- name
- cve-mcp-server-security-intelligence
- description
- Production-grade MCP server providing Claude with 27 security intelligence tools across 21 APIs for vulnerability research, CVE analysis, threat intelligence, and risk scoring
- triggers
- ["analyze this CVE for exploitation risk","check if this vulnerability is in CISA KEV","calculate risk score for these CVEs","search for exploits for CVE","lookup IP reputation and threat intelligence","generate security report for vulnerabilities","prioritize these CVEs by risk","check EPSS score for vulnerability"]
# CVE MCP Server Security Intelligence
> Skill by [ara.so](https://ara.so) — MCP Skills collection
## What This Project Does
CVE MCP Server is a production-grade Model Context Protocol server that transforms Claude into a comprehensive security analyst. It provides 27 security intelligence tools that integrate with 21 different APIs including NVD, EPSS, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, GreyNoise, GitHub, and more.
Instead of manually querying multiple security databases, this MCP server allows Claude to:
- Look up detailed CVE information with CVSS scores and affected products
- Calculate composite risk scores using EPSS, KEV status, and PoC availability
- Search for public exploits and proof-of-concept code
- Check IP addresses against threat intelligence feeds
- Analyze malware samples and indicators of compromise
- Generate executive security reports with prioritized recommendations
- Map vulnerabilities to MITRE ATT&CK techniques
The server runs locally via stdio, makes only outbound HTTPS requests, and supports both free APIs (no key required) and premium services.
## Installation
### Prerequisites
- Python 3.10 or higher
- Claude Desktop or any MCP-compatible client
- (Optional) API keys for premium services
### Install via pip/pipx (Recommended)
```bash
# Using pipx (isolated environment)
pipx install cve-mcp-server
# Using pip
pip install cve-mcp-server
# Using uv (faster)
uv pip install cve-mcp-server
```
### Install from Source
```bash
git clone https://github.com/mukul975/cve-mcp-server.git
cd cve-mcp-server
pip install -e .
```
## Configuration
### Claude Desktop Setup
Add to your Claude Desktop config file:
**macOS**: `~/Library/Application Support/Claude/claude_desktop_config.json`
**Windows**: `%APPDATA%\Claude\claude_desktop_config.json`
```json
{
"mcpServers": {
"cve-security": {
"command": "python",
"args": ["-m", "cve_mcp_server"],
"env": {
"NVD_API_KEY": "your-nvd-key-here",
"VIRUSTOTAL_API_KEY": "your-vt-key-here",
"SHODAN_API_KEY": "your-shodan-key-here",
"GREYNOISE_API_KEY": "your-greynoise-key-here",
"ABUSEIPDB_API_KEY": "your-abuseipdb-key-here",
"GITHUB_TOKEN": "your-github-token-here"
}
}
}
}
```
### Environment Variables
Required API keys (most are optional, tools degrade gracefully):
- `NVD_API_KEY` - NVD API 2.0 key (free, highly recommended for rate limits)
- `VIRUSTOTAL_API_KEY` - VirusTotal v3 API key
- `SHODAN_API_KEY` - Shodan API key
- `GREYNOISE_API_KEY` - GreyNoise Community or Enterprise key
- `ABUSEIPDB_API_KEY` - AbuseIPDB v2 key
- `GITHUB_TOKEN` - GitHub personal access token (public repo read)
- `ABUSECH_AUTH_KEY` - Abuse.ch (MalwareBazaar/ThreatFox) auth key
- `CIRCL_PDNS_USER` - CIRCL Passive DNS username
- `CIRCL_PDNS_PASSWORD` - CIRCL Passive DNS password
- `ALIENVAULT_OTX_KEY` - AlienVault OTX API key
### Create API Keys
Free tier API keys:
- **NVD**: https://nvd.nist.gov/developers/request-an-api-key
- **GitHub**: https://github.com/settings/tokens (needs `public_repo` scope)
- **VirusTotal**: https://www.virustotal.com/gui/join-us
- **AbuseIPDB**: https://www.abuseipdb.com/register
## Core Tool Categories
### 1. Vulnerability Intelligence (8 tools)
#### lookup_cve
Fetch detailed CVE record from NVD:
```python
# Claude will call this as:
# lookup_cve(cve_id="CVE-2024-3400")
# Returns:
{
"id": "CVE-2024-3400",
"description": "Command injection vulnerability in...",
"cvss_v3_score": 10.0,
"cvss_v3_severity": "CRITICAL",
"cvss_v3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"published": "2024-04-12T00:00:00",
"last_modified": "2024-04-15T12:34:56",
"cwe_ids": ["CWE-77"],
"references": [...],
"affected_products": [...]
