stars
7
Forks
2

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
cve-mcp-server-security-intelligence
description
Production-grade MCP server providing Claude with 27 security intelligence tools across 21 APIs for vulnerability research, CVE analysis, threat intelligence, and risk scoring
triggers
["analyze this CVE for exploitation risk","check if this vulnerability is in CISA KEV","calculate risk score for these CVEs","search for exploits for CVE","lookup IP reputation and threat intelligence","generate security report for vulnerabilities","prioritize these CVEs by risk","check EPSS score for vulnerability"]
# CVE MCP Server Security Intelligence > Skill by [ara.so](https://ara.so) — MCP Skills collection ## What This Project Does CVE MCP Server is a production-grade Model Context Protocol server that transforms Claude into a comprehensive security analyst. It provides 27 security intelligence tools that integrate with 21 different APIs including NVD, EPSS, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, GreyNoise, GitHub, and more. Instead of manually querying multiple security databases, this MCP server allows Claude to: - Look up detailed CVE information with CVSS scores and affected products - Calculate composite risk scores using EPSS, KEV status, and PoC availability - Search for public exploits and proof-of-concept code - Check IP addresses against threat intelligence feeds - Analyze malware samples and indicators of compromise - Generate executive security reports with prioritized recommendations - Map vulnerabilities to MITRE ATT&CK techniques The server runs locally via stdio, makes only outbound HTTPS requests, and supports both free APIs (no key required) and premium services. ## Installation ### Prerequisites - Python 3.10 or higher - Claude Desktop or any MCP-compatible client - (Optional) API keys for premium services ### Install via pip/pipx (Recommended) ```bash # Using pipx (isolated environment) pipx install cve-mcp-server # Using pip pip install cve-mcp-server # Using uv (faster) uv pip install cve-mcp-server ``` ### Install from Source ```bash git clone https://github.com/mukul975/cve-mcp-server.git cd cve-mcp-server pip install -e . ``` ## Configuration ### Claude Desktop Setup Add to your Claude Desktop config file: **macOS**: `~/Library/Application Support/Claude/claude_desktop_config.json` **Windows**: `%APPDATA%\Claude\claude_desktop_config.json` ```json { "mcpServers": { "cve-security": { "command": "python", "args": ["-m", "cve_mcp_server"], "env": { "NVD_API_KEY": "your-nvd-key-here", "VIRUSTOTAL_API_KEY": "your-vt-key-here", "SHODAN_API_KEY": "your-shodan-key-here", "GREYNOISE_API_KEY": "your-greynoise-key-here", "ABUSEIPDB_API_KEY": "your-abuseipdb-key-here", "GITHUB_TOKEN": "your-github-token-here" } } } } ``` ### Environment Variables Required API keys (most are optional, tools degrade gracefully): - `NVD_API_KEY` - NVD API 2.0 key (free, highly recommended for rate limits) - `VIRUSTOTAL_API_KEY` - VirusTotal v3 API key - `SHODAN_API_KEY` - Shodan API key - `GREYNOISE_API_KEY` - GreyNoise Community or Enterprise key - `ABUSEIPDB_API_KEY` - AbuseIPDB v2 key - `GITHUB_TOKEN` - GitHub personal access token (public repo read) - `ABUSECH_AUTH_KEY` - Abuse.ch (MalwareBazaar/ThreatFox) auth key - `CIRCL_PDNS_USER` - CIRCL Passive DNS username - `CIRCL_PDNS_PASSWORD` - CIRCL Passive DNS password - `ALIENVAULT_OTX_KEY` - AlienVault OTX API key ### Create API Keys Free tier API keys: - **NVD**: https://nvd.nist.gov/developers/request-an-api-key - **GitHub**: https://github.com/settings/tokens (needs `public_repo` scope) - **VirusTotal**: https://www.virustotal.com/gui/join-us - **AbuseIPDB**: https://www.abuseipdb.com/register ## Core Tool Categories ### 1. Vulnerability Intelligence (8 tools) #### lookup_cve Fetch detailed CVE record from NVD: ```python # Claude will call this as: # lookup_cve(cve_id="CVE-2024-3400") # Returns: { "id": "CVE-2024-3400", "description": "Command injection vulnerability in...", "cvss_v3_score": 10.0, "cvss_v3_severity": "CRITICAL", "cvss_v3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "published": "2024-04-12T00:00:00", "last_modified": "2024-04-15T12:34:56", "cwe_ids": ["CWE-77"], "references": [...], "affected_products": [...] } ``` #### search_cves Search NVD by keyword, product, or severity: ```python # search_cves(keyword="Apache Log4j", severity="CRITICAL", last_n_days=30) # search_cves(product="palo alto networks", max_results=10) ``` #### get_epss_score Get exploitation probability score (0.0-1.0): ```python # get_epss_score(cve_id="CVE-2024-3400") # Returns: { "cve": "CVE-2024-3400", "epss": 