Vulnfeed

Created By
Infai Tech19 days ago
An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
Overview

Introduction

VulnFeed monitors your project's dependencies for security vulnerabilities — native to Claude Code.

What it does:

  • Reads your lockfile (package-lock.json, requirements.txt, go.sum, Cargo.lock, Gemfile.lock, composer.lock, yarn.lock, Pipfile.lock, pnpm-lock.yaml)
  • Queries NVD + GitHub Advisory Database for known CVEs
  • Enriches with EPSS (Exploit Prediction Scoring System) scores to filter noise
  • Recommends exact fix versions from package registries
  • Monitors projects continuously — get alerts when new CVEs drop

9 tools:

  • scan_project — auto-detect and scan all lockfiles in a directory
  • scan_lockfile — scan a specific lockfile
  • check_package — check a single package for vulns
  • lookup_cve — detailed CVE info with EPSS + fix versions
  • monitor_project — register for continuous monitoring
  • check_alerts — new vulns since last scan
  • update_deps — update snapshot after upgrading packages
  • list_monitored — see all monitored projects
  • unmonitor_project — remove from monitoring

Free tier: 10 scans/day, 1 monitored project. No signup required. Paid: $14/mo via Polar.sh. Unlimited scans + projects.

Homepage

https://vulnfeed.novadyne.ai

Purchase URL

https://buy.polar.sh/polar_cl_l2u7OfEs3L3NaMKsCQByy271MbERK5JO6ePqR0mRfBj

Transport

stdio (local install), SSE (remote)

Tool count

9

Supported ecosystems

npm, PyPI, Go, crates.io, RubyGems, Packagist (9 lockfile formats)

Server Config

{
  "mcpServers": {
    "vulnfeed": {
      "command": "uvx",
      "args": [
        "vulnfeed-mcp"
      ]
    }
  }
}
Project Info
Created At
19 days ago
Updated At
19 days ago
Author Name
Infai Tech
Star
-
Language
-
License
-
Category

Recommend Servers

View All
Shippo
@Shippo

20 hours ago
Mnemom

13 hours ago