Skip to main content

cve-mcp-server-security-intelligence

Production-grade MCP server providing Claude with 27 security intelligence tools across 21 APIs for vulnerability research, CVE analysis, threat intelligence, and risk scoring

インストールへ移動

ソース情報

リポジトリ
reason-machines/mcp-skills
ソースの最終更新活動
2026年5月16日 20:48
検出された SKILL.md の言語
英語
スター
7
フォーク
2

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
cve-mcp-server-security-intelligence
description
Production-grade MCP server providing Claude with 27 security intelligence tools across 21 APIs for vulnerability research, CVE analysis, threat intelligence, and risk scoring
triggers
["analyze this CVE for exploitation risk","check if this vulnerability is in CISA KEV","calculate risk score for these CVEs","search for exploits for CVE","lookup IP reputation and threat intelligence","generate security report for vulnerabilities","prioritize these CVEs by risk","check EPSS score for vulnerability"]
# CVE MCP Server Security Intelligence > Skill by [ara.so](https://ara.so) — MCP Skills collection ## What This Project Does CVE MCP Server is a production-grade Model Context Protocol server that transforms Claude into a comprehensive security analyst. It provides 27 security intelligence tools that integrate with 21 different APIs including NVD, EPSS, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, GreyNoise, GitHub, and more. Instead of manually querying multiple security databases, this MCP server allows Claude to: - Look up detailed CVE information with CVSS scores and affected products - Calculate composite risk scores using EPSS, KEV status, and PoC availability - Search for public exploits and proof-of-concept code - Check IP addresses against threat intelligence feeds - Analyze malware samples and indicators of compromise - Generate executive security reports with prioritized recommendations - Map vulnerabilities to MITRE ATT&CK techniques The server runs locally via stdio, makes only outbound HTTPS requests, and supports both free APIs (no key required) and premium services. ## Installation ### Prerequisites - Python 3.10 or higher - Claude Desktop or any MCP-compatible client - (Optional) API keys for premium services ### Install via pip/pipx (Recommended) ```bash # Using pipx (isolated environment) pipx install cve-mcp-server # Using pip pip install cve-mcp-server # Using uv (faster) uv pip install cve-mcp-server ``` ### Install from Source ```bash git clone https://github.com/mukul975/cve-mcp-server.git cd cve-mcp-server pip install -e . ``` ## Configuration ### Claude Desktop Setup Add to your Claude Desktop config file: **macOS**: `~/Library/Application Support/Claude/claude_desktop_config.json` **Windows**: `%APPDATA%\Claude\claude_desktop_config.json` ```json { "mcpServers": { "cve-security": { "command": "python", "args": ["-m", "cve_mcp_server"], "env": { "NVD_API_KEY": "your-nvd-key-here", "VIRUSTOTAL_API_KEY": "your-vt-key-here", "SHODAN_API_KEY": "your-shodan-key-here", "GREYNOISE_API_KEY": "your-greynoise-key-here", "ABUSEIPDB_API_KEY": "your-abuseipdb-key-here", "GITHUB_TOKEN": "your-github-token-here" } } } } ``` ### Environment Variables Required API keys (most are optional, tools degrade gracefully): - `NVD_API_KEY` - NVD API 2.0 key (free, highly recommended for rate limits) - `VIRUSTOTAL_API_KEY` - VirusTotal v3 API key - `SHODAN_API_KEY` - Shodan API key - `GREYNOISE_API_KEY` - GreyNoise Community or Enterprise key - `ABUSEIPDB_API_KEY` - AbuseIPDB v2 key - `GITHUB_TOKEN` - GitHub personal access token (public repo read) - `ABUSECH_AUTH_KEY` - Abuse.ch (MalwareBazaar/ThreatFox) auth key - `CIRCL_PDNS_USER` - CIRCL Passive DNS username - `CIRCL_PDNS_PASSWORD` - CIRCL Passive DNS password - `ALIENVAULT_OTX_KEY` - AlienVault OTX API key ### Create API Keys Free tier API keys: - **NVD**: https://nvd.nist.gov/developers/request-an-api-key - **GitHub**: https://github.com/settings/tokens (needs `public_repo` scope) - **VirusTotal**: https://www.virustotal.com/gui/join-us - **AbuseIPDB**: https://www.abuseipdb.com/register ## Core Tool Categories ### 1. Vulnerability Intelligence (8 tools) #### lookup_cve Fetch detailed CVE record from NVD: ```python # Claude will call this as: # lookup_cve(cve_id="CVE-2024-3400") # Returns: { "id": "CVE-2024-3400", "description": "Command injection vulnerability in...", "cvss_v3_score": 10.0, "cvss_v3_severity": "CRITICAL", "cvss_v3_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "published": "2024-04-12T00:00:00", "last_modified": "2024-04-15T12:34:56", "cwe_ids": ["CWE-77"], "references": [...], "affected_products": [...] } ``` #### search_cves Search NVD by keyword, product, or severity: ```python # search_cves(keyword="Apache Log4j", severity="CRITICAL", last_n_days=30) # search_cves(product="palo