0.89234, "percentile": 0.99123, "date": "2024-05-16" } ``` #### check_kev_status Check if CVE is in CISA Known Exploited Vulnerabilities: ```python # check_kev_status(cve_id="CVE-2021-44228") # Returns: { "in_kev": true, "date_added": "2021-12-10", "due_date": "2021-12-24", "required_action": "Apply updates per vendor instructions", "known_ransomware": true } ``` #### bulk_cve_lookup Batch fetch up to 20 CVEs in parallel: ```python # bulk_cve_lookup(cve_ids=["CVE-2024-3400", "CVE-2023-44487", "CVE-2021-44228"]) ``` ### 2. Exploit & Attack Intelligence (4 tools) #### search_exploits Search GitHub for public PoC exploits: ```python # search_exploits(cve_id="CVE-2024-3400") # Returns: { "cve": "CVE-2024-3400", "exploit_count": 12, "exploits": [ { "title": "CVE-2024-3400 PoC", "url": "https://github.com/...", "stars": 45, "language": "Python", "created_at": "2024-04-13" } ] } ``` #### get_mitre_techniques Map CVE to MITRE ATT&CK framework: ```python # get_mitre_techniques(cve_id="CVE-2021-44228") # Returns: { "cve": "CVE-2021-44228", "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application", "tactic": "Initial Access", "description": "...", "mitigations": [...] } ] } ``` #### check_poc_availability Determine if PoC code exists across multiple sources: ```python # check_poc_availability(cve_id="CVE-2024-3400") # Returns: { "poc_available": true, "sources": ["GitHub", "Exploit-DB"], "confidence": "HIGH" } ``` ### 3. Risk Analysis & Reporting (4 tools) #### calculate_risk_score Compute composite 0-100 risk score: ```python # calculate_risk_score(cve_id="CVE-2024-3400") # Returns: { "cve": "CVE-2024-3400", "risk_score": 98.5, "risk_level": "CRITICAL", "components": { "cvss_score": 10.0, "epss_score": 0.89234, "in_kev": true, "poc_available": true, "exploit_maturity": "FUNCTIONAL" }, "recommendation": "Patch immediately - active exploitation confirmed" } ``` Risk score formula: ``` Base = CVSS * 10 (0-100) + EPSS * 30 (0-30) + KEV bonus: +20 + PoC bonus: +10 + Capped at 100 ``` #### prioritize_cves Rank multiple CVEs by composite risk: ```python # prioritize_cves(cve_ids=["CVE-2024-3400", "CVE-2023-4966", "CVE-2023-44487"]) # Returns sorted list with risk scores: [ {"cve": "CVE-2024-3400", "risk_score": 98.5, "priority": 1}, {"cve": "CVE-2023-44487", "risk_score": 87.3, "priority": 2}, {"cve": "CVE-2023-4966", "risk_score": 76.2, "priority": 3} ] ``` #### generate_risk_report Create executive security report: ```python # generate_risk_report(cve_ids=["CVE-2024-3400"], include_mitigations=True) # Returns formatted markdown report with: # - Executive summary # - CVE details with CVSS/EPSS # - KEV status and exploit availability # - MITRE ATT&CK mapping # - Prioritized remediation steps ``` ### 4. Network Intelligence (4 tools) #### lookup_ip_reputation Check IP against AbuseIPDB: ```python # lookup_ip_reputation(ip_address="185.220.101.34") # Returns: { "ip": "185.220.101.34", "abuse_confidence": 100, "total_reports": 1234, "is_public": true, "is_whitelisted": false, "country": "US", "isp": "Example ISP", "usage_type": "Data Center/Web Hosting/Transit" } ``` #### check_ip_noise Query GreyNoise for attack activity: ```python # check_ip_noise(ip_address="185.220.101.34") # Returns: { "ip": "185.220.101.34", "classification": "malicious", "last_seen": "2024-05-16", "tags": ["SSH Bruteforce", "Web Scanner"], "cves": ["CVE-2024-1234"], "actor": "Unknown" } ``` #### shodan_host_lookup Get open ports and vulnerabilities: ```python # shodan_host_lookup(ip_address="8.8.8.8") # Returns: { "ip": "8.8.8.8", "ports": [53, 443], "vulns": [], "services": [ {"port": 53, "protocol": "dns", "product": "Google DNS"} ], "os": null, "hostnames": ["dns.google"] } ``` ### 5. Threat Intelligence (4 tools) #### virustotal_lookup Analyze hashes/URLs/domains/IPs: ```python # virustotal_lookup(resource_type="hash", resource="44d88612fea8a8f36de82e1278abb02f") # virustotal_lookup(resource_type="url", resource="https://malicious.example.com") # virustotal_lookup(resource_type="domain", resource="malicious.example.com") # virustotal_lookup(resource_type="ip", resource="192.0.2.1") # Returns: { "resource": "44d88612fea8a8f36de82e1278abb02f", "positives": 56, "total": 70, "scan_date": "2024-05-16 12:34:56", "permalink": "https://virustotal.com/...", "detections": { "Kaspersky": "HEUR:Trojan.Win32.Generic", "Microsoft": "Trojan:Win32/Meterpreter" } } ``` #### search_malware Query MalwareBazaar for samples: ```python # search_malware(query_type="tag", query="Emotet", limit=10)
View on GitHub
This SKILL.md is very large, so SkillsMP previews the first section here. View on GitHub