cve-cache runs on your own machine — the client starts it, so there is no endpoint to ping. 40 installs a week from npm. Last commit 1 Jun 2026.
Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
Today is the operative word: we check cve-cache every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add cve-cache -- npx -y @weiseer/cve-cache-mcp
{
"mcpServers": {
"cve-cache": {
"args": [
"-y",
"@weiseer/cve-cache-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.cve-cache]
command = "npx"
args = ["-y", "@weiseer/cve-cache-mcp"]
{
"mcpServers": {
"cve-cache": {
"args": [
"-y",
"@weiseer/cve-cache-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"cve-cache": {
"args": [
"-y",
"@weiseer/cve-cache-mcp"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
CVE_CACHE_URL (Override remote snapshot URL), CVE_CACHE_LOCAL_ONLY (Skip remote fetch).
The author declared them in the registry entry; get the values from the project itself.
Git module dependencies and owning-agent routing for coding agents
Live npm/PyPI dependency-health verdicts so AI agents stop recommending stale or CVE'd packages
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Pipeline task management for AI agents - stages, dependencies, artifacts, claiming
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
JVM dependency intelligence for AI assistants via Maven Central
Dependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.
Dependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.
Answers built from our own checks of this server.