Security Recipes is answering right now. Last checked 5 min ago. It exposes 75 tools. Last commit 17 Sep 2026.
Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.
We read the source, 19 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
return JSON.parse(fs.readFileSync(path.join(ROOT, relativePath), "utf8"));
import { appendFileSync, readFileSync, readdirSync, statSync } from 'node:fs';
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 5 min ago.
claude mcp add security-recipes --transport http https://security-recipes.ai/mcp
{
"mcpServers": {
"security-recipes": {
"url": "https://security-recipes.ai/mcp"
}
}
}
[mcp_servers.security-recipes]
url = "https://security-recipes.ai/mcp"
{
"mcpServers": {
"security-recipes": {
"url": "https://security-recipes.ai/mcp"
}
}
}
{
"mcpServers": {
"security-recipes": {
"url": "https://security-recipes.ai/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
recipes_a2a_agent_card_trust_profile
recipes_agent_capability_risk_register
recipes_agent_handoff_boundary_pack
recipes_agent_identity_ledger
recipes_agent_memory_boundary_pack
recipes_agent_skill_supply_chain_pack
recipes_agent_trust_fabric_pack
recipes_agentic_action_runtime_pack
recipes_agentic_aivss_risk_scoring_pack
recipes_agentic_app_intake_pack
recipes_agentic_approval_receipt_pack
recipes_agentic_assurance_pack
recipes_agentic_catastrophic_risk_annex
recipes_agentic_control_plane_blueprint
recipes_agentic_entitlement_review_pack
recipes_agentic_exposure_graph
recipes_agentic_incident_response_pack
recipes_agentic_measurement_probe_pack
recipes_agentic_posture_snapshot
recipes_agentic_protocol_conformance_pack
recipes_agentic_readiness_scorecard
recipes_agentic_red_team_drill_pack
recipes_agentic_red_team_replay_harness
recipes_agentic_run_receipt_pack
recipes_agentic_soc_detection_pack
recipes_agentic_source_freshness_watch
recipes_agentic_standards_crosswalk
recipes_agentic_system_bom
recipes_agentic_telemetry_contract
recipes_agentic_threat_radar
recipes_browser_agent_boundary_pack
recipes_context_egress_boundary_pack
recipes_context_poisoning_guard_pack
recipes_critical_infrastructure_secure_context_pack
recipes_cve_catalog_info
recipes_cve_get
recipes_cve_search
recipes_design_partner_pilot_pack
recipes_enterprise_trust_center_export
recipes_get
recipes_hosted_mcp_readiness_pack
recipes_list
recipes_match_finding
recipes_mcp_authorization_conformance_pack
recipes_mcp_connector_intake_pack
recipes_mcp_connector_trust_pack
recipes_mcp_elicitation_boundary_pack
recipes_mcp_gateway_policy
recipes_mcp_risk_coverage_pack
recipes_mcp_server_get
recipes_mcp_servers_list
recipes_mcp_stdio_launch_boundary_pack
recipes_mcp_tool_risk_contract
recipes_mcp_tool_surface_drift_pack
recipes_mcp_upstream_call
recipes_mcp_upstream_context
recipes_mcp_upstream_servers
recipes_mcp_upstream_tools
recipes_model_provider_routing_pack
recipes_playbook_get
recipes_playbook_plan
recipes_playbooks_list
recipes_quality_report
recipes_refresh
recipes_search
recipes_secure_context_attestation_pack
recipes_secure_context_buyer_diligence_brief
recipes_secure_context_customer_proof_pack
recipes_secure_context_eval_pack
recipes_secure_context_evidence_contract
recipes_secure_context_lineage_ledger
recipes_secure_context_trust_pack
recipes_secure_context_value_model
recipes_server_info
recipes_workflow_control_plane
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://security-recipes.ai/mcp | streamable-http | answering | 649 ms | 5 min ago |
Security intelligence via x402 on Base. CVE lookup, IP reputation, secret scanning.
Read-only smart-contract security intelligence for autonomous agents.
Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions.
Sonatype component intelligence: versions, security analysis, and Trust Score recommendations
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
PostgreSQL security for AI agents: CVEs, yanked releases, exploits, and upgrade paths
SSH server management for agents, with per-server read-only and allowlist security modes
RunSec MCP server for workspace security scanning and remediation workflows.
Answers built from our own checks of this server.