}
```
#### search_cves
Search NVD by keyword, product, or severity:
```python
# search_cves(keyword="Apache Log4j", severity="CRITICAL", last_n_days=30)
# search_cves(product="palo alto networks", max_results=10)
```
#### get_epss_score
Get exploitation probability score (0.0-1.0):
```python
# get_epss_score(cve_id="CVE-2024-3400")
# Returns:
{
"cve": "CVE-2024-3400",
"epss": 0.89234,
"percentile": 0.99123,
"date": "2024-05-16"
}
```
#### check_kev_status
Check if CVE is in CISA Known Exploited Vulnerabilities:
```python
# check_kev_status(cve_id="CVE-2021-44228")
# Returns:
{
"in_kev": true,
"date_added": "2021-12-10",
"due_date": "2021-12-24",
"required_action": "Apply updates per vendor instructions",
"known_ransomware": true
}
```
#### bulk_cve_lookup
Batch fetch up to 20 CVEs in parallel:
```python
# bulk_cve_lookup(cve_ids=["CVE-2024-3400", "CVE-2023-44487", "CVE-2021-44228"])
```
### 2. Exploit & Attack Intelligence (4 tools)
#### search_exploits
Search GitHub for public PoC exploits:
```python
# search_exploits(cve_id="CVE-2024-3400")
# Returns:
{
"cve": "CVE-2024-3400",
"exploit_count": 12,
"exploits": [
{
"title": "CVE-2024-3400 PoC",
"url": "https://github.com/...",
"stars": 45,
"language": "Python",
"created_at": "2024-04-13"
}
]
}
```
#### get_mitre_techniques
Map CVE to MITRE ATT&CK framework:
```python
# get_mitre_techniques(cve_id="CVE-2021-44228")
# Returns:
{
"cve": "CVE-2021-44228",
"techniques": [
{
"id": "T1190",
"name": "Exploit Public-Facing Application",
"tactic": "Initial Access",
"description": "...",
"mitigations": [...]
}
]
}
```
#### check_poc_availability
Determine if PoC code exists across multiple sources:
```python
# check_poc_availability(cve_id="CVE-2024-3400")
# Returns:
{
"poc_available": true,
"sources": ["GitHub", "Exploit-DB"],
"confidence": "HIGH"
}
```
### 3. Risk Analysis & Reporting (4 tools)
#### calculate_risk_score
Compute composite 0-100 risk score:
```python
# calculate_risk_score(cve_id="CVE-2024-3400")
# Returns:
{
"cve": "CVE-2024-3400",
"risk_score": 98.5,
"risk_level": "CRITICAL",
"components": {
"cvss_score": 10.0,
"epss_score": 0.89234,
"in_kev": true,
"poc_available": true,
"exploit_maturity": "FUNCTIONAL"
},
"recommendation": "Patch immediately - active exploitation confirmed"
}
```
Risk score formula:
```
Base = CVSS * 10 (0-100)
+ EPSS * 30 (0-30)
+ KEV bonus: +20
+ PoC bonus: +10
+ Capped at 100
```
#### prioritize_cves
Rank multiple CVEs by composite risk:
```python
# prioritize_cves(cve_ids=["CVE-2024-3400", "CVE-2023-4966", "CVE-2023-44487"])
# Returns sorted list with risk scores:
[
{"cve": "CVE-2024-3400", "risk_score": 98.5, "priority": 1},
{"cve": "CVE-2023-44487", "risk_score": 87.3, "priority": 2},
{"cve": "CVE-2023-4966", "risk_score": 76.2, "priority": 3}
]
```
#### generate_risk_report
Create executive security report:
```python
# generate_risk_report(cve_ids=["CVE-2024-3400"], include_mitigations=True)
# Returns formatted markdown report with:
# - Executive summary
# - CVE details with CVSS/EPSS
# - KEV status and exploit availability
# - MITRE ATT&CK mapping
# - Prioritized remediation steps
```
### 4. Network Intelligence (4 tools)
#### lookup_ip_reputation
Check IP against AbuseIPDB:
```python
# lookup_ip_reputation(ip_address="185.220.101.34")
# Returns:
{
"ip": "185.220.101.34",
"abuse_confidence": 100,
"total_reports": 1234,
"is_public": true,
"is_whitelisted": false,
"country": "US",
"isp": "Example ISP",
"usage_type": "Data Center/Web Hosting/Transit"
}
```
#### check_ip_noise
Query GreyNoise for attack activity:
```python
# check_ip_noise(ip_address="185.220.101.34")
# Returns:
{
"ip": "185.220.101.34",
"classification": "malicious",
"last_seen": "2024-05-16",
"tags": ["SSH Bruteforce", "Web Scanner"],
"cves": ["CVE-2024-1234"],
"actor": "Unknown"
}
```
#### shodan_host_lookup
Get open ports and vulnerabilities:
```python
# shodan_host_lookup(ip_address="8.8.8.8")
# Returns:
{
"ip": "8.8.8.8",
"ports": [53, 443],
"vulns": [],
"services": [
{"port": 53, "protocol": "dns", "product": "Google DNS"}
],
"os": null,
"hostnames": ["dns.google"]
}
```
### 5. Threat Intelligence (4 tools)
#### virustotal_lookup
Analyze hashes/URLs/domains/IPs:
```python
# virustotal_lookup(resource_type="hash", resource="44d88612fea8a8f36de82e1278abb02f")
# virustotal_lookup(resource_type="url", resource="https://malicious.example.com")
# virustotal_lookup(resource_type="domain", resource="malicious.example.com")
# virustotal_lookup(resource_type="ip", resource="192.0.2.1")
# Returns:
{
"resource": "44d88612fea8a8f36de82e1278abb02f",
"positives": 56,
"total": 70,
"scan_date": "2024-05-16 12:34:56",
"permalink": "https://virustotal.com/...",
"detections": {
"Kaspersky": "HEUR:Trojan.Win32.Generic",
"Microsoft": "Trojan:Win32/Meterpreter"
}
}
```
#### search_malware
Query MalwareBazaar for samples:
```python
# search_malware(query_type="tag", query="Emotet", limit=10)
Auf GitHub ansehen