mcpbeat

AgentSec MCP Server

io.github.traveljamboree/agentsec-mcp
answering

AgentSec MCP is answering right now. Last checked 10 min ago. It exposes 3 tools.

Security intelligence via x402 on Base. CVE lookup, IP reputation, secret scanning.

Uptime history 41 hours of history
41 hours agonow
100.0%
Uptime 24h
91 of 91 checks
3
Tools
read from the server
123 ms
Response time
average over 24h
open, no key
Access
streamable-http

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.

run in your terminal
claude mcp add agentsec-mcp --transport http https://agentsec-mcp.agentsec-mcp.workers.dev/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "agentsec-mcp": {
      "url": "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.agentsec-mcp]
url = "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "agentsec-mcp": {
      "url": "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "agentsec-mcp": {
      "url": "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
    }
  }
}

Available tools 3

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

cve
cve_lookup
Look up known CVE vulnerabilities for an npm package+version or a specific CVE ID. Returns CVSS scores, descriptions, and fix versions from NVD and OSV. Results are cached for 10 minutes. Costs $0.01 USDC per call.
reputation
reputation_check
Check the reputation of an IP address or domain using AbuseIPDB and VirusTotal. Returns a security verdict (malicious/suspicious/unknown/clean) with confidence signals. Verdict is conservative: incomplete data returns 'unknown' never 'clean'. Results are cached for 10 minutes. Costs $0.01 USDC per call.
secret
secret_scan
Scan text content for hardcoded secrets, API keys, and credentials using 20 pre-compiled patterns. Privacy guarantee: Input text is NEVER logged, cached, stored, or forwarded. Only findings_count and finding offsets (not matched values) are returned. Detected pattern types include: AWS keys, GitHub/GitLab PATs, OpenAI/Anthropic keys, Stripe secrets, Slack tokens, PEM private keys, JWT tokens, and 13 more. Per-call rate limit: 100/min. Payment: $0.05 USDC per scan.

Endpoints

URLTransportStateLatencyChecked
https://agentsec-mcp.agentsec-mcp.workers.dev/mcp streamable-http answering 152 ms 10 min ago

AgentSec MCP — questions

Answers built from our own checks of this server.

What can AgentSec MCP do?
It exposes 3 tools, read directly from the server on our last check. Among them: cve_lookup, reputation_check, secret_scan. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is AgentSec MCP working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 123 ms. The bar chart above shows every period we have measured.
How do I connect AgentSec MCP?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does AgentSec MCP need an API key?
No. AgentSec MCP completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 3 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is AgentSec MCP?
It answers our handshake in 123 ms on average, which is faster than 79% of all working MCP servers we measure. That puts it in the quick quarter of the ecosystem. The comparison comes from our own checks across the whole registry, every 15 minutes.