mcpbeat Sign in

Security Intel MCP Server

answering

Security Intel MCP is answering right now. Last checked moments ago. It exposes 5 tools. Last commit 16 Sep 2026.

CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

Uptime history 47 days of history
47 days agonow
100.0%
Uptime 24h
92 of 92 checks
5
Tools
read from the server
81 ms
Response time
average over 24h
0
Stars
last commit 16 Sep 2026

What changed 5

Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 2 September 2026. No other catalogue keeps this.

16 Sep 2 tools appeared epss_score, known_exploited
16 Sep a tool description was rewritten cve_lookup
16 Sep a tool changed version
2 Sep a tool changed the parameters it asks for package_vulnerabilities

Nothing serious here today

Today is the operative word: we check Security Intel MCP every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 0 min ago.

run in your terminal
claude mcp add security-intel-mcp --transport http https://security.datakoot.com/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "security-intel-mcp": {
      "url": "https://security.datakoot.com/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.security-intel-mcp]
url = "https://security.datakoot.com/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "security-intel-mcp": {
      "url": "https://security.datakoot.com/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "security-intel-mcp": {
      "url": "https://security.datakoot.com/mcp"
    }
  }
}

Available tools 5

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

audit
audit_dependencies
Audit a whole dependency manifest for known vulnerabilities in one call. Paste a package.json (as 'manifest'), or pass a 'dependencies' array of {name, version} objects. Returns per-package findings and a summary. Ecosystem defaults to npm.
cve
cve_lookup
Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, references — plus whether it is on the CISA Known-Exploited list (actively exploited in the wild) and its EPSS exploit-probability. Sources: NVD (NIST), CISA KEV, FIRST EPSS.
epss
epss_score
Get the EPSS exploit-probability score (0-1) and percentile for one or more CVEs — the likelihood each is exploited in the next 30 days. Use it to prioritize patching. Pass cve_id for one, or cve_ids (array or comma-separated) for many. Source: FIRST.org EPSS.
known
known_exploited
Check whether a CVE is on the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild — or list the most recently added exploited vulnerabilities. Pass cve_id to check one; omit it to list recent (optionally filter by vendor/product, or ransomware_only). Source: CISA KEV, updated ~daily.
package
package_vulnerabilities
List known vulnerabilities for a software package (optionally a specific version) via OSV. Ecosystems: npm, pypi, cargo, go, maven, rubygems, nuget, composer, pub, hex.

Endpoints

URLTransportStateLatencyChecked
https://security.datakoot.com/mcp streamable-http answering 99 ms 0 min ago

Alternatives to Security Intel MCP

same job, measured the same way
Security Intel MCP
by datakoot

CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

5 tools answering
AgentGuard — security checks for AI agents
by shuaicongxiaomai

Secret, CVE and dependency-vulnerability scanning for AI agents (free, OSV.dev).

local only
Osv Advisory MCP Server
by cyanheads

Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.

101 installs/wk 4 tools answering
SRIFT
by srift

Secure P2P file transfer and encrypted chat for AI agents. No accounts, no API keys.

288 installs/wk 8 tools answering
Siteaudit MCP
by vdalhambra

SEO, performance, and security audits for any URL — no API keys required

75 installs/wk local only
Janee
by rsdouglas

Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.

100 installs/wk local only
MCP Codeaudit
by infoinlet-marketplace

Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.

23 installs/wk local only
mcp-toolbelt
by papacasper

29 pay-per-call DNS, SEO, SSL, security, and dev tools for AI agents. x402, no API key.

29 tools answering

Security Intel MCP — questions

Answers built from our own checks of this server.

What can Security Intel MCP do?
It exposes 5 tools, read directly from the server on our last check. Among them: audit_dependencies, cve_lookup, epss_score, known_exploited, package_vulnerabilities. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Security Intel MCP working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 92 of 92 checks got a reply (100.0%), average response time 81 ms. The bar chart above shows every period we have measured.
How do I connect Security Intel MCP?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Security Intel MCP need an API key?
No. Security Intel MCP completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 5 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Security Intel MCP?
It answers our handshake in 81 ms on average, which is faster than 85% of all working MCP servers we measure. That puts it in the quick quarter of the ecosystem. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is Security Intel MCP open source?
Yes — it is published under the MIT licence, written in JavaScript and 0 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.