alto networks", max_results=10) ``` #### get_epss_score Get exploitation probability score (0.0-1.0): ```python # get_epss_score(cve_id="CVE-2024-3400") # Returns: { "cve": "CVE-2024-3400", "epss": 0.89234, "percentile": 0.99123, "date": "2024-05-16" } ``` #### check_kev_status Check if CVE is in CISA Known Exploited Vulnerabilities: ```python # check_kev_status(cve_id="CVE-2021-44228") # Returns: { "in_kev": true, "date_added": "2021-12-10", "due_date": "2021-12-24", "required_action": "Apply updates per vendor instructions", "known_ransomware": true } ``` #### bulk_cve_lookup Batch fetch up to 20 CVEs in parallel: ```python # bulk_cve_lookup(cve_ids=["CVE-2024-3400", "CVE-2023-44487", "CVE-2021-44228"]) ``` ### 2. Exploit & Attack Intelligence (4 tools) #### search_exploits Search GitHub for public PoC exploits: ```python # search_exploits(cve_id="CVE-2024-3400") # Returns: { "cve": "CVE-2024-3400", "exploit_count": 12, "exploits": [ { "title": "CVE-2024-3400 PoC", "url": "https://github.com/...", "stars": 45, "language": "Python", "created_at": "2024-04-13" } ] } ``` #### get_mitre_techniques Map CVE to MITRE ATT&CK framework: ```python # get_mitre_techniques(cve_id="CVE-2021-44228") # Returns: { "cve": "CVE-2021-44228", "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application", "tactic": "Initial Access", "description": "...", "mitigations": [...] } ] } ``` #### check_poc_availability Determine if PoC code exists across multiple sources: ```python # check_poc_availability(cve_id="CVE-2024-3400") # Returns: { "poc_available": true, "sources": ["GitHub", "Exploit-DB"], "confidence": "HIGH" } ``` ### 3. Risk Analysis & Reporting (4 tools) #### calculate_risk_score Compute composite 0-100 risk score: ```python # calculate_risk_score(cve_id="CVE-2024-3400") # Returns: { "cve": "CVE-2024-3400", "risk_score": 98.5, "risk_level": "CRITICAL", "components": { "cvss_score": 10.0, "epss_score": 0.89234, "in_kev": true, "poc_available": true, "exploit_maturity": "FUNCTIONAL" }, "recommendation": "Patch immediately - active exploitation confirmed" } ``` Risk score formula: ``` Base = CVSS * 10 (0-100) + EPSS * 30 (0-30) + KEV bonus: +20 + PoC bonus: +10 + Capped at 100 ``` #### prioritize_cves Rank multiple CVEs by composite risk: ```python # prioritize_cves(cve_ids=["CVE-2024-3400", "CVE-2023-4966", "CVE-2023-44487"]) # Returns sorted list with risk scores: [ {"cve": "CVE-2024-3400", "risk_score": 98.5, "priority": 1}, {"cve": "CVE-2023-44487", "risk_score": 87.3, "priority": 2}, {"cve": "CVE-2023-4966", "risk_score": 76.2, "priority": 3} ] ``` #### generate_risk_report Create executive security report: ```python # generate_risk_report(cve_ids=["CVE-2024-3400"], include_mitigations=True) # Returns formatted markdown report with: # - Executive summary # - CVE details with CVSS/EPSS # - KEV status and exploit availability # - MITRE ATT&CK mapping # - Prioritized remediation steps ``` ### 4. Network Intelligence (4 tools) #### lookup_ip_reputation Check IP against AbuseIPDB: ```python # lookup_ip_reputation(ip_address="185.220.101.34") # Returns: { "ip": "185.220.101.34", "abuse_confidence": 100, "total_reports": 1234, "is_public": true, "is_whitelisted": false, "country": "US", "isp": "Example ISP", "usage_type": "Data Center/Web Hosting/Transit" } ``` #### check_ip_noise Query GreyNoise for attack activity: ```python # check_ip_noise(ip_address="185.220.101.34") # Returns: { "ip": "185.220.101.34", "classification": "malicious", "last_seen": "2024-05-16", "tags": ["SSH Bruteforce", "Web Scanner"], "cves": ["CVE-2024-1234"], "actor": "Unknown" } ``` #### shodan_host_lookup Get open ports and vulnerabilities: ```python # shodan_host_lookup(ip_address="8.8.8.8") # Returns: { "ip": "8.8.8.8", "ports": [53, 443], "vulns": [], "services": [ {"port": 53, "protocol": "dns", "product": "Google DNS"} ], "os": null, "hostnames": ["dns.google"] } ``` ### 5. Threat Intelligence (4 tools) #### virustotal_lookup Analyze hashes/URLs/domains/IPs: ```python # virustotal_lookup(resource_type="hash", resource="44d88612fea8a8f36de82e1278abb02f") # virustotal_lookup(resource_type="url", resource="https://malicious.example.com") # virustotal_lookup(resource_type="domain", resource="malicious.example.com") # virustotal_lookup(resource_type="ip", resource="192.0.2.1") # Returns: { "resource": "44d88612fea8a8f36de82e1278abb02f", "positives": 56, "total": 70, "scan_date": "2024-05-16 12:34:56", "permalink": "https://virustotal.com/...", "detections": { "Kaspersky": "HEUR:Trojan.Win32.Generic", "Microsoft": "Trojan:Win32/Meterpreter" } } ``` #### search_malware Query MalwareBazaar for samples: ```python # search_malware(query_type="tag", query="Emotet", limit=10)
GitHubで見る
この SKILL.md は非常に大きいため、SkillsMP では最初のセクションだけを表示しています。 GitHubで見る